Go Back   TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags: ,

Sponsored Links



Default Computer OU permissions

Active Directory


Reply
 
Thread Tools Search this Thread
  #1  
Old 10-11-2009
Glen
 
Posts: n/a
Default Computer OU permissions

I've been struggling with this for awhile so I'll ask for help.

Currently, the Computer OU is the default container where new computer
accounts are added. The problem is, I end up with all sorts of accounts
there and they are never moved to the right OU.

I would like to require that the computer account be created first, or at
least restrict access to the default Computers OU so new accounts can not be
created by non-domain admins.

I don't see anything security settings in the ACL that should allow accounts
to be created by non-admins but it still seems to be happening. The only
account that I think might be allowing this to happen is the System Account
which has Full Control but I"m leary to change the settings on that.

My goal is that if a new computer is added to the domain by a non-admin,
they would be restricted from adding the account and would have to contact
their administrator to manually make the account ahead of time.

Any help would be appreciated.

Thanks.
Reply With Quote
  #2  
Old 11-11-2009
Meinolf Weber [MVP-DS]
 
Posts: n/a
Re: Default Computer OU permissions

Hello Glen,

By default each domain user is able to add up to 10 computers to the domain,
check all your policies, start with Default domain controllers GPO.

Under Computer configuration, windows settings, security settings, local
policies, user rights assignment, in the right pane check "Add workstations
to the domain". By default authenticated users are listed there.

See also:
http://support.microsoft.com/kb/243327/en-us

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> I've been struggling with this for awhile so I'll ask for help.
>
> Currently, the Computer OU is the default container where new computer
> accounts are added. The problem is, I end up with all sorts of
> accounts there and they are never moved to the right OU.
>
> I would like to require that the computer account be created first, or
> at least restrict access to the default Computers OU so new accounts
> can not be created by non-domain admins.
>
> I don't see anything security settings in the ACL that should allow
> accounts to be created by non-admins but it still seems to be
> happening. The only account that I think might be allowing this to
> happen is the System Account which has Full Control but I"m leary to
> change the settings on that.
>
> My goal is that if a new computer is added to the domain by a
> non-admin, they would be restricted from adding the account and would
> have to contact their administrator to manually make the account ahead
> of time.
>
> Any help would be appreciated.
>
> Thanks.
>



Reply With Quote
  #3  
Old 11-11-2009
Florian Frommherz [MVP]
 
Posts: n/a
Re: Default Computer OU permissions

Howdie!

Glen schrieb:
> Currently, the Computer OU is the default container where new computer
> accounts are added. The problem is, I end up with all sorts of accounts
> there and they are never moved to the right OU.
>
> I would like to require that the computer account be created first, or at
> least restrict access to the default Computers OU so new accounts can not be
> created by non-domain admins.
>
> I don't see anything security settings in the ACL that should allow accounts
> to be created by non-admins but it still seems to be happening. The only
> account that I think might be allowing this to happen is the System Account
> which has Full Control but I"m leary to change the settings on that.


Yeah - what you noticed is correct. Users are allowed to join up to 10
machines to the domain (by default). They don't need to have admin privs
to do that. Meinolf already provided you with a link on how you can
disable that - or change the default number of machines they can add.
When setting the number to 0, I would also make sure a certain group of
people (let them be the Helpdesk, any 2nd level support folks..) have
the ability to create machine accounts other than you. You certainly
don't want to run and rush to join machines to the domain..

Another aproach that I've seen pretty often is using redircmp (and
redirusr). That let's you specify another default location - possibly an
OU, other than the "Computers" container that is built-in. Like that,
you could create a standard Group Policy newly joined machines apply.
I've seen folks link Software Installation policies or prep-scripts to
such an OU.

Cheers,
Florian
--
Microsoft MVP - Group Policy
eMail: prename [at] frickelsoft [dot] net.
blog: http://www.frickelsoft.net/blog.
ANY advice you get on the Newsgroups should be tested thoroughly in your
lab.
Reply With Quote
Reply

  TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory


Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads for: "Default Computer OU permissions"
Thread Thread Starter Forum Replies Last Post
Default groups and security permissions Xavier Active Directory 11 11-03-2010 11:12 PM
Restore/repair the default permissions in vista jean-paul martell Operating Systems 4 01-01-2010 10:30 PM
How to Restore Default Folder/Drive Permissions Paul Thomas Vista Help 5 27-06-2009 01:28 AM
Default file/folder security permissions for a new user renegade_master_12121@yahoo.co.uk Windows Security 3 14-01-2009 12:58 AM
default NTFS permissions - 2003 - vista PE? James Windows Security 4 25-11-2008 08:45 PM


All times are GMT +5.5. The time now is 05:17 PM.