Hope this helps You're basically looking for two events in the Security eventlog. 4732 A member was added to a security-enabled local group. 4733 A member was removed from a security-enabled local group.
eventvwr /f:"<QueryList><Query Id='0' Path='Security'><Select Path='Security'>*[System[(EventID=4732 or EventID=4733)]]</Select></Query></QueryList>"
wmic ntevent where "LogFile='security' and (EventIdentifier=4732 or EventIdentifier=4733)"
To fix the issue you can do I am trying to uninstall Microsoft SQL Server from my local machine. Uninstall instructions say one must delete all local security groups for SQL Server components before uninstalling, however I cannot figure how to do this on Windows 10 Home. I have found online two ways of doing this, but neither has worked. , Try: