# Approve Local Administrators

> Build the list of approved local administrator accounts and groups, so Security Monitor can flag unapproved and orphaned administrators on your endpoints.

Source: https://docs.capaone.com/capaone/security-monitor/approve-local-administrators/  
Product: CapaOne — a separate CapaSystems product; do not apply this page to any other.

Security Monitor checks the local administrator accounts and groups on every Windows endpoint
against a list you approve. Anything not on the list is reported as an unapproved administrator in
the **Local Administrators** widget. This page shows you how to build and maintain that list.

:::note[Before you start]
The endpoints must have reported their security inventory to CapaOne. Endpoints without security
inventory aren't included in the widget.
:::

## Open the approved list

1. Go to **Windows → Security** and select the **Overview** tab.
2. In the **Local Administrators** widget, select the tune icon.

The **Approved Local Administrators** dialog opens. It lists every local administrator account and
group found on your endpoints, with its **Name**, **Type**, and **Source**.

![Approved Local Administrators dialog with the Built-in administrator rules box, the Domain Admins rule selected, and a list of accounts with their type and source](/attachments/capaone/approve-local-administrators-dialog.png)

| Column | Values |
|---|---|
| **Type** | **User** or **Group**. |
| **Source** | **Local** for accounts and groups on the endpoint, **ActiveDirectory** for domain accounts and groups, or **Orphan** for accounts whose user no longer exists. |

## Approve built-in administrators

Under **Built-in administrator rules**, you can approve well-known administrator accounts on every
endpoint at once, including endpoints you add later:

- **Administrator** approves the built-in local Administrator account on every endpoint.
- **Domain Admins** approves the Domain Admins group on every endpoint.

The rules match the accounts by their security identifier (SID), so they work even if an account
has been renamed. Rows covered by a rule are marked as approved in the list.

## Approve individual accounts and groups

1. Use the search field to find an account or group by name, type, or source.
2. Select the check box next to each account or group you want to approve. Select the check box in
   the column header to approve every row that matches your search.
3. Click **Save**.

The number of approved identities is shown in the top-right corner of the dialog. When you save,
the **Local Administrators** widget recalculates.

## Review the results

The widget shows the share of compliant endpoints, the number of **Unapproved admins**, and the
number of **Orphaned accounts**. An endpoint is compliant when every local administrator on it is
approved.

- Click the **Non-compliant** segment of the chart to list the endpoints with at least one
  unapproved administrator.
- Select the table icon to see each endpoint's number of **Admins**, **Unapproved**
  administrators, and **Orphaned** accounts.

To remove an unapproved administrator from endpoints, you can deploy a PowerBrick such as
[Remove User From Local Group](/capaone/application-manager/powerbricks/remove-user-from-local-group/)
or [Local Group Remove All Except](/capaone/application-manager/powerbricks/local-group-remove-all-except/).

## Good to know

- The approved list applies to the whole organization. It isn't tied to a configuration or group.
- Orphaned accounts still hold administrator rights on the endpoint. Remove them, or approve them
  only if you have a reason to keep them. See
  [Orphaned User Accounts](/capaone/troubleshooting/orphaned-user-accounts/).
- The widget doesn't change the endpoints. It reports what it finds. Privilege Manager controls
  temporary elevation separately. See [Privilege Manager](/capaone/privilege-manager/).
