Re: Right to add computers to a domain



In article <ObU8a#$dGHA.4576@xxxxxxxxxxxxxxxxxxxx>, in the
microsoft.public.windows.server.security news group, Riki
<riki@xxxxxxxxxxxxx> says...

Is it possible to create a user on a domain (Windows 2003 Server) with the
right to add computers to that domain, but without being member of the
Domain Admins group?

I'm working for a training center for pc technicians, and our students often
have to install different versions of windows on their system as an
exercise.
After the installation, they should be able to add their computer to our
domain, without the intervention of a domain admin. That's why we want to
give them the name and password of an account that can do just that.

Is that possible?


In both Windows 2000 and Windows Server 2003, domain users already have
the right to join computers to a domain. Nothing special required to
enable this.

--
Paul Adare - MVP Virtual Machines
It all began with Adam. He was the first man to tell a joke--or a lie.
How lucky Adam was. He knew when he said a good thing, nobody had said
it before. Adam was not alone in the Garden of Eden, however, and does
not deserve all the credit; much is due to Eve, the first woman, and
Satan, the first consultant." - Mark Twain
.



Relevant Pages

  • Some users unable to log into domain.
    ... Testing to slowly move over 40-50 computers to a domain.. ... I can switch back to the reduced access account and it does work ... Ive tried two logins featured under the domain admins group, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Active directory Group Policy (Win2k)
    ... When I enforce the policy onto the computers in the new OU, ... Domain Admins so the Domain Admins cannot view ... workstations, to access Microsoft Office. ...
    (microsoft.public.security)
  • Re: MS ADAM/AD: Absolute simplest repl/sync solution for MS ADAM on 2 or more WinXP machines?
    ... Microsoft® Windows® Server 2003, Enterprise Edition ... ADAM does not require a forest, domain, or domain controller. ... install ADAM on computers that are configured as any of the following: ... >> doesn't mean one doesn't exist but because of the support path it is not ...
    (microsoft.public.windows.server.active_directory)
  • Re: Restrict access to administrative shares?
    ... to only include the domain admins group of those domain member machines that you want ... to restrict access to assuming that other users have no need to access shares on the ... You could move the computers you want to restrict into their own OU and set ...
    (microsoft.public.win2000.security)
  • Re: Group Policy setting for restricting creation of local user accounts
    ... if DA was not in each machine's local Administrators ... group that mimics domain admins rights minus the right to create local ... being able to create accounts on the computers. ... local computer user accounts when the computer is joined to the ...
    (microsoft.public.windows.group_policy)