Permissions to re-join computer to domain

From: GSDPack (GSDPack_at_discussions.microsoft.com)
Date: 02/24/05

  • Next message: Tony Eversole: "Re: Event 2089........ Is this a problem?"
    Date: Thu, 24 Feb 2005 09:01:06 -0800
    
    

    I have setup a separate OU that contains about sixty machine accounts. I
    would like to setup the permissions to allow any domain user to re-join the
    machine to the domain.

    The scenario we have:

    A WindowsXP machine is imaged when problems exist. I most cases the machine
    account is not removed from the domain. A new image is brought down from an
    imaging server and the machine is re-booted. During the re-boot the computer
    name is changed from the image name to the original name and re-started.

    Here we would like to assign permissions to domain users to re-join the
    computer to the domain. I have tired setting Domain Users security on the OU
    to create/delete computer accounts and created a GPO for Domain Users to add
    machines to the domain.

    However when they login as the local Administrator attempt to add the
    machine to the domain they receive “Access is Denied”

    Any ideas on the permissions that need to be set?

    Thanks.

    Lester


  • Next message: Tony Eversole: "Re: Event 2089........ Is this a problem?"

    Relevant Pages

    • Re: Domain account iwth restricted rights
      ... Normally the "Authenticated Users" special group has the logon locally ... The Domain Users causes the "Logon Locally" right to be present ... So you need both different permissions and different rights perhaps. ... What is the best way to lock down these accounts? ...
      (microsoft.public.windows.server.active_directory)
    • Re: Domain account iwth restricted rights
      ... primary group and each was removed from Domain Users. ... The Domain Users causes the "Logon Locally" right to be present ... So you need both different permissions and different rights perhaps. ... What is the best way to lock down these accounts? ...
      (microsoft.public.windows.server.active_directory)
    • Re: Domain account iwth restricted rights
      ... primary group and each was removed from Domain Users. ... So you need both different permissions and different rights perhaps. ... What is the best way to lock down these accounts? ... REMOVE them from the Domain Users group (every user is a member ...
      (microsoft.public.windows.server.active_directory)
    • Re: Permissions to re-join computer to domain
      ... I would like to setup the permissions to allow any domain ... I have tired setting Domain Users ... > security on the OU to create/delete computer accounts and created a ...
      (microsoft.public.exchange2000.active.directory.integration)
    • Re: File Sharing (again - sorry, Pd)
      ... InTerminal, type umask. ... Back in the good old days, Mac OS X user accounts ... The reason that the file permissions are "resetting" each time the ... that folder inherit the ACLs from the folder. ...
      (uk.comp.sys.mac)

    Loading