Add workstation to Domain

G

George Spiro

Hi,

I am looking first of all to block all domain users to add machines to the
domain. I do not want to allow anyone besides Domain Admins and one other
account to add machines to the domain.

So the other is where do I need to configure to allow this user to add
machines to the domain. This user will be like a service account i do not
want to give him login privileges. Will be used with SMS and BDD.

I am slightly confused regarding local security policy, domain security
policy, domain controler security policy.

Thanks for your help,

George
 
S

steamfish

George said:
Hi,

I am looking first of all to block all domain users to add machines to the
domain. I do not want to allow anyone besides Domain Admins and one other
account to add machines to the domain.

So the other is where do I need to configure to allow this user to add
machines to the domain. This user will be like a service account i do not
want to give him login privileges. Will be used with SMS and BDD.

I am slightly confused regarding local security policy, domain security
policy, domain controler security policy.

Thanks for your help,

George
 
G

Greg O

This is explained in detail in "Mastering Windows Server 2003" by Mark
Minasi Chapter 5.

"But you can change that. If you like, you can create a whole new group
called Installers. Then we'll
give the group the power to change machine passwords and delete machine
accounts."
 
G

George Spiro

I dont see the value Create Computer Object, I got only Create global
objects.
 
S

Steven L Umbach

Where are you seeing create global objects?? Anyhow go to the advanced page
of the security page of the Active Directory container [using Active
Directory Users and Computers] that you want to give the user/group
permissions to and then you should see create computer objects when you add
or edit a user/group in the access control list.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top