Re: Preventing Users from removing their PC from the Domain



Hey Joe,

just fyi ...

It took me a while to remember to check this, but it is as I had
posted, i.e. without the credentials the computer account is just
disabled, but with them it is removed.

--
Roger Abell
Microsoft MVP (Windows Server : Security)

"Joe Richards [MVP]" <humorexpress@xxxxxxxxxxx> wrote in message
news:eYGgFMUmGHA.4700@xxxxxxxxxxxxxxxxxxxxxxx
You can't prevent an admin (or really anyone with local physical access)
on a machine from removing it from a domain. The credentials supplied when
it asks for credentials are simply to disable the account in the domain.
They are not required, if the computer can't disable the account in AD, it
will simply disjoin from the domain locally and leave the domain account
enabled.

--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm



rndinit9@xxxxxxxxx wrote:
Currently users are able to remove their PC's from the domain w/o being
prompted for a DomainAdmin username/pass. This is becomming a problem.
How can I set it that in order for a PC to be removed from the domain,
that a domain admin username & password must be entered.

Your help is appreciated.



.



Relevant Pages

  • Re: Changed name of machine = cant login
    ... I was getting an error "The credentials supplied conflict with an existing ... network cable, rebooted, logged in w/ local admin account, clicked my way ... creating a computer account in AD is not going to resolve your ... > The steps you took to rename the machine are wrong. ...
    (microsoft.public.win2000.networking)
  • Re: User May be Logged in somewhere else. Lockout 3x a day
    ... Could also be an Scheduled Task or mapped drive that uses persistent credentials. ... Common Causes for Account Lockouts ... This section describes some of the common causes for account lockouts The common ... manager on member computers that use the account as well as domain controllers. ...
    (microsoft.public.win2000.general)
  • Re: Please help me, it is highly Urgent.............
    ... The reason why the threshold is given as 5 is because of security concern. ... with credentials that subsequently expired. ... Account lockout duration = 0 ... Persistent drives may have been established ...
    (microsoft.public.windows.server.active_directory)
  • Re: custom page for user credentials?
    ... credentials against the various domains. ... after the user authenticates with IIS handling the SSPI Negotiation. ... possible for IIS6 to link a Passport user account to an AD user account -- ...
    (microsoft.public.inetserver.iis.security)
  • Re: Integrated Windows Authentication not working
    ... >>> my domain account (which won't work because I've set up ... >>Is your web server a member of a domain or does it have a ... >>submit credentials automatically for the IE security zone ... Windows Authentication, then IE will FIRST try to send the credentials ...
    (microsoft.public.inetserver.iis.security)