Re: Default Rights

From: Chriss3 (noSpamHere_at_chrisse.se)
Date: 03/18/04


Date: Thu, 18 Mar 2004 17:19:20 +0100

indeed.

Override the Default Limit of the Number of Computers an Authenticated User
Can Join to a Domain
You can override the default limit, using either of the following methods:
  a.. Use the Ldp (Ldp.exe) tool included in the Microsoft Windows 2000
Resource Kit.
  b.. Use an Active Directory Services Interface (ADSI) script to increase
or decrease the value of the Active Directory ms-DS-MachineAccountQuota
attribute. To do this:
    1.. Install the Windows 2000 Support tools if they have not already been
installed. To install these tools, run Setup.exe from the Support\Tools
folder on the Windows 2000 Server or the Windows 2000 Professional CD-ROM.
    2.. Run Adsiedit.msc as an administrator of the domain.
    3.. Expand the Domain NC node. This node contains an object that begins
with "DC=" and reflects the correct domain name. Right-click this object,
and then click Properties.
    4.. In the Select which properties to view box, click Both.
    5.. In the Select a property to view box, click
ms-DS-MachineAccountQuota.
    6.. In the Edit Attribute box, type a number. This number represents the
number of workstations that you want users to be able to maintain
concurrently.
    7.. Click Set, and then click OK.

-- 
Regards
Christoffer Andersson
No email replies please - reply in the newsgroup
"Johan Arwidmark" <johan.please_respond_to_forum.arwidmark@lutteman.se>
skrev i meddelandet news:c8ij5019a435cmhd0r4ln9gsr53i7b6m3p@4ax.com...
> By default, authenticated users can add 10 workstations to a domain.
>
> You can remove this permission...
>
>
> regards
> Johan Arwidmark
>
> Windows User Group - Nordic
> http://www.wug-nordic.net
>
>
>
>
>
> On Thu, 18 Mar 2004 09:59:18 -0600, "John Hiebert"
> <hieberj@okstate.edu> wrote:
>
> >I have AD running on 2003, not 2000, but this is the closest newsgroup I
> >found.
> >
> >Can anyone confirm that by default, any domain user can add/remove a
> >computer from AD if that have admin rights to the local workstation?
> >
> >If this is true, what do I  need to remove to prohibit domain users from
> >adding and removing workstations from the domain?
> >
> >Thanks
> >
>


Relevant Pages

  • Re: Please Help: Windows XP Professional In Windows 2000 Domain Based network.
    ... You mentioned that dns is correctly configured, just be sure that the XP computers do ... NOT have any ISP dns servers listed as a preferred dns server even down the list as ... > A fresh installation of Windows XP Professional (few workstations) have ... > been added to our Windows 2000 domain based network. ...
    (microsoft.public.windowsxp.general)
  • Re: Please Help: Windows XP Professional In Windows 2000 Domain Based network.
    ... You mentioned that dns is correctly configured, just be sure that the XP computers do ... NOT have any ISP dns servers listed as a preferred dns server even down the list as ... > A fresh installation of Windows XP Professional (few workstations) have ... > been added to our Windows 2000 domain based network. ...
    (microsoft.public.win2000.group_policy)
  • Re: Please Help: Windows XP Professional In Windows 2000 Domain Based network.
    ... You mentioned that dns is correctly configured, just be sure that the XP computers do ... NOT have any ISP dns servers listed as a preferred dns server even down the list as ... > A fresh installation of Windows XP Professional (few workstations) have ... > been added to our Windows 2000 domain based network. ...
    (microsoft.public.win2000.networking)
  • Re: Vant see pcs in domain
    ... (server name: RM1SRV1) ... and the workstations name is. ... i was able to see the computers again. ... MCSA: Messaging on Windows 2003 ...
    (microsoft.public.cert.exam.mcse)
  • Re: Domain not reachable via DNS-name
    ... Sounds very wired that they are listed as NT4.0 Computers in the directory, ... Forest and domain are working in Windows 2003 native mode. ... all workstations are using the local DNS Server ...
    (microsoft.public.win2000.active_directory)