What is the minimum privilege to join client PC to AD Domain?


hi,

in ad user groups, group has minimum privilege and can join client pc ad domain?  possible a user that not in group of administrator/enterprise admin still can perform add winxp ad domain?  help.

jason

 

as others have pointed out, default, authenticated user can join computers domain (the number of computers added in manner, limited value of ms-ds-machineaccountquota attribute, set default 10 (more on @ http://support.microsoft.com/kb/243327)

the recommended approach limit user rights add workstations domain user right assignment (default domain controllers gpo) removing authenticated users , adding designated group of support staff handling computer provisioning tasks

hth
marcin



Windows Server  >  Directory Services



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Windows 2016 RDS event 1306 Connection Broker Client failed to redirect the user... Error: NULL