Windows Command #24 – net localgroup (Windows OS)

Minimal black and neon-green illustration representing the Windows net localgroup command and local user groups.

The Windows net localgroup command lets you list local groups, inspect group membership, and—when authorized—add or remove users from local groups.

In Windows Command #23 – net user, we worked with user accounts. net localgroup moves one level up: it shows how Windows organizes those users into local groups such as Users, Administrators, and Remote Desktop Users.

List local groups

net localgroup

Run the command with no group name to display local groups configured on the computer.

C:\> net localgroup

Aliases for \\LAB-PC

-------------------------------------------------------------------------------
*Administrators
*Backup Operators
*Remote Desktop Users
*Users
The command completed successfully.

This example is fictional. Your Windows edition and installed software may create additional local groups.

Video 1: net localgroup walkthrough

This walkthrough demonstrates listing local groups, creating a group, viewing membership, and adding or removing members with net localgroup.

Inspect one group

net localgroup Administrators
net localgroup Users
net localgroup "Remote Desktop Users"

Adding a group name displays the members of that group. Put names containing spaces inside quotation marks.

For example, net localgroup Administrators is a quick way to see which accounts currently belong to the local Administrators group. Listing a group is a read-only operation; it does not grant anyone new permissions.

Video 2: View local groups in Windows

Laurence Tindall demonstrates using net localgroup from Command Prompt to display the local groups configured on a Windows computer.

Add a user to a local group

On a computer you are authorized to administer, the general syntax is:

net localgroup GroupName UserName /add

For a fictional support account:

net localgroup "Remote Desktop Users" labtech /add

This adds the fictional labtech account to the local Remote Desktop Users group. Membership changes usually require an elevated Command Prompt and should follow the organization’s access-control policy.

Remove a user from a local group

net localgroup "Remote Desktop Users" labtech /delete

The /delete switch removes that account from the specified group. It does not delete the user account itself. That distinction matters: group membership and the underlying account are separate objects.

Video 3: Administrator-group example

Windows Report demonstrates several ways to change account type in Windows 11, including net localgroup from the terminal.

Create or delete a custom local group

Administrators can also create custom local groups for approved workflows:

net localgroup "Mining Ops" /add
net localgroup "Mining Ops"
net localgroup "Mining Ops" /delete

The first command creates a fictional group named Mining Ops. The second displays its members. The third removes the group. Creating or deleting groups should be done only when the change matches an approved system design.

net user vs. net localgroup

  • net user — list and inspect user accounts.
  • net localgroup — list local groups and inspect their membership.
  • net user username — show details about one account.
  • net localgroup groupname — show members of one group.

Together, the two commands provide a quick command-line view of local Windows identity structure.

Data-center troubleshooting example

A technician can sign into a Windows management station but cannot use a tool restricted to a specific local support group. A sensible read-only check is:

whoami
net user
net localgroup
net localgroup "Remote Desktop Users"

These commands confirm the current identity, show local accounts, show available groups, and inspect one group’s membership. If the expected account is missing, the next step is to follow the organization’s authorization process before changing membership.

Built-in help

net localgroup /?
net help localgroup

Use the built-in help to review syntax supported by the installed Windows version before making changes.

Common beginner mistakes

  • Confusing a group with a user account.
  • Forgetting quotation marks around group names that contain spaces.
  • Assuming membership in Users and Administrators is equivalent.
  • Using /delete on the group when the intention was only to remove one member.
  • Trying to change protected group membership without an elevated and authorized session.
  • Adding users to privileged groups without a documented operational need.

Practice

  1. Open Command Prompt.
  2. Run net localgroup.
  3. Identify the Users group.
  4. Run net localgroup Users.
  5. Run net localgroup Administrators.
  6. Compare those results with net user yourusername.
  7. In one sentence, explain the difference between a Windows user account and a local group.

Previous Windows lessons

Windows Command #23 – net user (Windows OS)

Windows Command #22 – whoami (Windows OS)

Windows Command #21 – getmac (Windows OS)

Reference

Microsoft’s net localgroup command reference

Key takeaway

net localgroup gives Windows administrators and technicians a fast way to inspect local groups and membership from Command Prompt. Start with read-only listing commands, and make membership changes only on systems you are authorized to administer.

Leave a comment