Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

How can the right of removing computers from a domain can be given to a group of users?

Posted on 2009-04-09
2
Medium Priority
?
235 Views
Last Modified: 2012-05-06
How can the right of removing computers from a domain can be given to a group of users? I have noticed that local administrator is able to remove computers from the domain, however once the computer is remove AD is not aware of the change so the computer is not removed or any Red X appears either.

I have also notice that if a regular user (domain user) does it the computer does not get removed but a Red X appears on AD for that specific computer. Same happen if the user if domain user is added to the local admin on that particular workstation.

I know a domain user byt default is able to join up to 10 machines to the domain. But would a domain by default a regular user account able to separte a computer account from the domain?

If not how would it be possible to allow the members of a Security Group to be able to remove computers from AD (add them to a workgroup), so when the computer gets removed from that domain the Red X will appear on AD.

0
Comment
Question by:llarava
2 Comments
 
LVL 47

Accepted Solution

by:
Donald Stewart earned 1500 total points
ID: 24111882
0
 

Author Comment

by:llarava
ID: 24185175
dstewartjr:

I have tried but it didn't work.

How do you disjoin a computer from your domain, in other words what user account does your helpdesk/analyst has on AD.
A regular users can't disjoin a computer from AD. But a local admin user could do it, if that is the case I have notice that the computer account will not be shown as DISABLED.

So far using delegation over the Computer OU does not give the right to the user to disjoin the computer from AD (right click my computer and when going to CHANGE it's grey out.

In order to do that what level of access does your user account has when disjoining the compt accout from the domain?


0

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Wouldn't it be nice if objects in Active Directory automatically moved into the correct Organizational Units? This is what AutoAD aims to do and as a plus, it automatically creates Sites, Subnets, and Organizational Units.
It’s time for spooky stories and consuming way too much sugar, including the many treats we’ve whipped for you in the world of tech. Check it out!
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

571 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question