Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Join Machines To Domain

Status
Not open for further replies.

zeveck

Programmer
Jun 6, 2005
142
US
How do I make it so that a specified group, say DomainFriends, can add/remove/replace machines on the domain?

The 'Add workstations to domain' privilege appears to allow the group to Add, but only NEW machines. When there is already an existing machine of the same NetBIOS name I get an 'Access Denied' from accounts with the privilege even though the Administrator can still add such a machine just fine.

Thoughts?
 
But I don't want the users to be able to add/remove accounts...just add/remove/replace computers. Account Operators appears to offer too much; and I am not sure what I have to delegate to achieve my intended goal... =(
 
Give Full Control on the OU containing the computer accounts for the group. Only works if OU's for computers and user accounts are different of course.
 
Add these users to a security group and call it <whatever>. In GPMC, appoint delegation to whichever computer OU's you want this group to modify. With special priviliges, you can delegate this group to create and/or delete computer objects in specified computer OU's, or move computer objects to or from specified computer OU's.

Hope this helps.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top