Re: Permissions to join computers to domain




"obnetadmin" <obnetadmin@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:365BE461-2D3E-4A25-8F67-3D4DBEFE742F@xxxxxxxxxxxxxxxx
I have a single forest, single domain Windows Server 2003 AD environment. I
want a couple of users to be able to add computers to the domain without
having to add them to the Domain Admin group. Could this be achieved
through
delegation?

Yes.

You can do a variety of things, one available even under WinNT,
and several which fall under the term 'delegation' as Microsoft has
used it:

1) Account Operators can add comuters to the domain

2) By default, ordinary users can add up to 10 computers
(but this can be changed -- it was mainly enabled to let
people re-add their own computer)

3) Delegate full control over some specific OU - essentially
making the user/group an OU or department 'admin'
without making them a domain admin in any sense

4) Specifically delegate just the permissions you wish, such
as "Add child objects" which allows for adding computers
user etc

#4 can be done conveniently by Right-Clicking on a particular
OU and using the "Delegation of Control Wizard" OR by
bringing up the full properties->Security and adding any
combination of delegated authority you wish.



.



Relevant Pages

  • Re: Need limited domain admin rights user account.
    ... The delegation of control wizard does not add group memberships ... there is both a group for allowing an account to add computers ... Granting Domain Admin is not needed. ...
    (microsoft.public.windows.server.security)
  • Re: Permissions to join computers to domain
    ... having to add them to the Domain Admin group. ... and several which fall under the term 'delegation' as Microsoft has ... ordinary users can add up to 10 computers ... Delegate full control over some specific OU - essentially ...
    (microsoft.public.windows.server.active_directory)
  • Re: "Join Computer to Domain" priviledge only
    ... Every Domain User can add 10 computers to the domain by default. ... Delegation Of Control Wizard is what you look for, ... > power user privileges on all computers. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Custom rights
    ... create an account he goes thru the process fine until I arrive to the "Create ... > By default any user can log onto a server other than domain controller. ... > To add computers to the domain go to AD Users and Computers. ... >> Look into AD delegation, though you may need to do some custom delegation. ...
    (microsoft.public.win2000.security)
  • Re: Delegation Wizard
    ... > computers OU Built-In or not!! ... * Configure the delegation of control wizard as mentioned in the links ... * create separate admin accounts to perform admin tasks ... * Create an OU for the Admin roles and the admin tasks ...
    (microsoft.public.win2000.active_directory)