?
Solved

Add workstation to a domain

Posted on 2010-09-06
2
Medium Priority
?
964 Views
Last Modified: 2012-05-10
Windows Server 2008 question:
I need the user to log on to a domian without having a computer predefined in AD
I think it is the "Add workstation to domain" policy that i'm looking after. It is set to "Authenticated Users" but the user can't log on to the domain without having a predefined computer in AD.
0
Comment
Question by:B-data
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 7

Expert Comment

by:Waseems
ID: 33613481
when computer is joined to domain computer account is created under computers container you will have to delegate the user to create computer account under this container
0
 
LVL 7

Accepted Solution

by:
Mohamed Khairy earned 2000 total points
ID: 33613995
Hi B-data,

There are a big confusions here, You need the user to log on to a domian without having a computer predefined in AD and this is the normal situation, anyone that have a domain user credentials can log on to the rdomain from any joined computer on the network and there are no needs to create computer acount first.

So please explain more your problem as I understood from Waseems's answer that you need to delegate a sufficent right to an ordinary user to join computers to the domain and if this is what you need so read the below carefully:

By default, any authenticated user has the right to join computers and can create up to 10 computer accounts in the domain and to accomplish your request, you have to delegate the appropriate user rights through the Active Directory Users and Computers console as previously explained on Wassems's comments but you have to take care from the permission step because you may receive the access denied error message.

Here are the detailed steps as came in Microsoft article: http://support.microsoft.com/kb/932455


1- Click Start, click Run, type dsa.msc, and then click OK.

2- In the task pane, expand the domain node.

3- Locate and right-click the OU that you want to modify, and then click Delegate Control.

4- In the Delegation of Control Wizard, click Next.

5- Click Add to add a specific user or a specific group to the Selected users and groups list, and then click Next.

6- In the Tasks to Delegate page, click Create a custom task to delegate, and then click Next.

7- Click Only the following objects in the folder, and then from the list, click to select the Computer objects check box. Then, select the check boxes below the list, Create selected objects in this folder and Delete selected objects in this folder.

8- Click Next.

9- In the Permissions list, click to select the following check boxes:

- Reset Password
- Read and write Account Restrictions
- Validated write to DNS host name
- Validated write to service principal name

10- Click Next, and then click Finish.

11- Close the "Active Directory Users and Computers" MMC snap-in

Wish this may help.

Regards,
MKhairy


0

Featured Post

Veeam Disaster Recovery in Microsoft Azure

Veeam PN for Microsoft Azure is a FREE solution designed to simplify and automate the setup of a DR site in Microsoft Azure using lightweight software-defined networking. It reduces the complexity of VPN deployments and is designed for businesses of ALL sizes.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Always backup Domain, SYSVOL etc.using processes according to Microsoft Best Practices. This is meant as a disaster recovery process for small environments that did not implement backup processes and did not run a secondary domain controller that ne…
Let's recap what we learned from yesterday's Skyport Systems webinar.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…
Suggested Courses
Course of the Month10 days, 10 hours left to enroll

765 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question