Permissions to add/remove computer accounts from domain

Hi

We are running Windows 2003 AD.

I have an OU named StudentComputers.

I would like to give the Student Admins (security group: StudentAdmins) permission to add computers to the domain within the StudentComputers OU. There will be in excess of 100 computers they will be adding to the domain.

I've checked this link here:

http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/Windows_2000_Active_Directory/Q_23124549.html

But not sure if the info has changed.

Can anyone advise how I can do this, if I go to Delegate Control Wizard of the StudentComputers OU, then there is nothing to Add/Remove computers from Domain?

Any help appreciated!
LVL 3
kam_ukAsked:
Who is Participating?
 
Mike ThomasConnect With a Mentor ConsultantCommented:
Somewhat yes I just had to look this up to check as its been a while.

This article may help

http://blogs.technet.com/jhoward/archive/2005/04/18/403817.aspx

Adding permssions to the OU will ensure that the Admin you want can move objects to the desired OU but you may want to add more permssions to allow them to manage those objects.


0
 
Mike ThomasConsultantCommented:
You can select the advanced view in AD Users and Computers and set permission using the security tab
0
 
kam_ukAuthor Commented:
Thanks, but still can't see it?
0
Making Bulk Changes to Active Directory

Watch this video to see how easy it is to make mass changes to Active Directory from an external text file without using complicated scripts.

 
Mike ThomasConsultantCommented:
"Create all child objects" is the permission you need to set on the OU, you may need to add the permission to the default computers container if you have no build process that creates the computer object on the correct OU.
0
 
kam_ukAuthor Commented:
"Create all child objects" ah ok, so this actually gives the permission to add objects to the domain?

Thanks again.
0
 
FemSteenkampConnect With a Mentor Commented:
If you delegate the the create computer objects ( under  Create all child objects) to the Student Admins, they can bypass the need for increasing the limit of joining computers to the domain by prestaging the computer account in AD (create computer object in AD before the computer is joined to teh domain) Then when you join the computer to the domain, it will find a computer object already exists within ad , with the same name, and associate the joining computer to that account. This way they can use the default "join to domain" wizard.

if just the deligation is done, you will have to use scripts (vbscript/powershell, or tools like NETDOM) to specify in which lcation (OU)  the newly added computer needs to be placed, if no location provided all newly joined machines will be in default location ( at install time is computers, but this location can be changed as a new default for all joining computers to domain)
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.