Click here to get back home

Add workstation to Domain

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Add workstation to Domain George Spiro 07-28-2006
Posted by George Spiro on July 28, 2006, 10:48 am
Please log in for more thread options
Hi,

I am looking first of all to block all domain users to add machines to the
domain. I do not want to allow anyone besides Domain Admins and one other
account to add machines to the domain.

So the other is where do I need to configure to allow this user to add
machines to the domain. This user will be like a service account i do not
want to give him login privileges. Will be used with SMS and BDD.

I am slightly confused regarding local security policy, domain security
policy, domain controler security policy.

Thanks for your help,

George





Posted by Andrei Ungureanu [MVP] on July 28, 2006, 11:07 am
Please log in for more thread options
you'll need to modify Default Domain Controller Policy.
http://technet2.microsoft.com/WindowsServer/en/library/7207aa3e-d95d-4176-a1ca-bc629f1ca6981033.mspx?mfr=true

--
Regards,
Andrei Ungureanu
www.eventid.net
Test our new EventReader!
http://www.altairtech.ca/eventreader/default2.asp?ref=au

> Hi,
>
> I am looking first of all to block all domain users to add machines to the
> domain. I do not want to allow anyone besides Domain Admins and one other
> account to add machines to the domain.
>
> So the other is where do I need to configure to allow this user to add
> machines to the domain. This user will be like a service account i do not
> want to give him login privileges. Will be used with SMS and BDD.
>
> I am slightly confused regarding local security policy, domain security
> policy, domain controler security policy.
>
> Thanks for your help,
>
> George
>
>
>
>



Posted by George Spiro on July 31, 2006, 10:30 am
Please log in for more thread options
I dont see the value Create Computer Object, I got only Create global
objects.

"Andrei Ungureanu [MVP]" <contact me via www.itboard.ro> wrote in message
> you'll need to modify Default Domain Controller Policy.
> http://technet2.microsoft.com/WindowsServer/en/library/7207aa3e-d95d-4176-a1ca-bc629f1ca6981033.mspx?mfr=true
>
> --
> Regards,
> Andrei Ungureanu
> www.eventid.net
> Test our new EventReader!
> http://www.altairtech.ca/eventreader/default2.asp?ref=au
>
>> Hi,
>>
>> I am looking first of all to block all domain users to add machines to
>> the
>> domain. I do not want to allow anyone besides Domain Admins and one other
>> account to add machines to the domain.
>>
>> So the other is where do I need to configure to allow this user to add
>> machines to the domain. This user will be like a service account i do not
>> want to give him login privileges. Will be used with SMS and BDD.
>>
>> I am slightly confused regarding local security policy, domain security
>> policy, domain controler security policy.
>>
>> Thanks for your help,
>>
>> George
>>
>>
>>
>>
>
>



Posted by Andrei Ungureanu [MVP] on July 31, 2006, 11:52 am
Please log in for more thread options
you can set the Create Computer Objects permission by using the Delegate
Control wizard. Right click on an OU and start the wizard.

--
Regards,
Andrei Ungureanu
www.eventid.net
Test our new EventReader!
http://www.altairtech.ca/eventreader/default2.asp?ref=au

>I dont see the value Create Computer Object, I got only Create global
>objects.
>
> "Andrei Ungureanu [MVP]" <contact me via www.itboard.ro> wrote in message
>> you'll need to modify Default Domain Controller Policy.
>> http://technet2.microsoft.com/WindowsServer/en/library/7207aa3e-d95d-4176-a1ca-bc629f1ca6981033.mspx?mfr=true
>>
>> --
>> Regards,
>> Andrei Ungureanu
>> www.eventid.net
>> Test our new EventReader!
>> http://www.altairtech.ca/eventreader/default2.asp?ref=au
>>
>>> Hi,
>>>
>>> I am looking first of all to block all domain users to add machines to
>>> the
>>> domain. I do not want to allow anyone besides Domain Admins and one
>>> other
>>> account to add machines to the domain.
>>>
>>> So the other is where do I need to configure to allow this user to add
>>> machines to the domain. This user will be like a service account i do
>>> not
>>> want to give him login privileges. Will be used with SMS and BDD.
>>>
>>> I am slightly confused regarding local security policy, domain security
>>> policy, domain controler security policy.
>>>
>>> Thanks for your help,
>>>
>>> George
>>>
>>>
>>>
>>>
>>
>>
>
>



Posted by Steven L Umbach on July 31, 2006, 9:01 pm
Please log in for more thread options
Where are you seeing create global objects?? Anyhow go to the advanced page
of the security page of the Active Directory container [using Active
Directory Users and Computers] that you want to give the user/group
permissions to and then you should see create computer objects when you add
or edit a user/group in the access control list.



>I dont see the value Create Computer Object, I got only Create global
>objects.
>
> "Andrei Ungureanu [MVP]" <contact me via www.itboard.ro> wrote in message
>> you'll need to modify Default Domain Controller Policy.
>> http://technet2.microsoft.com/WindowsServer/en/library/7207aa3e-d95d-4176-a1ca-bc629f1ca6981033.mspx?mfr=true
>>
>> --
>> Regards,
>> Andrei Ungureanu
>> www.eventid.net
>> Test our new EventReader!
>> http://www.altairtech.ca/eventreader/default2.asp?ref=au
>>
>>> Hi,
>>>
>>> I am looking first of all to block all domain users to add machines to
>>> the
>>> domain. I do not want to allow anyone besides Domain Admins and one
>>> other
>>> account to add machines to the domain.
>>>
>>> So the other is where do I need to configure to allow this user to add
>>> machines to the domain. This user will be like a service account i do
>>> not
>>> want to give him login privileges. Will be used with SMS and BDD.
>>>
>>> I am slightly confused regarding local security policy, domain security
>>> policy, domain controler security policy.
>>>
>>> Thanks for your help,
>>>
>>> George
>>>
>>>
>>>
>>>
>>
>>
>
>



Similar ThreadsPosted
possible to log when a domain user locks workstation? August 23, 2006, 12:41 am
Access is denied when trying to add a workstation to a new domain December 11, 2006, 3:12 pm
Windows 2003 Single Mode - Workstation Login says: DOMAIN (Win 200 January 10, 2006, 8:41 pm
Workstation Authentication December 4, 2007, 3:56 pm
Auditing Workstation logons from DC January 24, 2006, 7:29 pm
cannot decrypt files on my workstation January 3, 2007, 4:04 pm
Finding out which account added a workstation to the AD... September 1, 2005, 9:19 am
IAS + user smartcard + workstation certificate July 6, 2007, 9:48 am
Workstation Security Policies & RSoP December 14, 2007, 9:08 am
Windows NT 4.0. workstation logging into Win server 2003 ? September 18, 2005, 10:04 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap