Re: unable to add machine accounts to domain

Tech-Archive recommends: Fix windows errors by optimizing your registry



I would like to have all authenticated users be able to add workstations to
the domain. Currently onlt administrators and account operators can
sucessfully ad a machine.

New users cannot add 10 machine anymore as well...

Thank You!!!

"Jorge de Almeida Pinto [MVP]" wrote:

OK, please explain what you would like to achieve...don't forget any
details, just say what you really want

Having that I will try to help you

--

Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)

# Jorge de Almeida Pinto # MVP Windows Server - Directory Services

BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx
-----------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no rights!
* Always test before implementing!
-----------------------------------------------------------------------------


-----------------------------------------------------------------------------
"stosti" <stosti@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:25AA187E-86B8-4870-A272-FE88F7D14FDF@xxxxxxxxxxxxxxxx
The artical is a bit confusing... So you cannot do it by using the
deligation of control wizard? If yes which one in the list is the correct
one to check off? If not what tool or program do you use to make the
changes
they list?

6 to 9 months ago the built in right to add 10 work stations to the domain
stoped working as well. I actually would prefer to get this working
again.
Can the number (10) be changed? If yes where is that modified?

Thanks!!!

"Jorge de Almeida Pinto [MVP]" wrote:

see:
http://blogs.dirteam.com/blogs/jorge/archive/2006/01/05/369.aspx

--

Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)

# Jorge de Almeida Pinto # MVP Windows Server - Directory Services

BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx
-----------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no
rights!
* Always test before implementing!
-----------------------------------------------------------------------------


-----------------------------------------------------------------------------
"stosti" <stosti@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:E3A042B0-2A87-47AA-AFBF-4853B413DD21@xxxxxxxxxxxxxxxx
I added the authenticated users group to the domain group policies under
add
workstations to the domain. Why doesn't it work? If i add a user to
the
account operators group that user can add users to the domain.

I tried adding the user by account name in the group policy's. That
did
not
work either...

Thanks,
Scott






.



Relevant Pages

  • Re: Administrators Group in Local Users and Groups
    ... However think of if it did work, that SID has no domain affinity so ANY account operator of ANY domain would then have admin rights to your workstations. ... I am trying to find out how to add in the domain group Account Operators to each workstations administrator group. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Administrators Group in Local Users and Groups
    ... I do not see a problem with adding junior admins to the Account Operators ... Builtin groups have a well known sid, in the case of acc ops it is ... > you applied it to an admin group, it would give a resolution error. ... >> each workstations administrator group. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Net Send help
    ... This posting is provided "AS IS" with no warranties, and confers no rights. ... I have 3 Windows XP Pro workstations ...
    (microsoft.public.windows.server.networking)
  • Re: Group Policy
    ... This posting is provided "AS IS" with no warranties, and confers no rights. ... We have 20 workstations ...
    (microsoft.public.windows.server.general)
  • Re: Move Workstations around OUs via script.
    ... This posting is provided "AS IS" with no warranties, and confers no rights. ... We have many PC's in 'Workstations' container in AD that no longer ...
    (microsoft.public.windows.server.active_directory)