Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Unable to re-add laptops to domain

Posted on 2013-05-14
1
Medium Priority
?
2,272 Views
Last Modified: 2013-05-19
Hi,


I have a whole bunch of laptops which are currently being re-imaged at the moment. Once this process is complete the next step is to add them to the domain using a temporary account which I have delegated access to join machines to the domain but I am getting an error message:

“The Join Operation was not successfully. This could be because an existing computer having name “XXXXXXX” was previously created using a different set of credentials. Use a different computer name or contact your administrator to remove any stale conflicting account. To the error was Access is denied”

The laptop accounts are still in their respective OUs and I have deleted one of the computer objects from the domain assuming that it conflicts with the same laptop name which associates to a unique SID but unfortunately I still get the same issue.

I have no issue re-joining the laptop to the domain if I use my own account which has Domain Admin rights.

I delegated the following permissions:

 - Create selected objects in this folder and Delete selected objects in this folder.
 -  Reset Password
 -  Read and write Account Restrictions
 -   Validated write to DNS host name
 -  Validated write to service principal name

Essentially I want to give this account the very minimal amount of permissions to simply re-add these computer accounts to the domain


Any help would be greatly appreciated
0
Comment
Question by:dcirona86
1 Comment
 
LVL 24

Accepted Solution

by:
Nagendra Pratap Singh earned 2000 total points
ID: 39167068
The full list would be
   
Create Computer Objects
    Delete Computer Objects

    Read All Properties
    Write All Properties
    Read Permissions
    Modify Permissions
    Change Password
    Reset Password
    Validated write to DNS host name
    Validated write to service principle name

http://jonconwayuk.wordpress.com/2011/10/20/minimum-permissions-required-for-account-to-join-workstations-to-the-domain-during-deployment/
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When you try to extract and to view the contents of a Microsoft Update Standalone Package (MSU) for Windows Vista, you cannot extract the files from the MSU. Here we are going to explain how to extract those hotfix details without using any third pa…
A quick guide on how to use Group Policy to create a custom power plan and set it active on Windows 7.
This Micro Tutorial will teach you how to the overview of Microsoft Security Essentials. This is a free anti-virus software that guards your PC against viruses, spyware, worms, and other malicious software. This will be demonstrated using Windows…
This Micro Tutorial will give you a basic overview of Windows DVD Burner through its features and interface. This will be demonstrated using Windows 7 operating system.
Suggested Courses

916 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question