Skip to content

Mohammed Wasay

Dallas based Design Technologist & Hybrid Developer

  • Home
  • Posts
    • Azure
    • Office 365
    • Current Page Parent Windows
    • VMware
    • Linux
    • Mac
  • Resources
  • Client
    • Make a payment
  • Résumé
  • Contact
  • About
  • Get NordVPN

Create A Dedicated Account To Join Computers To A Domain

Posted on February 28, 2017 by mo wasay Windows

Admins often need to automate things, like creating a dedicated account for joining machines to an Active Directory (AD) domain.  This is useful for things like System Center Configuration Manger task sequences and System Center Virtual Machine Manager templates or similar needs.

First create a standard Windows user account.  Next, right-click on the Computers Organization Unit (OU) within your AD domain.  From the menu choose Delegate Control.

On the next screen (Users or Groups) choose Add and select the user account you just created.  Click Next.  Choose “Create a custom task to delegate” on the next screen.

Next, choose to only delegate control to computer objects and tick Create and Delete selected objects in this folder.  Click Next.

On the next screen choose to show general permissions and from the list select:

  • Reset password
  • Read and write account restrictions
  • Validated write to DNS host name
  • Validated write to service principal name

Click Next and finish to complete the wizard.  Repeat this process for any other OUs where you’ll be joining computers to the domain.

Tags: AaccountadminAdministratorautomateautomatedComputerscreateDedicateddomainJoinnoservertowaywindows

Share
  • Next Hack: Microsoft Outlook AutoComplete
  • Previous Cleaning up Office365 Groups Mess

You may also like...

  • Going back to the basics….moving out of Amazon Drive!

  • Find out mapped network drive logins

    Find out mapped network drive logins

  • Active Directory Ports required between client and domain controllers

Mo Wasay
My name is Mo Wasay. I work with a variety of technologies and engage with the community and customers around the world. I am located in Dallas, Texas, U.S.A. I like to share my knowledge and experiences and help others who come across similar situations. My current focus is Microsoft Azure, Azure Stack and Windows Server.

Categories

  • Active Directory
  • Azure
  • Information Technology
  • Linux
  • Mac
  • Office 365
  • PowerShell
  • SCCM
  • SharePoint
  • VMware
  • Windows

Archives

  • April 2020
  • February 2020
  • August 2019
  • July 2019
  • March 2019
  • December 2018
  • October 2018
  • September 2018
  • May 2018
  • April 2018
  • March 2018
  • February 2018
  • December 2017
  • November 2017
  • September 2017
  • August 2017
  • June 2017
  • May 2017
  • April 2017
  • March 2017
  • February 2017
  • January 2017
  • December 2016
  • November 2016
  • October 2016
  • September 2016
  • August 2016
  • July 2016
  • June 2016
  • May 2016
  • April 2016
  • March 2016
  • January 2016
  • November 2015
  • September 2015
  • August 2015
  • July 2015
  • June 2015
  • January 2013
  • June 2012
  • April 2012
  • March 2012
  • February 2012
  • April 2011

Tags

365 2008 2012 2016 access active AD Address bulk centos directory DNS domain Error Exchange file for get group in ip Linux list mailbox microsoft multiple network office office365 On online password powershell r2 remove security server service site system to user users vmware windows

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org
View Mo Wasay, MSCS, MCITP, MCSE, VCP, ISM, CIS's profile on LinkedIn

Mohammed Wasay © 2021. All Rights Reserved.

Powered by WordPress. Theme by Alx.