Add the Administrators security group to roaming user profiles
Verified with Windows 11 25H2 — updated on July 10, 2026
Supported on: At least Windows Server 2003 operating systems or Windows XP Professional
Path in the GPO console
Computer Configuration\Administrative Templates\System\User Profiles Description
This policy setting adds the Administrator security group to the roaming user profile share. Once an administrator has configured a user's roaming profile, the profile will be created at the user's next login. The profile is created at the location that is specified by the administrator. For the Windows XP Professional and Windows 2000 Professional operating systems, the default file permissions for the newly generated profile are full control, or read and write access for the user, and no file access for the administrators group. By configuring this policy setting, you can alter this behavior. If you enable this policy setting, the administrator group is also given full control to the user's profile folder. If you disable or do not configure this policy setting, only the user is given full control of their user profile, and the administrators group has no file system access to this folder. Note: If the policy setting is enabled after the profile is created, the policy setting has no effect. Note: The policy setting must be configured on the client computer, not the server, for it to have any effect, because the client computer sets the file share permissions for the roaming profile at creation time. Note: In the default case, administrators have no file access to the user's profile, but they may still take ownership of this folder to grant themselves file permissions. Note: The behavior when this policy setting is enabled is exactly the same behavior as in Windows NT 4.0.
Registry
Software\Policies\Microsoft\Windows\System Value name: AddAdminGroupToRUP
Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Add the Administrators security group to roaming user profiles
; State: Enabled
; Supported on: At least Windows Server 2003 operating systems or Windows XP Professional
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\System]
"AddAdminGroupToRUP"=dword:00000001 More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Add the Administrators security group to roaming user profiles
# State: Enabled
# Supported on: At least Windows Server 2003 operating systems or Windows XP Professional
$path = 'HKLM:\Software\Policies\Microsoft\Windows\System'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AddAdminGroupToRUP' -Value 1 -Type DWord Intune XML
No direct Policy CSP / OMA-URI mapping for this policy. Use the Intune Remediation tab, or ingest the ADMX in Intune. Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Add the Administrators security group to roaming user profiles
# State: Enabled
# Supported on: At least Windows Server 2003 operating systems or Windows XP Professional
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows\System' -Name 'AddAdminGroupToRUP' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Add the Administrators security group to roaming user profiles
# State: Enabled
# Supported on: At least Windows Server 2003 operating systems or Windows XP Professional
$path = 'HKLM:\Software\Policies\Microsoft\Windows\System'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AddAdminGroupToRUP' -Value 1 -Type DWord SCCM scripts
# Exported from gporais.com
# Policy: Add the Administrators security group to roaming user profiles
# State: Enabled
# Supported on: At least Windows Server 2003 operating systems or Windows XP Professional
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Add the Administrators security group to roaming user profiles
# State: Enabled
# Supported on: At least Windows Server 2003 operating systems or Windows XP Professional
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows\System' -Name 'AddAdminGroupToRUP' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Add the Administrators security group to roaming user profiles
# State: Enabled
# Supported on: At least Windows Server 2003 operating systems or Windows XP Professional
$path = 'HKLM:\Software\Policies\Microsoft\Windows\System'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AddAdminGroupToRUP' -Value 1 -Type DWord Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.