Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Active Directory > joining domain

Reply
Thread Tools Display Modes

joining domain

 
 
dkblee
Guest
Posts: n/a

 
      04-07-2010
hi! Is it possible to have the users rejoin xp,win7 to win2003 AD with the
computer object already exist in the AD? i know that this can be done through
administrator group, but can this be done by the user without adding them
into the domain admain grp or accoutn operator?

what's the best practice and previlege that i shd give to the support team
who only need to able to join the pc into the domain?


Thanks.
 
Reply With Quote
 
 
 
 
Paul Bergson [MVP-DS]
Guest
Posts: n/a

 
      04-07-2010
They have to be able to delete and add. If you are talking about doing this
to one machine not a real big deal but if you want folks to do this all the
time it could be a maintenance nightmare. Can you elaborate on what you are
trying to do and maybe there is another way to do something.

Such as delegating control of computer management on an ou for a user or
security group.

--
Paul Bergson
MVP - Directory Services
MCITP - Enterprise Administrator
MCTS, MCT, MCSE, MCSA, MCP, Security +, BS CSci
2008, Vista, 2003, 2000 (Early Achiever), NT4
Microsoft's Thrive IT Pro of the Month - June 2009

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewGroups. This
posting is provided "AS IS" with no warranties and confers no rights.
"dkblee" <> wrote in message
news:2B33AA94-15F8-466E-B3E1-...
> hi! Is it possible to have the users rejoin xp,win7 to win2003 AD with the
> computer object already exist in the AD? i know that this can be done
> through
> administrator group, but can this be done by the user without adding them
> into the domain admain grp or accoutn operator?
>
> what's the best practice and previlege that i shd give to the support team
> who only need to able to join the pc into the domain?
>
>
> Thanks.



 
Reply With Quote
 
kj [SBS MVP]
Guest
Posts: n/a

 
      04-07-2010
dkblee wrote:
> hi! Is it possible to have the users rejoin xp,win7 to win2003 AD
> with the computer object already exist in the AD? i know that this
> can be done through administrator group, but can this be done by the
> user without adding them into the domain admain grp or accoutn
> operator?
>
> what's the best practice and previlege that i shd give to the support
> team who only need to able to join the pc into the domain?
>
>
> Thanks.


Try resetting the computer account - which should set the computer account
password back to the default of "COMPUTERNAME$". Should be just like a
computer pre-create and the computer should find an object already for the
join and change the password on successfull join. Give it a try, but I think
that will work.

--
/kj


 
Reply With Quote
 
Meinolf Weber [MVP-DS]
Guest
Posts: n/a

 
      04-08-2010
Hello dkblee,

Yes, it can be done, see for more details in:
http://support.microsoft.com/kb/932455

http://support.microsoft.com/kb/243327/en-us

http://blogs.dirteam.com/blogs/jorge...01/05/369.aspx

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> hi! Is it possible to have the users rejoin xp,win7 to win2003 AD with
> the computer object already exist in the AD? i know that this can be
> done through administrator group, but can this be done by the user
> without adding them into the domain admain grp or accoutn operator?
>
> what's the best practice and previlege that i shd give to the support
> team who only need to able to join the pc into the domain?
>
> Thanks.
>



 
Reply With Quote
 
tkutil
Guest
Posts: n/a

 
      04-08-2010
you could use the netdom tool. You as administrator "add" the computer in AD
and then the user runs the netdom tool to "join". That way the user does not
need admin rights

"dkblee" wrote:

> hi! Is it possible to have the users rejoin xp,win7 to win2003 AD with the
> computer object already exist in the AD? i know that this can be done through
> administrator group, but can this be done by the user without adding them
> into the domain admain grp or accoutn operator?
>
> what's the best practice and previlege that i shd give to the support team
> who only need to able to join the pc into the domain?
>
>
> Thanks.

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Re: Active Directory problems/dcdiag error kj [SBS MVP] Windows Server 4 03-24-2010 09:19 PM
Re: Active Directory problems/dcdiag error kj [SBS MVP] Windows Small Business Server 3 03-24-2010 09:19 PM
Critical Issue Broken delegated domain Kashif Windows Server 3 02-15-2010 09:12 PM
Unable to add computer to domain Nik Active Directory 5 12-18-2009 08:29 PM
The local domain controller could not connect with - 2008 boe Active Directory 9 11-22-2009 01:05 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59