Re: "Add workstations to Domain" security

From: Steven L Umbach (n9rou@attbi.com)
Date: 04/01/03


From: "Steven L Umbach" <n9rou@attbi.com>
Date: Tue, 01 Apr 2003 00:16:24 GMT


        You could try this tip, but instead of increasing number set it to
zero. Let us know it it works. --- Steve

http://www.jsifaq.com/SUBM/tip6400/rh6418.htm

"RMorphis" <noc@eprollc.com> wrote in message
news:030f01c2f7dd$5098a7d0$a101280a@phx.gbl...
> When I check the Domain, Domain Controller, and Local
> security policy on my Domain controller, the "Add
> workstations to Domain" effictive setting is to allow only
> Domain Admins to join computers to the domain.
>
> On the Computers OU in ADU&C, Authenticated Users have
> read only access, All other accounts are admin or system
> accounts.
>
> Currently, Non-Admins are able to join workstations to the
> domain. I can create a new user who is a member of the
> domain user group only, and that account would be able to
> join a workstation to my domain.
>
> What's going on and how can I prevent it?
>
> Thanks.



Relevant Pages

  • Re: Changing servers
    ... as a domain controller with the same domain name and set up all the user ... accounts, do I have to log the existing workstations off the older domain ... Directory (on the new server) for each workstation and then carry on using ...
    (microsoft.public.windows.server.general)
  • "Add workstations to Domain" security
    ... When I check the Domain, Domain Controller, and Local ... Domain Admins to join computers to the domain. ... All other accounts are admin or system ... Non-Admins are able to join workstations to the ...
    (microsoft.public.win2000.security)
  • Re: Changing servers
    ... as a domain controller with the same domain name and set up all the user ... accounts, do I have to log the existing workstations off the older domain ... Directory (on the new server) for each workstation and then carry on using ...
    (microsoft.public.windows.server.general)
  • Re: restrict local users totally
    ... accounts that reside locally on the workstation. ... >be any local users, because it's a domain controller. ... >workstations connecting to it can have local or domain users. ...
    (Security-Basics)
  • Re: SBS Slow user logons problem
    ... You deleted both accounts and created new accounts for them (I also saw the ... Go to all workstations, log in as the Domain Admin and delete ALL profiles ... I have deleted the Reverse DNS zone on the SBS server and recreated it. ... Connection-specific DNS Suffix. ...
    (microsoft.public.windows.server.sbs)