Add IIS AppPool\ASP.NET v4.0 to local windows group
Tag : windows , By : Tom Berthon
Date : November 28 2020, 01:01 AM

help you fix your problem You need to use Python Win32 Extensions to interact with Windows. I think some of the methods in win32net module would help you to get the information you need.

Hope this helps You're basically looking for two events in the Security eventlog.
4732 A member was added to a security-enabled local group. 4733 A member was removed from a security-enabled local group.
eventvwr /f:"<QueryList><Query Id='0' Path='Security'><Select Path='Security'>*[System[(EventID=4732 or EventID=4733)]]</Select></Query></QueryList>"
wmic ntevent where "LogFile='security' and (EventIdentifier=4732 or EventIdentifier=4733)"
get-eventlog -logname security | where {$_.InstanceId -eq 4732 -or $_.InstanceId -eq 4733} 
var list = new EventLog { Log = "Security" }
            .Where(evl => evl.InstanceId == 4732 || evl.InstanceId == 4733)
            .Select(cv => cv.Message);
foreach (var msg in list)

I wish did fix the issue. If you want to create a user you need to actually create a user. The statement you're using returns a user account only if it already exists:
$User = [ADSI]"WinNT://$Computer/$UserName,user"
& net user $UserName ($Cred.GetNetworkCredential().Password) /expires:never /add
$acct = [adsi]"WinNT://$Computer"
$user = $acct.Create('User', $UserName)
$AdminGroupName = Get-WmiObject Win32_Group -Filter "LocalAccount=True AND SID='S-1-5-32-544'" |
                  Select-Object -Expand Name
$AdminGroup = [adsi]"WinNT://$Computer/$AdminGroupName,group"

To fix the issue you can do I am trying to uninstall Microsoft SQL Server from my local machine. Uninstall instructions say one must delete all local security groups for SQL Server components before uninstalling, however I cannot figure how to do this on Windows 10 Home. I have found online two ways of doing this, but neither has worked. , Try:
Remove-LocalGroup -Name 'SQLServer2005SQLBrowserUser$<computername>'

