Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

active directory delegation control

Posted on 2014-03-21
2
Medium Priority
?
337 Views
Last Modified: 2014-03-27
We configure active directory delegation control for particular user to join a computer to domain.
If we add a new computer to domain then it successfully join to domain. But if same computer remove form domain and rejoin again we are getting error. Please find attachment for screen shot.
Same I was doing in administrator account this computer was re- join to domain. There is something delegation issue. Please help me to resolve this issue.
Error.jpg
0
Comment
Question by:rsbgroup
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 37

Expert Comment

by:Mahesh
ID: 39944979
Two things you need to do:

In addition to delegation, in Default domain policy GPO, grant same user \ group "add workstation to domain" user rights and then run gpupdate /force on DC, may be DC reboot is more useful.
Now you can try rejoining existing accounts, it should work
If still you face issues, try below.
When you rejoin same computer to domain again, 1st reset its existing computer account in active directory by right clicking it and click on reset computer
This will reset its existing binding by resetting its secure channel
Then hopefully you can able to rejoin same computer account again

Mahesh
0
 
LVL 5

Accepted Solution

by:
Arjun Vyavahare earned 1000 total points
ID: 39944992
Hi,

Suggestion you to refer below link, which has given step by step screenshot based information along with the solution:

http://chentiangemalc.wordpress.com/2012/07/27/case-of-the-domain-join-failure/

I hope this will solve your issue.

Regards,
Arjun
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
How to deal with a specific error when using the Enable-RemoteMailbox cmdlet to create a mailbox in the cloud-based service, for an existing user in an on-premises Active Directory.
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Suggested Courses

664 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question