Allow only desktop administrators to "add workstations to a domain" but prevent them from adding servers to the 2003 domain??

Allow only desktop administrators to "add workstations to a domain" but how can prevent them from adding Windows 2000/2003 servers to the 2003 domain??
cmkmfgAsked:
Who is Participating?

Improve company productivity with a Business Account.Sign Up

x
 
JamesDSConnect With a Mentor Commented:
cmkmfg
The permissions you are seeking are not possible.

The permissions needed to join a workstation to the domain is essentially, create machine account, reset machine account password and reset DNS name on machine account.

A machine account is the same for Workstation and Server and is not identified as a server until it logs in for the first time (ie first reboot after a successful join).

If you store servers and workstations in different OUs you could limit addition of new computer accounts to the Servers OU, but that wouldn't stop servers being put into the wrong OU.

Cheers

JamesDS
0
 
SembeeCommented:
I don't think you can. The domain will not know what sort of system the machine is until after it has joined.

Simon.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.