Public/TenantConfiguration/Baseline/ConfigurationPolicies/JyskIT-Baseline-SEC-LocalUserGroupMembership.json

{
  "templateReference": {
    "templateDisplayName": "Local user group membership",
    "templateFamily": "endpointSecurityAccountProtection",
    "templateId": "22968f54-45fa-486c-848e-f8224aa69772_1",
    "templateDisplayVersion": "Version 1"
  },
  "platforms": "windows10",
  "roleScopeTagIds": [
    "0"
  ],
  "technologies": "mdm",
  "description": "Make sure the local administrators group is only populated with the correct users",
  "name": "JyskIT-Baseline-SEC-LocalUserGroupMembership",
  "settings": [
    {
      "id": "0",
      "settingInstance": {
        "@odata.type": "#microsoft.graph.deviceManagementConfigurationGroupSettingCollectionInstance",
        "settingInstanceTemplateReference": {
          "settingInstanceTemplateId": "de06bec1-4852-48a0-9799-cf7b85992d45"
        },
        "groupSettingCollectionValue": [
          {
            "settingValueTemplateReference": null,
            "children": [
              {
                "@odata.type": "#microsoft.graph.deviceManagementConfigurationGroupSettingCollectionInstance",
                "settingInstanceTemplateReference": {
                  "settingInstanceTemplateId": "76fa254e-cbdb-4718-8bdd-cd41e57caa02"
                },
                "groupSettingCollectionValue": [
                  {
                    "settingValueTemplateReference": null,
                    "children": [
                      {
                        "@odata.type": "#microsoft.graph.deviceManagementConfigurationChoiceSettingInstance",
                        "settingInstanceTemplateReference": null,
                        "choiceSettingValue": {
                          "children": [
                            {
                              "@odata.type": "#microsoft.graph.deviceManagementConfigurationSimpleSettingCollectionInstance",
                              "settingInstanceTemplateReference": null,
                              "simpleSettingCollectionValue": [
                                {
                                  "@odata.type": "#microsoft.graph.deviceManagementConfigurationStringSettingValue",
                                  "settingValueTemplateReference": null,
                                  "value": "JyskIT-Baseline-SEC-LocalAdmins"
                                }
                              ],
                              "settingDefinitionId": "device_vendor_msft_policy_config_localusersandgroups_configure_groupconfiguration_accessgroup_users"
                            }
                          ],
                          "settingValueTemplateReference": null,
                          "value": "device_vendor_msft_policy_config_localusersandgroups_configure_groupconfiguration_accessgroup_userselectiontype_users"
                        },
                        "settingDefinitionId": "device_vendor_msft_policy_config_localusersandgroups_configure_groupconfiguration_accessgroup_userselectiontype"
                      },
                      {
                        "@odata.type": "#microsoft.graph.deviceManagementConfigurationChoiceSettingInstance",
                        "settingInstanceTemplateReference": null,
                        "choiceSettingValue": {
                          "children": [],
                          "settingValueTemplateReference": null,
                          "value": "device_vendor_msft_policy_config_localusersandgroups_configure_groupconfiguration_accessgroup_action_add_restrict"
                        },
                        "settingDefinitionId": "device_vendor_msft_policy_config_localusersandgroups_configure_groupconfiguration_accessgroup_action"
                      },
                      {
                        "@odata.type": "#microsoft.graph.deviceManagementConfigurationChoiceSettingCollectionInstance",
                        "settingInstanceTemplateReference": null,
                        "choiceSettingCollectionValue": [
                          {
                            "children": [],
                            "settingValueTemplateReference": null,
                            "value": "device_vendor_msft_policy_config_localusersandgroups_configure_groupconfiguration_accessgroup_desc_administrators"
                          }
                        ],
                        "settingDefinitionId": "device_vendor_msft_policy_config_localusersandgroups_configure_groupconfiguration_accessgroup_desc"
                      }
                    ]
                  }
                ],
                "settingDefinitionId": "device_vendor_msft_policy_config_localusersandgroups_configure_groupconfiguration_accessgroup"
              }
            ]
          }
        ],
        "settingDefinitionId": "device_vendor_msft_policy_config_localusersandgroups_configure"
      }
    }
  ]
}