• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 203
  • Last Modified:

Configure admin account to have permissions to join machines to domain, but nothing else. Possible?

We have sysprep'd  a VM image that automatically (via sysprep.inf) joins the new VM's to the domain using a cloned domain admin account

at the the moment it has full admin privileges.

Is it possible to configure this user account to ONLY be able to join machines to the domain, and NOTHING else?

(worth doing as the hash of the pass is in the sysprep.ini file, & NTLM rainbow tables are getting quite complete these days.)

1 Solution
Hi Wibble_,

you can try using the delegation of control wizard in AD under the OU where the user account resides
Create a normal user and delegate the add workstations to domain privilege to that user: http://www.jsifaq.com/SUBQ/tip8100/rh8144.htm

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now