How to add a user to the Hyper-V administrators group

Granting full local administrator rights just so a user can manage virtual machines poses a security risk. By adding an account to the built-in Hyper-V Administrators local group, the user can create, start, and configure virtual machines without having full control over the host operating system. This step-by-step guide will show you how to add local or domain users to this group using Computer Management, PowerShell, or Command Prompt.

ADVERTISEMENT

Adding a user to the Hyper-V Administrators group grants non-administrators complete and unrestricted access to all Hyper-V features.

Method 1: Computer Management (GUI)

  1. Click on the Windows start menu button or the search icon on the taskbar.
  2. Type computer management.
  3. Right-click on Computer Management and select Run as administrator.
  4. When the 'User Account Control' window appears, click Yes. If prompted, enter an administrator password and click Yes.
  5. Expand System Tools > Local Users and Groups.
  6. Click Groups.
  7. In the center pane, double-click Hyper-V Administrators.
    Open Hyper-V Administrators settings in Windows Computer Management
  8. In the 'Hyper-V Administrators Properties' window, click Add at the bottom of the window.
  9. In the 'Select Users' window, type the username you want to add to the Hyper-V administrators group.
  10. Click Check names.
  11. Once the correct [computer name + username] combination appears, click OK.
    Add a user to the Hyper-V administrators group using Windows Computer Management
  12. Click Apply at the bottom of the 'Hyper-V Administrators Properties' window.
  13. Click OK.
  14. Restart your computer.

The user is now part of the Hyper-V Administrators group and has unrestricted access to all Hyper-V features.

Alternative method to open Computer Management as administrator: Press Windows + R > Type compmgmt.msc > Press Ctrl + Shift + Enter.

ADVERTISEMENT

Method 2: PowerShell (CLI)

  • Right-click the Windows start menu button and select Terminal (Admin) or Windows PowerShell (Admin).
  • To add a local user, run:
    
    Add-LocalGroupMember -Group "Hyper-V Administrators" -Member "[Username]"
    
    
  • To add a domain user, specify the domain name:
    
    Add-LocalGroupMember -Group "Hyper-V Administrators" -Member "[DOMAIN\Username]"
    
    
  • Restart your computer.
SPONSORED

Method 3: Command Prompt (CMD)

  1. Open Command Prompt as administrator.
  2. Run the following command:
    
    net localgroup "Hyper-V Administrators" "[Username]" /add
    
    
  3. Restart your computer.
SPONSORED

Troubleshooting & notes

  • User must sign out: The most common reason permissions fail after adding a user to the Hyper-V Administrators group is that active security tokens do not update dynamically. The target account must log off and log back in (or reboot the computer) before opening Hyper-V Manager.
  • Access denied error in Hyper-V Manager: If the user gets an "You do not have the required permission to complete this task" error even when the user is a member of the Hyper-V Administrators group, verify that WinRM is properly configured and enabled or check local security policies:
    
    Enable-PSRemoting -Force
    
    
  • Domain controllers note: On Active Directory Domain Controllers, local groups do not exist. You must manage group members through Active Directory Users and Computers in the Builtin container.
ADVERTISEMENT