What is the minimum privilege to join client PC to AD Domain?
hi,
in ad user groups, group has minimum privilege and can join client pc ad domain? possible a user that not in group of administrator/enterprise admin still can perform add winxp ad domain? help.
jason
as others have pointed out, default, authenticated user can join computers domain (the number of computers added in manner, limited value of ms-ds-machineaccountquota attribute, set default 10 (more on @ http://support.microsoft.com/kb/243327)
the recommended approach limit user rights add workstations domain user right assignment (default domain controllers gpo) removing authenticated users , adding designated group of support staff handling computer provisioning tasks
hth
marcin
Windows Server > Directory Services
Comments
Post a Comment