Re: Preventing Users from removing their PC from the Domain



In regards to what really happens when a PC leaves the domain. I liked
your answer the most, because it was clear and simple.

Joe Richards [MVP] wrote:
You can't prevent an admin (or really anyone with local physical access)
on a machine from removing it from a domain. The credentials supplied
when it asks for credentials are simply to disable the account in the
domain. They are not required, if the computer can't disable the account
in AD, it will simply disjoin from the domain locally and leave the
domain account enabled.

--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm



rndinit9@xxxxxxxxx wrote:
Currently users are able to remove their PC's from the domain w/o being
prompted for a DomainAdmin username/pass. This is becomming a problem.
How can I set it that in order for a PC to be removed from the domain,
that a domain admin username & password must be entered.

Your help is appreciated.


.



Relevant Pages

  • Re: No updates for Stinger
    ... MowGreen [MVP] wrote: ... > You cannot use it unless you Create an account and it wants your ... > Why Start getting Spam,, After 10 years on the internet and No Spamm ... so on) and some of the trials have, in fact, required a valid email ...
    (microsoft.public.windowsxp.newusers)
  • Re: Maximum machine account password age
    ... microsoft.public.windows.server.security news group, Joe Richards ... you could have password policy of 30 days and computers ... Paul Adare - MVP Virtual Machines ... It all began with Adam. ...
    (microsoft.public.windows.server.security)
  • Re: Combo Box Filter
    ... "Ken Snell (MVP)" wrote: ... would have a Row Source query that returns the Account Numbers. ... locate account within employeeid ...
    (microsoft.public.access.formscoding)
  • MVP - CHEAP SHOT
    ... I'm not an MVP either, but I've been monitoring this NG and looking at every ... many of the posted problems are repeats from day-to-day, ... 1) help folks learn how to help themselves; ... Select your mail account. ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • Re: Active Directory Fails as LDAP Address Book
    ... Joe Richards Microsoft MVP Windows Server Directory Services ... A similar method is used with Entourage in grabbing the GAL (Microsoft Entourage is an web http based email client and uses LDAP directories). ...
    (microsoft.public.windows.server.active_directory)