Solved

Allow only desktop administrators to "add workstations to a domain" but prevent them from adding servers to the 2003 domain??

Posted on 2004-10-02
2
217 Views
Last Modified: 2010-04-19
Allow only desktop administrators to "add workstations to a domain" but how can prevent them from adding Windows 2000/2003 servers to the 2003 domain??
0
Comment
Question by:cmkmfg
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 104

Expert Comment

by:Sembee
ID: 12212557
I don't think you can. The domain will not know what sort of system the machine is until after it has joined.

Simon.
0
 
LVL 16

Accepted Solution

by:
JamesDS earned 250 total points
ID: 12215374
cmkmfg
The permissions you are seeking are not possible.

The permissions needed to join a workstation to the domain is essentially, create machine account, reset machine account password and reset DNS name on machine account.

A machine account is the same for Workstation and Server and is not identified as a server until it logs in for the first time (ie first reboot after a successful join).

If you store servers and workstations in different OUs you could limit addition of new computer accounts to the Servers OU, but that wouldn't stop servers being put into the wrong OU.

Cheers

JamesDS
0

Featured Post

10 Questions to Ask when Buying Backup Software

Choosing the right backup solution for your organization can be a daunting task. To make the selection process easier, ask solution providers these 10 key questions.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The HP utility "HP Lights-Out Online Configuration Utility for Windows Server 2003/2008" could be of great use when it comes to remotely configure a HP servers ILO WITHOUT rebooting the server. We would only need to create and run scripts using thi…
I guess it is not common knowledge to most Wintel engineers/administrators: If you have an SNMP-based monitoring system in your environment (and it's common to have SNMP or Syslog) it's reasonably easy to enable monitoring of the Windows Event logs,…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Add bar graphs to Access queries using Unicode block characters. Graphs appear on every record in the color you want. Give life to numbers. Hopes this gives you ideas on visualizing your data in new ways ~ Create a calculated field in a query: …

621 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question