Re: "Add workstations to Domain" security

From: Rmorphis (rmorphis@barrios.com)
Date: 04/15/03


From: "Rmorphis" <rmorphis@barrios.com>
Date: Tue, 15 Apr 2003 10:38:15 -0700


That did it, thanks for the help!

>-----Original Message-----
> You could try this tip, but instead of increasing
number set it to
>zero. Let us know it it works. --- Steve
>
>http://www.jsifaq.com/SUBM/tip6400/rh6418.htm
>
>"RMorphis" <noc@eprollc.com> wrote in message
>news:030f01c2f7dd$5098a7d0$a101280a@phx.gbl...
>> When I check the Domain, Domain Controller, and Local
>> security policy on my Domain controller, the "Add
>> workstations to Domain" effictive setting is to allow
only
>> Domain Admins to join computers to the domain.
>>
>> On the Computers OU in ADU&C, Authenticated Users have
>> read only access, All other accounts are admin or system
>> accounts.
>>
>> Currently, Non-Admins are able to join workstations to
the
>> domain. I can create a new user who is a member of the
>> domain user group only, and that account would be able
to
>> join a workstation to my domain.
>>
>> What's going on and how can I prevent it?
>>
>> Thanks.
>
>
>.
>



Relevant Pages

  • Re: Associate a Mailbox With an Account From Another Forest
    ... Exchange server "advanced" mailbox tab! ... be domain admins, so I'll have to remove them, but this at least confirms ... that my trust is working properly. ... >> With the exception of the user accounts who are members of the Domain ...
    (microsoft.public.exchange.setup)
  • Re: How can I disable all users in AD while keeping the admin accounts active?
    ... Since the same script slightly modified can be used to re-enable the ... accounts, I spit out the names of accounts ... Set adoConnection = CreateObject ... ' Administrators, Domain Admins, or Enterprise Admins. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Sub Domain Admin Accounts
    ... because it is a member of the Enterprise administrators universal group. ... Other members of the child domain admins group would not have this ability ... >> no technical reason why an admin accounts in one domain need to access ...
    (microsoft.public.windows.server.general)
  • Re: Domain administrator local admin on every machine
    ... Furthermore once i setup the domain admins i want to ... disable all local accounts, or at least prevent login to local ... net user Administrator SomeStrongPassword ... net localgroup Administrators "Domain Admins" BackupAdmin /add ...
    (microsoft.public.windows.server.general)
  • Re: dcpromo without domain admin rights
    ... as long as their are not domain admins, it can be delegated to add new ... as long as the server is a non-DC those admins will be able to ... taken from "Best Practices for Delegating Active Directory Administration ... The default domain controller policy is modified to grant the rights ...
    (microsoft.public.windows.server.active_directory)