Re: Delegating permission to add computers to the domain

From: David Everett [MSFT] (deverett_at_online.microsoft.com)
Date: 03/29/04


Date: Mon, 29 Mar 2004 13:44:43 -0600

Actually, the steps provided were meant to be placed on the OU where
Delegation is needed, not on the Computers container.

for example:
OU=Portable,OU=Clients,DC=parent,DC=com

I don't believe sysprep joins machines to OUs where groups have been
delegated rights based upon the group membership of the user doing the join
under Sysprep.

>From what I know of Sysprep you can alter the Unattend.txt or the
Sysprep.inf files by adding a MachineObjectOU entry that specifies the OU
where machines from a particular image will be added. Members of GroupA
should be given an image containing the Unattend.txt with a MachineObjectOU
referencing the OU where they have delegated rights.

As a test, I would first verify these users have the rights they need by
taking a machine that is currently in a workgroup and have them use netdom
to join into the delegated OU. If this works then you know it is a problem
with the Unattend.txt or Sysprep.inf and not a delegated permissions issue.

Also, make sure the Sysprep.inf has the FQDN for the domain name and not the
NetBIOS Domain Name.

226315 Computer Account Organizational Unit Can Be Specified by Using the
http://support.microsoft.com/?id=226315

If you need assistance in troubleshooting the Sysprep/mini-setup
configuration you might want to post to
microsoft.public.windowsxp.setup_deployment.

-- 
David Everett
Microsoft Corporation
This posting is provided "AS IS" with no warranties, and confers no rights.
"Ulf B. Simon-Weidner [MVP]" <nospam2-ulf@usw-consulting.com> wrote in
message news:MPG.1ad27d6a16d88f7b989ae9@msnews.microsoft.com...
> Jon Paskett says...
> > Thanks for the reply David,
> >
> > You are focusing on the Computers container. I understand that default
> > behavior is that new computers are created in the Computers container.
Can
> > this be changed, based upon group membership, to automatically add them
to a
> > Computers OU located within their Parent? That is my ultimate goal. They
can
> > predeploy them, but I want to have the ability to automatically add them
to
> > the OU they are delegated permission to do so.
> >
> > Thanks for your help
> >
> > Jon
> >
> Hi Jon,
>
> if I understand you correctly you are asking if it is possible to change
the
> default container where computer Objects are created.
>
> If you are using Windows Server 2003 you can change that container to any
OU
> using the redircmp command (or redirusr for the default container for
users).
>
> Test this with your applications which are directory aware in a
testenvironment
> prior to implementing it in your production network.
>
> Gruesse - Sincerely,
>
> Ulf B. Simon-Weidner


Relevant Pages

  • RE: Aftermath of REDIRCMP.EXE?
    ... the PC's currently in the computers OU will not ... If the Default Domain policy is set to ENFORCED, then a block on the new ... default Computers Container as a place to put machines that for whatever ... not block the default domain policy, so we had to move the machines back into ...
    (microsoft.public.windows.server.active_directory)
  • Re: Custom rights
    ... create an account he goes thru the process fine until I arrive to the "Create ... > By default any user can log onto a server other than domain controller. ... > To add computers to the domain go to AD Users and Computers. ... >> Look into AD delegation, though you may need to do some custom delegation. ...
    (microsoft.public.win2000.security)
  • Re: Delegation Wizard
    ... > computers OU Built-In or not!! ... * Configure the delegation of control wizard as mentioned in the links ... * create separate admin accounts to perform admin tasks ... * Create an OU for the Admin roles and the admin tasks ...
    (microsoft.public.win2000.active_directory)
  • RE: Delegation of duties to junior administrator
    ... This will help you to be able to customize the delegation ... define templates for use in this wizard. ... That gives members in this group, full admin ... With computers being separate from servers, this only allows the members to ...
    (microsoft.public.windows.server.active_directory)
  • Re: Need limited domain admin rights user account.
    ... change you see and are attributing to an action of the delegation wiz. ... "Mike Bailey" wrote in message ... > You said that there is a group for allowing an account to add computers ... >> account) to which it is delegating. ...
    (microsoft.public.windows.server.security)