Adding workstations to domains

From: Ed (Ed_at_discussions.microsoft.com)
Date: 08/31/04


Date: Tue, 31 Aug 2004 13:25:19 -0700

Hello all,

For security purposes, I have trimmed the members of the Domain Admins group
accross all domains to only a select few. When doing this, ex-members of
that group are no longer able to add machines to the domain. In Default
Domain Policy and Default Domain Controllers Policy | User Rights Assignment,
I have added these users to the "Add workstations to the Domain" policy, but
it still doesn't work. I have also Delegated control to the Computers
container so they have the right to write.

What am i missing? I need these users to be able to add machines to the
domain without them having domain admin rights. Thanks.



Relevant Pages

  • Re: NT4->2003 Computer Account Migration Problem
    ... win2k3 domain, domain admin is by default the computer's local admin. ... and remigrate the computers using a specific account to perform migration ... Add NT Domain Admin to Win2k3Dom Domain admins group and Win2k3Dom ...
    (microsoft.public.windows.server.migration)
  • Re: Active directory Group Policy (Win2k)
    ... When I enforce the policy onto the computers in the new OU, ... Domain Admins so the Domain Admins cannot view ... workstations, to access Microsoft Office. ...
    (microsoft.public.security)
  • Re: administrator locked out of SBS 2003
    ... The Domain Admins group was a member of ... included in the "Deny log on locally" local security policy settings. ... Select "All users except local administrators" ... That allowed the installation of VMware server to complete. ...
    (microsoft.public.windows.server.sbs)
  • Re: Clarification Needed
    ... My plan was to create 2 GPO's one User Level and one Domain Admin GPO. ... Is there any problem removing and in line with the above thinking, add domain users to the User GPO and domain admins to the Domain Admins GPO. ... You can alter the NFTS permissions of the Group Policies by accessing the tab "Security" at the properties of the Policy. ... If a group of users shall not apply/overtake a Group Policy, simple add a "Deny Group Policy" permission to the group... ...
    (microsoft.public.windows.group_policy)
  • Re: Domain user with local administrators right
    ... domain account to the domain admins group, this is in turn a member of the ... with this domain account (selecting the domain from the drop down box under ... If the server is a domain controller, then there is no local administrators ... group so membership of domain admins should suffice. ...
    (microsoft.public.windows.server.active_directory)