Re: DSACLS and joining a domain

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 05/05/05


Date: Thu, 5 May 2005 12:19:30 -0500

I believe the user only needs create computer objects to join computers to
the domain. --- Steve

"Ed Little" <SPAMlittle_eddieME@hotmail.comNOT> wrote in message
news:1jaee.7499$uE3.84@charlie.risq.qc.ca...
> Hello,
>
> I am wondering what the minimum permissions needed to join a computer to a
> domain are? I would like to autocreate computer objects using dsadd, and
> them set the appropriate permissions using dsacls. Seems easy enough, but
> it is pretty slow. When adding a computer in ADUC, and specifying the
> group/user who can join it to the domain, it seems to associated many
> unnecessary permissions. Maybe they are all needed, but mimicing these
> settings with dsacls takes for ever. Any ideas?
>
> Thanks a bunch.
>
> Ed
>



Relevant Pages

  • Re: What happens to the machine name in AD?
    ... The user needs Write permissions on the computer object to modify all ... usually grant these rights on the OU that contains the computer objects. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Trying to use NetJoinDomain API...
    ... Nope I used the delegation wizard to set ACLs, and I also went in and added ... These are the permissions granted to the group, ... Computer Objects ...
    (microsoft.public.windows.server.active_directory)
  • Re: What happens to the machine name in AD?
    ... The normal user doesn't have these permissions, ... > usually grant these rights on the OU that contains the computer objects. ...
    (microsoft.public.windows.server.active_directory)
  • Re: DSACLS and joining a domain
    ... Thanks Steve, but I am a little confused. ... mimic this ACE with many iterations of dsacls, ... > I believe the user only needs create computer objects to join computers to ... >> them set the appropriate permissions using dsacls. ...
    (microsoft.public.win2000.security)
  • Re: Allow users to change Description attribute for computer account
    ... by giving a users group create computer objects permission on the domain or ... The delegation wizard simply changes AD permissions on the object. ... > I found a script on technet from the scripting guys. ...
    (microsoft.public.security)