Re: Preventing Users from removing their PC from the Domain



You can't prevent an admin (or really anyone with local physical access) on a machine from removing it from a domain. The credentials supplied when it asks for credentials are simply to disable the account in the domain. They are not required, if the computer can't disable the account in AD, it will simply disjoin from the domain locally and leave the domain account enabled.

--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm



rndinit9@xxxxxxxxx wrote:
Currently users are able to remove their PC's from the domain w/o being
prompted for a DomainAdmin username/pass. This is becomming a problem.
How can I set it that in order for a PC to be removed from the domain,
that a domain admin username & password must be entered.

Your help is appreciated.

.



Relevant Pages

  • Re: Unlock acct permissions
    ... It may actually be the best of the bunch but it is very old now so it is mostly about those GOOD FUNDAMENTALS that one needs and which Joe referenced. ... >>>Overall you appear to be a very "green" admin and you should buy one or more>>>books and learn this stuff before you do too much more. ... >>>Joe Richards Microsoft MVP Windows Server Directory Services ... How do I get DSACLS to run on a specific account? ...
    (microsoft.public.win2000.active_directory)
  • Re: Incoming E-Mail - cant create contact in OU
    ... central admin pool different than the web app. ... that account a little (if the web app is compromised or something, ... So I started with giving the app pool account domain admins permissions then ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: Security Breach in AD! Help!
    ... > about 5 minutes the user was removed from the built in admin group. ... > changed the default domain policy, the default domain controller policy, ... >> auditing of account logon for success and failure and account management ... >> success and failure in Domain Controller Security Policy. ...
    (microsoft.public.win2000.security)
  • Re: Wscript within VBA
    ... One box is running VBA code,. ... One box is a domain controller, or has an account trusted to manipulate AD ... >> It posts a form to an ASP page, ... >> Since what you want to do sounds like it will require admin privileges, ...
    (microsoft.public.vb.database)
  • RE: Question regarding admin passwords on sbs.
    ... I'd also ask you to reconsider disabling the Administrator account, ... describe create another account with Domain Admin privileges for your regular ... Even Microsoft has no solution to *Crack* the ...
    (microsoft.public.windows.server.sbs)