Solved

Add workstation to a domain

Posted on 2010-09-06
2
955 Views
Last Modified: 2012-05-10
Windows Server 2008 question:
I need the user to log on to a domian without having a computer predefined in AD
I think it is the "Add workstation to domain" policy that i'm looking after. It is set to "Authenticated Users" but the user can't log on to the domain without having a predefined computer in AD.
0
Comment
Question by:B-data
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 7

Expert Comment

by:Waseems
ID: 33613481
when computer is joined to domain computer account is created under computers container you will have to delegate the user to create computer account under this container
0
 
LVL 7

Accepted Solution

by:
Mohamed Khairy earned 500 total points
ID: 33613995
Hi B-data,

There are a big confusions here, You need the user to log on to a domian without having a computer predefined in AD and this is the normal situation, anyone that have a domain user credentials can log on to the rdomain from any joined computer on the network and there are no needs to create computer acount first.

So please explain more your problem as I understood from Waseems's answer that you need to delegate a sufficent right to an ordinary user to join computers to the domain and if this is what you need so read the below carefully:

By default, any authenticated user has the right to join computers and can create up to 10 computer accounts in the domain and to accomplish your request, you have to delegate the appropriate user rights through the Active Directory Users and Computers console as previously explained on Wassems's comments but you have to take care from the permission step because you may receive the access denied error message.

Here are the detailed steps as came in Microsoft article: http://support.microsoft.com/kb/932455


1- Click Start, click Run, type dsa.msc, and then click OK.

2- In the task pane, expand the domain node.

3- Locate and right-click the OU that you want to modify, and then click Delegate Control.

4- In the Delegation of Control Wizard, click Next.

5- Click Add to add a specific user or a specific group to the Selected users and groups list, and then click Next.

6- In the Tasks to Delegate page, click Create a custom task to delegate, and then click Next.

7- Click Only the following objects in the folder, and then from the list, click to select the Computer objects check box. Then, select the check boxes below the list, Create selected objects in this folder and Delete selected objects in this folder.

8- Click Next.

9- In the Permissions list, click to select the following check boxes:

- Reset Password
- Read and write Account Restrictions
- Validated write to DNS host name
- Validated write to service principal name

10- Click Next, and then click Finish.

11- Close the "Active Directory Users and Computers" MMC snap-in

Wish this may help.

Regards,
MKhairy


0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article explains the steps required to use the default Photos screensaver to display branding/corporate images
Auditing domain password hashes is a commonly overlooked but critical requirement to ensuring secure passwords practices are followed. Methods exist to extract hashes directly for a live domain however this article describes a process to extract u…
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…

737 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question