Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Mini per to join computers to domain

Posted on 2015-01-27
4
Medium Priority
?
261 Views
Last Modified: 2015-01-28
Hello Expert,
I have a temporary person technician that comes in once in a while to do work for us.I want to assign him with the permission to join computers into our domain and remove the computers from our domain, no other access rights.
I use windows 2008 Domain Controller.

This is what I've done so far...
1 - created a user account for the technician.
2 - On the top domain name in Active Directory i right click and selected Delegation control wizard and Added that user into the delegate control.
3 - From the Delegate common tasks i selected only "Join a computer to the domain"
4- finish

I have tested the above configuration and came to understand that the user is not able to join computers into the domain,This is where I'm stuck... I want to know what else permissions i needed to assign to this user so that he can only join computers into our domain and Absolutely no other permissions

Waiting for your support.
Thank you.
0
Comment
Question by:smpvm
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 24

Accepted Solution

by:
VB ITS earned 2000 total points
ID: 40574784
There's a few extra permissions you need to enable. You also need to use the delegate control wizard on the Computers container as this is where the computer object gets created when a machine joins the domain.

- In Active Directory Users and Computers, right click on the Computers container and then click Delegate Control..
- Click Add to add the account you created for your technician
- Select Create a custom task to delegate in the next window
- Select Only the following objects in the folder then tick the Computer objects box in the list
- Tick both the Create selected objects in this folder and Delete selected objects in this folder boxes
 
- In the next window tick these options under Show these permissions:
- General
- Property-specific
- In the Permissions box tick these options:
- Reset Password
- Read and write account restrictions
- Validated write to DNS host name
- Validated write to service principal name
Delegate-Control---Permissions-1.pngDelegate-Control---Permissions-2.png- Click Next then Finish when done
- Now try joining a computer to the domain
0
 

Author Comment

by:smpvm
ID: 40574950
Hello VB ITS,

You are the real Expert, perfect. It is working fine. Everyone happy with my solution infact the credit goes to you :)

Regards
0
 

Author Closing Comment

by:smpvm
ID: 40574951
Best solution
0
 
LVL 24

Expert Comment

by:VB ITS
ID: 40574960
Thanks smpvm! Happy to help :)
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Issue: One Windows 2008 R2 64bit server on the network unable to connect to a buffalo Device (Linkstation) with firmware version 1.56. There are a total of four servers on the network this being one of them. Troubleshooting Steps: Connect via h…
New Windows 7 Installations take days for Windows-Updates to show up and install. This can easily be fixed. I have finally decided to write an article because this seems to get asked several times a day lately. This Article and the Links apply to…
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

636 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question