[Last Call] Learn how to a build a cloud-first strategyRegister Now


How to restrict security level to linking of clients to domain only?

Posted on 2004-11-18
Medium Priority
Last Modified: 2010-03-18
We are running a network with Windows 2000 Server. We need that one of our technicians has only enough security level to link clients to the domain, but nothing else. Is that possible to do and if yes, how?
Question by:Erwin Krisch
  • 3
  • 2

Expert Comment

ID: 12613889
So he needs to be able to create computer accounts then?  I take it one technitian will create the user account and settings, and then the restricted tech will go to the desktop and join it to the domain?

It can be done, he needs the "add workstation to domain" access right.  Create the tech as a normal user, then open Domain Security Policy. Go to Local Policies, User rights assignment.  Near the top is the Add workstation to domain right.  Enable the right and add the tech's username to the list.

Browse the other rights to see if he will need any other functions, but that should allow him to join a computer to the domain, and create the computer account using his logon details and not an admins.

Author Comment

by:Erwin Krisch
ID: 12615135
“ I take it one technitian will create the user account and settings, and then the restricted tech will go to the desktop and join it to the domain?”

Yes, the above is correct. But will he still have the ability to make other changes on the network like: creating accounts, changing security levels and sharing rights or deleting computers from the network? I hope not. This is a very basic technician who does not know much about networking. All we do is that when we get new clients, we let him wander around and access the local administrator accounts and then link the computers to the domain. Any other rights he should not have other than using his account to do the linking business as aforementioned.

Author Comment

by:Erwin Krisch
ID: 12628585
I tried the above. But it doesn't work. I created the user, loged on on the client as a local administrator trried to join the client to the domain as the new user, but it tells me acess denied.

Expert Comment

ID: 12654297
You may also need to set the access under the Domain Controller Security policy.  On a DC there are 3 different areas to set various rights.

The local Group policy, the domain security policy and the domain controller policy.  Set this setting on each of these, and it should work.

There may be another right needed, but I'm pretty sure there is only the one, but it certainly is possible, and no he will not be able to do any other administrative things, other than those he has rights to.


Accepted Solution

SKULLS_Hawk earned 700 total points
ID: 12654407
Finally found the article I was thinking of.  There are other rights needed.  Method 2 on the below article I believe will sort it for you.


Featured Post

Get free NFR key for Veeam Availability Suite 9.5

Veeam is happy to provide a free NFR license (1 year, 2 sockets) to all certified IT Pros. The license allows for the non-production use of Veeam Availability Suite v9.5 in your home lab, without any feature limitations. It works for both VMware and Hyper-V environments

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Have you ever set up your wireless router at home or in the office to find that you little pop-up bubble in the bottom right-hand corner of Windows read "IP Conflict - One of more computers on the network have been assigned the following IP address"…
Resolve DNS query failed errors for Exchange
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
Please read the paragraph below before following the instructions in the video — there are important caveats in the paragraph that I did not mention in the video. If your PaperPort 12 or PaperPort 14 is failing to start, or crashing, or hanging, …

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question