troubleshooting Question

Join computer to domain but can't logon to computers

Avatar of twcadmin
twcadmin asked on
Windows Server 2003Active DirectoryOS Security
4 Comments3 Solutions545 ViewsLast Modified:
How do I create a user that can join a computer to the domain but can't logon to any computers?

I want to create a user for sysprep to use to join the computer to the domain but I don't want this user able to do anything else. I already added the user to "Add workstations to domain" right in the default group policy so all thats left is not letting the user log on. Is this possible? My first guess would be to add the user to "Deny logon locally" user right but would this prevent them from joining the computer to the domain? Can anyone suggest anything else to secure the account?

Our community of experts have been thoroughly vetted for their expertise and industry experience.

Join our community to see this answer!
Unlock 3 Answers and 4 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 3 Answers and 4 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros