Re: Granting permission to re-add a computer account

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: Joe Richards [MVP] (humorexpress_at_hotmail.com)
Date: 03/14/04


Date: Sun, 14 Mar 2004 09:57:06 -0500

I wouldn't recommend deleting and recreating the account. I would instead
recommend resetting the account and having the machine rejoin, this can be
done by simply delegating reset password on the computer objects (more
specifically on the OU with the ace inherited to computer objects).

-- 
http://www.joeware.net   (download joeware)
http://www.cafeshops.com/joewarenet  (wear joeware)
"kj2n" <anonymous@discussions.microsoft.com> wrote in message
news:c3dc01c40867$16f5fcd0$a101280a@phx.gbl...
> I am trying to grant access to our help desk to have the
> ability to add computers to our domain. I have done the
> following:
>
> Delegated Authority at the domain level to the following:
> - Create Computer objects
> - Delete Computer objects
>
> They can add new computers to the domain, but can not
> remove and then re-add a computer to the domain. Could
> this have something to do with resetting the computer
> account within AD and not having the appropriate
> permissions for that task?  What security settings do I
> need to allow?
>
> Thanks.


Relevant Pages

  • Re: Delegate ad workstations to domain
    ... And this one to readd an existing computer object, reinstall computer without deleting in AD for example: ... The problem is that the computer account password reset has to be delegated additional. ... default domain GPO so the help desk staff can add workstations to the ... staff so they can create and delete computer objects. ...
    (microsoft.public.windows.server.active_directory)
  • Re: MachineObjectOU Setting doesnt work for me
    ... also tried to use the "administrator" account as DomainAdmin in sysprep.inf. ... Create Computer objects ... we are having a few problems with sysprep. ...
    (microsoft.public.windowsxp.setup_deployment)
  • Re: Script used to create computer accounts does not perform as expect
    ... When I create computer objects, I set the appropriate bits of the ... This would account ... Here is the Script ... Create-computer-accounts.vbs COM-391DC9C841E Workstations ...
    (microsoft.public.windows.server.active_directory)
  • Re: Searching AD to determine account usage
    ... there's no built in tool that does what you want. ... are a number of scripts around that will give you a list of each user ... account and when it last logged on, ... It was written to do this for computer objects, but can also be used for ...
    (microsoft.public.windows.server.active_directory)
  • Re: Joining computers to the domain
    ... For an account to have rights to add computers to the domain they need ... "Create Computer Objects" on the Computers container. ... given that account the following permissions within thier own container (and ...
    (microsoft.public.windows.server.active_directory)