Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Active Directory > Re: Default Computer OU permissions

Reply
Thread Tools Display Modes

Re: Default Computer OU permissions

 
 
Florian Frommherz [MVP]
Guest
Posts: n/a

 
      11-10-2009
Howdie!

Glen schrieb:
> Currently, the Computer OU is the default container where new computer
> accounts are added. The problem is, I end up with all sorts of accounts
> there and they are never moved to the right OU.
>
> I would like to require that the computer account be created first, or at
> least restrict access to the default Computers OU so new accounts can not be
> created by non-domain admins.
>
> I don't see anything security settings in the ACL that should allow accounts
> to be created by non-admins but it still seems to be happening. The only
> account that I think might be allowing this to happen is the System Account
> which has Full Control but I"m leary to change the settings on that.


Yeah - what you noticed is correct. Users are allowed to join up to 10
machines to the domain (by default). They don't need to have admin privs
to do that. Meinolf already provided you with a link on how you can
disable that - or change the default number of machines they can add.
When setting the number to 0, I would also make sure a certain group of
people (let them be the Helpdesk, any 2nd level support folks..) have
the ability to create machine accounts other than you. You certainly
don't want to run and rush to join machines to the domain..

Another aproach that I've seen pretty often is using redircmp (and
redirusr). That let's you specify another default location - possibly an
OU, other than the "Computers" container that is built-in. Like that,
you could create a standard Group Policy newly joined machines apply.
I've seen folks link Software Installation policies or prep-scripts to
such an OU.

Cheers,
Florian
--
Microsoft MVP - Group Policy
eMail: prename [at] frickelsoft [dot] net.
blog: http://www.frickelsoft.net/blog.
ANY advice you get on the Newsgroups should be tested thoroughly in your
lab.
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
ANS: "What's the deal with UAC (Windows Needs Your Permission screens)" and "...But I thought I was an administrator" Jimmy Brush Windows Vista File Management 198 12-31-2009 07:58 AM
Need help getting permissions used by removed default trustee Paul Randall Windows Vista Administration 7 04-02-2007 07:34 AM
Vista installation hangs at boot screen crazye_star Windows Vista Installation 5 03-28-2007 02:58 AM
Stop 0x0000007b after Setup BobMiller Windows Vista Installation 8 08-05-2006 09:29 PM
Stop 0x0000007b at end of Install BobMiller Windows Vista Installation 2 08-03-2006 06:52 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59