Link to home
Start Free TrialLog in
Avatar of Wibble_
Wibble_

asked on

Configure admin account to have permissions to join machines to domain, but nothing else. Possible?

We have sysprep'd  a VM image that automatically (via sysprep.inf) joins the new VM's to the domain using a cloned domain admin account

at the the moment it has full admin privileges.

Is it possible to configure this user account to ONLY be able to join machines to the domain, and NOTHING else?

(worth doing as the hash of the pass is in the sysprep.ini file, & NTLM rainbow tables are getting quite complete these days.)

W.
Avatar of Jay_Jay70
Jay_Jay70
Flag of Australia image

Hi Wibble_,

you can try using the delegation of control wizard in AD under the OU where the user account resides
ASKER CERTIFIED SOLUTION
Avatar of CoccoBill
CoccoBill
Flag of Finland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial