If a user has local administrative rights of their own PC and a Domain user account, they can join their PC to the Domain. In this case, you'll want to remove their local administrative privileges to prevent them from joining systems to the domain.
Definitely not the most secure process...
Hope this helps...
Mike
Main Topics
Browse All Topics





by: Raheem05Posted on 2009-10-25 at 17:28:27ID: 25659131
Click Start, click Run, type dsa.msc, and then click OK
Under Security Settings/Local Policies/User Rights Assignment - Add workstations to domain edit permissions and set to domain admins only