"Add workstations to Domain" security

From: RMorphis (noc@eprollc.com)
Date: 04/01/03


From: "RMorphis" <noc@eprollc.com>
Date: Mon, 31 Mar 2003 15:29:03 -0800


When I check the Domain, Domain Controller, and Local
security policy on my Domain controller, the "Add
workstations to Domain" effictive setting is to allow only
Domain Admins to join computers to the domain.

On the Computers OU in ADU&C, Authenticated Users have
read only access, All other accounts are admin or system
accounts.

Currently, Non-Admins are able to join workstations to the
domain. I can create a new user who is a member of the
domain user group only, and that account would be able to
join a workstation to my domain.

What's going on and how can I prevent it?

Thanks.



Relevant Pages

  • Re: "Add workstations to Domain" security
    ... > When I check the Domain, Domain Controller, and Local ... > workstations to Domain" effictive setting is to allow only ... > Domain Admins to join computers to the domain. ... All other accounts are admin or system ...
    (microsoft.public.win2000.security)
  • Re: Changing servers
    ... as a domain controller with the same domain name and set up all the user ... accounts, do I have to log the existing workstations off the older domain ... Directory (on the new server) for each workstation and then carry on using ...
    (microsoft.public.windows.server.general)
  • Re: Changing servers
    ... as a domain controller with the same domain name and set up all the user ... accounts, do I have to log the existing workstations off the older domain ... Directory (on the new server) for each workstation and then carry on using ...
    (microsoft.public.windows.server.general)
  • Re: restrict local users totally
    ... accounts that reside locally on the workstation. ... >be any local users, because it's a domain controller. ... >workstations connecting to it can have local or domain users. ...
    (Security-Basics)
  • Re: SBS Slow user logons problem
    ... You deleted both accounts and created new accounts for them (I also saw the ... Go to all workstations, log in as the Domain Admin and delete ALL profiles ... I have deleted the Reverse DNS zone on the SBS server and recreated it. ... Connection-specific DNS Suffix. ...
    (microsoft.public.windows.server.sbs)