Go Back   TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags: , , , ,

Sponsored Links



User suddenly can no longer 'join workstation to the domain' denied

Active Directory


Reply
 
Thread Tools Search this Thread
  #1  
Old 15-01-2010
Mr Troy
 
Posts: n/a
User suddenly can no longer 'join workstation to the domain' denie

Hi,

We have a 2003SP2/2008R2 environment. We have a specific account we use in
a script to automatically join the workstation to the domain.

The account has rights via a group...the group is listed in the domain
policy to "allow join workstations to the domain." Any other account in that
group works fine when joining PCs to the domain.

The account in the script receives the "access denied" pop-up when joining
to a domain.

Anyone ever seen and resolve a similar issue?

Thank you,
Mr Troy
Reply With Quote
  #2  
Old 15-01-2010
Meinolf Weber [MVP-DS]
 
Posts: n/a
Re: User suddenly can no longer 'join workstation to the domain' denie

Hello Mr Troy,

See if one of these applies:
http://support.microsoft.com/kb/243327/en-us

http://support.microsoft.com/kb/932455

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> Hi,
>
> We have a 2003SP2/2008R2 environment. We have a specific account we
> use in a script to automatically join the workstation to the domain.
>
> The account has rights via a group...the group is listed in the domain
> policy to "allow join workstations to the domain." Any other account
> in that group works fine when joining PCs to the domain.
>
> The account in the script receives the "access denied" pop-up when
> joining to a domain.
>
> Anyone ever seen and resolve a similar issue?
>
> Thank you,
> Mr Troy



Reply With Quote
  #3  
Old 15-01-2010
Paul Bergson [MVP-DS]
 
Posts: n/a
Re: User suddenly can no longer 'join workstation to the domain' denie

Has the password expired?

--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4
Microsoft's Thrive IT Pro of the Month - June 2009

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup This
posting is provided "AS IS" with no warranties, and confers no rights.

"Mr Troy" <MrTroy@discussions.microsoft.com> wrote in message
news:CCEEAF94-75DF-4A9C-BCB9-555BDF7FAEC5@microsoft.com...
> Hi,
>
> We have a 2003SP2/2008R2 environment. We have a specific account we use
> in
> a script to automatically join the workstation to the domain.
>
> The account has rights via a group...the group is listed in the domain
> policy to "allow join workstations to the domain." Any other account in
> that
> group works fine when joining PCs to the domain.
>
> The account in the script receives the "access denied" pop-up when joining
> to a domain.
>
> Anyone ever seen and resolve a similar issue?
>
> Thank you,
> Mr Troy



Reply With Quote
  #4  
Old 15-01-2010
Mr Troy
 
Posts: n/a
RE: User suddenly can no longer 'join workstation to the domain' denie

Hi Paul,

Password is set to never expire and I can login to the domain with that
account.


Hi Meinolf,

I'll give the Delegation Wizard a shot-thank you.

Thing is, I don't understand why the account stopped working. Yes, there's
a 10 max computer accounts per user, but with the user account in a group
that is listed in the Domain Controller Policy to allow "add workstation to
the domain," I thought that should circumvent the limit of 10. It had been
working for at least 4 years and then "POOF" it stopped working with no rhyme
or reason.

Very strange,
Mr Troy
Reply With Quote
  #5  
Old 15-01-2010
kj [SBS MVP]
 
Posts: n/a
Re: User suddenly can no longer 'join workstation to the domain' denie

Mr Troy wrote:
> Hi Paul,
>
> Password is set to never expire and I can login to the domain with
> that account.


I'd rather delegate the right to the OU.

http://technet.microsoft.com/en-us/l...64(WS.10).aspx

The Add Workstation to Domain user right is supported for applications that
use earlier SAM (Security Accounts Manager) NET APIs to create computer
accounts. Users that have this right are allowed to create 10 computer
accounts in the Active Directory Computers container using these earlier
APIs. When a user creates a computer account using this user right, the
Domain Admins group becomes the owner of the computer object. Note that this
right is not recognized when LDAP is used to create computer accounts.

In Windows 2000 and later, the recommended way to allow a user or group to
create computer accounts is by granting that user or group the permission to
Create Computer Objects on the desired container. This can be accomplished
in GPMC. When a computer account is created using access control
permissions, the actual creator of the object becomes the owner of that
object.
>
>
> Hi Meinolf,
>
> I'll give the Delegation Wizard a shot-thank you.
>
> Thing is, I don't understand why the account stopped working. Yes,
> there's a 10 max computer accounts per user, but with the user
> account in a group that is listed in the Domain Controller Policy to
> allow "add workstation to the domain," I thought that should
> circumvent the limit of 10. It had been working for at least 4 years
> and then "POOF" it stopped working with no rhyme or reason.
>
> Very strange,
> Mr Troy


--
/kj


Reply With Quote
  #6  
Old 16-01-2010
Mr Troy
 
Posts: n/a
User suddenly can no longer 'join workstation to the domain' denied

I haven't yet tested the Delegation piece. Will do that shortly.

In the meantime, I was able to get the user account to work once again-IF
it's both in the group and added as a user to the GPO "add workstation to the
domain."

Could've sworn I tried that yesterday, but I must have removed the account
from the group and added it separately.

Thank you everyone for your input...it is very helpful!

Mr. Troy
Reply With Quote
Reply

  TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory


Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads for: "User suddenly can no longer 'join workstation to the domain' denied"
Thread Thread Starter Forum Replies Last Post
Adding domain user to a Windows 7 laptop: The trust relationship between this workstation and the primary domain failed. Doumbia Operating Systems 5 11-08-2010 01:30 PM
Windows XP workstation cannot join 2003 Domain toddfugere Networking & Security 4 07-01-2010 08:52 PM
User dis-join from domain, how to re-join again Newbie Active Directory 6 18-03-2009 09:35 AM
Minimum security settings of computer accounts for allowing domain user account to join domain M C Active Directory 2 18-08-2008 11:17 PM
Access Denied when trying to join a server to the domain Matty Active Directory 2 14-12-2007 02:29 PM


All times are GMT +5.5. The time now is 09:44 PM.