Adding Computers to the domain

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Aaron (anonymous_at_discussions.microsoft.com)
Date: 08/25/04


Date: Tue, 24 Aug 2004 17:01:18 -0700

Hello,

Am trying to add these permissions more granularly then
by adding accounts in the account operator built in group.

I have delegated advanced rights on specific OU's
granting create/delete rights for groups, users, advanced
security objects, and accounts.

The users can manipulate and create all objects, no
problem. However now some cannot join a computer to the
domain even though they created teh computer object with
the matching name beforehand. I am aware that AD lets 10
machines on the domain per user account, but wouldnt
these setting override that default limit? How do i get
this working without having to throw everyone back into
the account operator group?

Thanks!
Aaron



Relevant Pages

  • Re: Delegation Account Unlock to Users
    ... Account Operator and other accounts that have enhanced native rights are protected by the adminsdholder functionality, google on adminsdholder and you will get a ton of hits explaining it. ... I have delegated the Account Unlock function to my helpdesk but I'm encountering some problems now. ... I'd like to enquire if anyone has managed to succesfully delegate the Account Unlock function to work on the above 2 scenarios, other than on User Objects only. ...
    (microsoft.public.win2000.security)
  • RE: Local Group memberships
    ... be ADMT migration objects. ... If you want to add a user who is member of account operators in Windows NT ... Manually add the user to the "account operator" group. ... Export the membership from NT domain to a .txt file. ...
    (microsoft.public.windows.server.migration)
  • Access denied in Users and Computers
    ... i'm having a strange problem in my Windows Server 2003 AD: ... a W2K3 member server with the Admin Tools installed ... uses "FIND" to locate a user account ...
    (microsoft.public.windows.server.active_directory)