Go Back   TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags: , ,

Sponsored Links



Delegate domain user permission to join domain

Active Directory


Reply
 
Thread Tools Search this Thread
  #1  
Old 23-04-2005
Misoft
 
Posts: n/a
Delegate domain user permission to join domain

I have a person who i must delegate him to join domain permission .I do :
Right click abc.com , delegate control ...,next ,add user peter@abc.com
,next ,checked "Join a computer to the domain" ,next ,finnish .But Peter
cannot join another computer to domain .
Pls ,tell me WHY ?
How can I delegate him join another computer to domain ???
Thank so much for reading !!!


Reply With Quote
  #2  
Old 23-04-2005
neo [mvp outlook]
 
Posts: n/a
Re: Delegate domain user permission to join domain

by default authenticated users (domain users) can only add 10 machines to
the domain. see
http://blogs.technet.com/jhoward/arc...18/403817.aspx for
instructions on how to change.

"Misoft" <horse2k4_4@yahoo.cm> wrote in message
news:u5Qp546RFHA.2788@TK2MSFTNGP09.phx.gbl...
>I have a person who i must delegate him to join domain permission .I do :
> Right click abc.com , delegate control ...,next ,add user peter@abc.com
> ,next ,checked "Join a computer to the domain" ,next ,finnish .But Peter
> cannot join another computer to domain .
> Pls ,tell me WHY ?
> How can I delegate him join another computer to domain ???
> Thank so much for reading !!!
>
>



Reply With Quote
  #3  
Old 23-04-2005
Misoft
 
Posts: n/a
Re: Delegate domain user permission to join domain

I do http://blogs.technet.com/jhoward/arc...18/403817.aspx . But
when my user join computer to domain it report "Access Deny"
WHY ?
Thanks so much for reading

"neo [mvp outlook]" <neo@online.mvps.org> wrote in message
news:e2#kQY7RFHA.1476@TK2MSFTNGP09.phx.gbl...
> by default authenticated users (domain users) can only add 10 machines to
> the domain. see
> http://blogs.technet.com/jhoward/arc...18/403817.aspx for
> instructions on how to change.
>
> "Misoft" <horse2k4_4@yahoo.cm> wrote in message
> news:u5Qp546RFHA.2788@TK2MSFTNGP09.phx.gbl...
> >I have a person who i must delegate him to join domain permission .I do :
> > Right click abc.com , delegate control ...,next ,add user

peter@abc.com
> > ,next ,checked "Join a computer to the domain" ,next ,finnish .But Peter
> > cannot join another computer to domain .
> > Pls ,tell me WHY ?
> > How can I delegate him join another computer to domain ???
> > Thank so much for reading !!!
> >
> >

>
>



Reply With Quote
  #4  
Old 23-04-2005
neo [mvp outlook]
 
Posts: n/a
Re: Delegate domain user permission to join domain

Lets go thru the steps.

1) Delegated the right to create a computer account in a specific OU

2) User creates the computer account in the OU *AND* specifies which
account/group may join the computer to the domain. (Watch this one as it
defaults to Domain Admins and tends to be what generates the Access Denied
later.)

3) User goes to machine in question and joins it to the domain within 15
minutes


"Misoft" <horse2k4_4@yahoo.cm> wrote in message
news:uy$BKp9RFHA.3444@tk2msftngp13.phx.gbl...
>I do http://blogs.technet.com/jhoward/arc...18/403817.aspx . But
> when my user join computer to domain it report "Access Deny"
> WHY ?
> Thanks so much for reading
>
> "neo [mvp outlook]" <neo@online.mvps.org> wrote in message
> news:e2#kQY7RFHA.1476@TK2MSFTNGP09.phx.gbl...
>> by default authenticated users (domain users) can only add 10 machines to
>> the domain. see
>> http://blogs.technet.com/jhoward/arc...18/403817.aspx for
>> instructions on how to change.
>>
>> "Misoft" <horse2k4_4@yahoo.cm> wrote in message
>> news:u5Qp546RFHA.2788@TK2MSFTNGP09.phx.gbl...
>> >I have a person who i must delegate him to join domain permission .I do
>> >:
>> > Right click abc.com , delegate control ...,next ,add user

> peter@abc.com
>> > ,next ,checked "Join a computer to the domain" ,next ,finnish .But
>> > Peter
>> > cannot join another computer to domain .
>> > Pls ,tell me WHY ?
>> > How can I delegate him join another computer to domain ???
>> > Thank so much for reading !!!
>> >
>> >

>>
>>

>
>



Reply With Quote
  #5  
Old 24-04-2005
ptwilliams
 
Posts: n/a
Re: Delegate domain user permission to join domain

Wouldn't it be easier to just delegate the permissions on the computers
container?

And then, grant delete as well and write in another OU so that a move can be
performed?

Maybe not, I would assume that pre-creating computer accounts would be a
real chore ;-)

--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net



Reply With Quote
  #6  
Old 25-04-2005
neo [mvp outlook]
 
Posts: n/a
Re: Delegate domain user permission to join domain

maybe for some... maybe not for others. really depends on how the site
operates.

"ptwilliams" <ptw2001@hotmail.com> wrote in message
news:Osix57LSFHA.3052@TK2MSFTNGP09.phx.gbl...
> Wouldn't it be easier to just delegate the permissions on the computers
> container?
>
> And then, grant delete as well and write in another OU so that a move can
> be
> performed?
>
> Maybe not, I would assume that pre-creating computer accounts would be a
> real chore ;-)
>
> --
> Paul Williams
> Microsoft MVP - Windows Server - Directory Services
> http://www.msresource.net | http://forums.msresource.net
>
>
>



Reply With Quote
  #7  
Old 25-04-2005
ptwilliams
 
Posts: n/a
Re: Delegate domain user permission to join domain

I guess.

I just wouldn't give the people who join the machines to the domain any
access to AD --they'd just be able to add machines. Somebody else could
move those computers ;-)

--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net



Reply With Quote
Reply

  TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory


Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads for: "Delegate domain user permission to join domain"
Thread Thread Starter Forum Replies Last Post
Delegate administrative right to a user group on a single server inside a domain el Active Directory 2 19-05-2010 06:51 PM
User suddenly can no longer 'join workstation to the domain' denied Mr Troy Active Directory 5 16-01-2010 12:00 AM
User dis-join from domain, how to re-join again Newbie Active Directory 6 18-03-2009 09:35 AM
Delegate permission let one user to join pc to a domain Active Directory 6 19-08-2008 03:21 AM
Minimum security settings of computer accounts for allowing domain user account to join domain M C Active Directory 2 18-08-2008 11:17 PM


All times are GMT +5.5. The time now is 12:30 PM.