Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Allow only desktop administrators to "add workstations to a domain" but prevent them from adding servers to the 2003 domain??

Posted on 2004-10-02
2
Medium Priority
?
219 Views
Last Modified: 2010-04-19
Allow only desktop administrators to "add workstations to a domain" but how can prevent them from adding Windows 2000/2003 servers to the 2003 domain??
0
Comment
Question by:cmkmfg
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 104

Expert Comment

by:Sembee
ID: 12212557
I don't think you can. The domain will not know what sort of system the machine is until after it has joined.

Simon.
0
 
LVL 16

Accepted Solution

by:
JamesDS earned 750 total points
ID: 12215374
cmkmfg
The permissions you are seeking are not possible.

The permissions needed to join a workstation to the domain is essentially, create machine account, reset machine account password and reset DNS name on machine account.

A machine account is the same for Workstation and Server and is not identified as a server until it logs in for the first time (ie first reboot after a successful join).

If you store servers and workstations in different OUs you could limit addition of new computer accounts to the Servers OU, but that wouldn't stop servers being put into the wrong OU.

Cheers

JamesDS
0

Featured Post

Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

by Batuhan Cetin In this article I will be guiding through the process of removing a failed DC metadata from Active Directory (hereafter, AD) using the ntdsutil tool in a Windows Server 2003 environment. These steps are not necessary in a Win…
This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
Visualize your data even better in Access queries. Given a date and a value, this lesson shows how to compare that value with the previous value, calculate the difference, and display a circle if the value is the same, an up triangle if it increased…
How to fix incompatible JVM issue while installing Eclipse While installing Eclipse in windows, got one error like above and unable to proceed with the installation. This video describes how to successfully install Eclipse. How to solve incompa…

715 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question