?
Solved

cant join domain

Posted on 2005-04-01
6
Medium Priority
?
279 Views
Last Modified: 2010-04-13
imagine i have created account A with admin rights and used it for a period of time.but now i remove the admin rights from tha account. but i still want this account be able to add pcs to the domain.i already add this user in the active directorys user and computers with the rights to add pcs to the domain. when i add a new pc to domain it sure does, but if i want to re add a pc in the domain, it gives me an error with access denied. i think is because the account dont have the rights to overwrite certain files or something in the AD, so i need to know what kind of rights and where to set it. i already gave the right to create and delete objects in AD.
0
Comment
Question by:matutolas
  • 3
  • 3
6 Comments
 
LVL 16

Accepted Solution

by:
JamesDS earned 500 total points
ID: 13679650
matutolas
As well as join domain, you also need to grant a few other rights to allow the computer account to be reset.

On computer objects only:
Create/Delete
Reset Password

You might also need these ones as well:
Read All/Write All
Validated write to DNS Host Name
Validated write to Service Principle Name

Cheers

JamesDS
0
 
LVL 1

Author Comment

by:matutolas
ID: 13694481
JamesDS

where can i find the reset password option? and if i give this writes to the user can he reset the admin password?? where can i find the options to validate the write to dns host name and the service principle name?? im using dhcp to give ips so i supose when i add the abject in the domain the dns will automatically change.

thanks matutolas
0
 
LVL 16

Expert Comment

by:JamesDS
ID: 13695348
matutolas
The rights to make changes to objects on the domain are modified using the Active Directory Users and Computers Tool.

Open the tool, switch on advanced mode (View/advanced features)
Select the OU containing the objects you wish to apply the new security too.
Rightclick and select properties/security/advanced.
Hit add and select the group or users you wish to give the rights too.

In the apply onto window, select computers and scroll down the list to find the rights I mentioned earlier.

Pay attention to the other options within this dialog and be very careful as AD permissioning is easy to screw up!

voila!

Cheers

JamesDS
0
Get expert help—faster!

Need expert help—fast? Use the Help Bell for personalized assistance getting answers to your important questions.

 
LVL 1

Author Comment

by:matutolas
ID: 13695794
JamesDS

im sorry my ingorance, but i dont see the resent password option there, i just add two permissions for the user, add and delete computer objects, and nothing else. like i said the user is able to add pcs to domain if there is no record before from the same pc. and im concerning about the read all and write all permission. will that permission have any impact if the user want to arm the network??

thanks a lot

matutolas
0
 
LVL 16

Expert Comment

by:JamesDS
ID: 13696185
matutolas
You need to set the Apply Onto window to computer objects. The reset password right is near the bottom (4th one up on my domain).

These rights are set on an OU or at the domain root.

Cheers

JamesDS
0
 
LVL 1

Author Comment

by:matutolas
ID: 13734806
JamesDS

i know i already accept your answer, but today i found another problem related with my question, i already gave all the permissions that you said. imagine in my AD i have a object with name XXX and i try to join into the domain with another pc with name XXX but with diferent SID, what permissons do i have to give for that?

thanks

matutolas
0

Featured Post

Keep up with what's happening at Experts Exchange!

Sign up to receive Decoded, a new monthly digest with product updates, feature release info, continuing education opportunities, and more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
Why WooCommerce is one of the majorly favored choices when it comes to having an eCommerce store. This article will acquaint you with some reasons that I believe make it one of the best eCommerce platforms available.
Is your OST file inaccessible, Need to transfer OST file from one computer to another? Want to convert OST file to PST? If the answer to any of the above question is yes, then look no further. With the help of Stellar OST to PST Converter, you can e…
Enter Foreign and Special Characters Enter characters you can't find on a keyboard using its ASCII code ... and learn how to make a handy reference for yourself using Excel ~ Use these codes in any Windows application! ... whether it is a Micr…
Suggested Courses
Course of the Month9 days, 14 hours left to enroll

571 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question