Solved

How can the right of removing computers from a domain can be given to a group of users?

Posted on 2009-04-09
2
226 Views
Last Modified: 2012-05-06
How can the right of removing computers from a domain can be given to a group of users? I have noticed that local administrator is able to remove computers from the domain, however once the computer is remove AD is not aware of the change so the computer is not removed or any Red X appears either.

I have also notice that if a regular user (domain user) does it the computer does not get removed but a Red X appears on AD for that specific computer. Same happen if the user if domain user is added to the local admin on that particular workstation.

I know a domain user byt default is able to join up to 10 machines to the domain. But would a domain by default a regular user account able to separte a computer account from the domain?

If not how would it be possible to allow the members of a Security Group to be able to remove computers from AD (add them to a workgroup), so when the computer gets removed from that domain the Red X will appear on AD.

0
Comment
Question by:llarava
2 Comments
 
LVL 47

Accepted Solution

by:
Donald Stewart earned 500 total points
ID: 24111882
0
 

Author Comment

by:llarava
ID: 24185175
dstewartjr:

I have tried but it didn't work.

How do you disjoin a computer from your domain, in other words what user account does your helpdesk/analyst has on AD.
A regular users can't disjoin a computer from AD. But a local admin user could do it, if that is the case I have notice that the computer account will not be shown as DISABLED.

So far using delegation over the Computer OU does not give the right to the user to disjoin the computer from AD (right click my computer and when going to CHANGE it's grey out.

In order to do that what level of access does your user account has when disjoining the compt accout from the domain?


0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This script can help you clean up your user profile database by comparing profiles to Active Directory users in a particular OU, and removing the profiles that don't match.
This article shows how to deploy dynamic backgrounds to computers depending on the aspect ratio of display
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now