Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

How can the right of removing computers from a domain can be given to a group of users?

Posted on 2009-04-09
2
Medium Priority
?
232 Views
Last Modified: 2012-05-06
How can the right of removing computers from a domain can be given to a group of users? I have noticed that local administrator is able to remove computers from the domain, however once the computer is remove AD is not aware of the change so the computer is not removed or any Red X appears either.

I have also notice that if a regular user (domain user) does it the computer does not get removed but a Red X appears on AD for that specific computer. Same happen if the user if domain user is added to the local admin on that particular workstation.

I know a domain user byt default is able to join up to 10 machines to the domain. But would a domain by default a regular user account able to separte a computer account from the domain?

If not how would it be possible to allow the members of a Security Group to be able to remove computers from AD (add them to a workgroup), so when the computer gets removed from that domain the Red X will appear on AD.

0
Comment
Question by:llarava
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 47

Accepted Solution

by:
Donald Stewart earned 1500 total points
ID: 24111882
0
 

Author Comment

by:llarava
ID: 24185175
dstewartjr:

I have tried but it didn't work.

How do you disjoin a computer from your domain, in other words what user account does your helpdesk/analyst has on AD.
A regular users can't disjoin a computer from AD. But a local admin user could do it, if that is the case I have notice that the computer account will not be shown as DISABLED.

So far using delegation over the Computer OU does not give the right to the user to disjoin the computer from AD (right click my computer and when going to CHANGE it's grey out.

In order to do that what level of access does your user account has when disjoining the compt accout from the domain?


0

Featured Post

Learn Veeam advantages over legacy backup

Every day, more and more legacy backup customers switch to Veeam. Technologies designed for the client-server era cannot restore any IT service running in the hybrid cloud within seconds. Learn top Veeam advantages over legacy backup and get Veeam for the price of your renewal

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Did you know that more than 4 billion data records have been recorded as lost or stolen since 2013? It was a staggering number brought to our attention during last week’s ManageEngine webinar, where attendees received a comprehensive look at the ma…
This process allows computer passwords to be managed and secured without using LAPS. This is an improvement on an existing process, enhanced to store password encrypted, instead of clear-text files within SQL
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…

661 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question