have you run gpupdate on the client machine to make sure that the domain GPO is getting applied?
from cmd prompt - gpupdate /force
I have created a user as domain user in AD, I delegated permission at the domain level so that he can create computer objects in the domain.
in local policy/user rights at the domain level I added him to join workstation to the domain.
in Windows XP, I made the user a member of local administrator.
Now when the user tries to join the WXP to the domain he gets an error message:
Your computer could not be joined to the domain because the following error has occured: Access Denied.
Can someone help through this?
Thanks
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
this is a single user , I delegated permission at the domain level so that he can create computer objects in the domain.
in local policy/user rights at the domain level I added him to join workstation to the domain.
in Windows XP, I made the user a member of local administrator.
Now when the user tries to join the WXP to the domain he gets an error message:
Your computer could not be joined to the domain because the following error has occured: Access Denied.
I have run Gpupdate both at the DC and windows XP and it didn't hepl.
Network connection is good , DNS is good....
1. Right click on created computer object in AD
2. Propirties
3. Managed By
4. Press Change button
5. Select user acount that must join computer into domain
6. Click OK. (twice)
7. User has permision to join computer to domain now.
You do not need:
"in Windows XP, I made the user a member of local administrator."
I guess I figured the way to delegate a domain user to join the computer to the domain while this computer object has been already created in a specific OU.
-Delegate control at the OU level where the computer object is created
-select create a custom task to delegate
select only the following objects in the folder
-select computer objects
-select both check boxes "Create/Delete selected objects in this folder"
-I selected Full control ( here I am not sure if it's too much privileges)
Is that safe guys???
Business Accounts
Answer for Membership
by: rknetworkPosted on 2009-03-26 at 17:27:41ID: 23997095
Did you try this:
e.com/OS/ M icrosoft_O perating_S ystems/Ser ver/ Window s_2000_Act ive_Direct ory/Q_2312 4549.html# a20782076
http://www.experts-exchang
??