Cloud Build

A Microsoft Azure Blog, 365 and all things Tech

Skip to content
  • About Me
  • Terms
  • Contact Us

stop users from adding machines to the domain

How to allow Domain Users to add computers to the domain

Posted on December 5, 2020 by Imran Rashid
Reading Time: 4 minutes

In this blog post I will be going through:

1) How to grant delegate control to allow a user to add machines to the domain in a selected OU within Active Directory

2) How to grant users permissions to add machines to the domain via group policy (Default Domain Policy). This policy will allow permissions through your AD structure

3) How to prevent authenticated users from joining workstations to a domain (Disabling the default limit which allows users to add 10 machines to the domain)

By default, Windows domain users can join 10 machine accounts to the domain.

This default was implemented to prevent misuse, but can be overridden by an administrator by making a change to an object in Active Directory. I will go through the process of how to disable this feature later on in this blog post.

Note that users in the Administrators or Domain Administrators groups, and those users who have delegated permissions on containers in Active Directory to create and delete computer accounts, are not restricted by this limitation.

Enabling delegation rights is beneficial if you have a domain account which requires permissions to add mass machines to the domain but you don’t wish to grant the account domain admin rights. For example, in a Virtual Desktop solution like Windows Virtual Desktop where an account needs to be specified to add Virtual Session hosts to the domain automatically. We want to avoid adding an account with domain admin rights.

How to grant delegate control to add machines to the domain in a selected OU within Active Directory

1) Launch Active Directory

Note: I have already created a standard domain account within Active Directory named cloudbuild3. In this demo I will be allowing the account to create computer objects in my WVD Session Hosts OU. This is the OU where all my WVD Sessions hosts are deployed and are added to the domain in the process.

2) If not already done so, click view and enable advanced features


3) Right click your OU and click delegate control.

4) Click next

5) Click Add

6) Add the user/group you wish to allow, in my case I will be granting clouduser3 delegation control to be able to add WVD Session hosts in this OU to the domain. You could add also add a security group if your requirements are different

7) Click Create a custom task to delegate and click next

8) Click the options as show in the screenshot below and click next

9) Click Create All Child Object

10) Click Next and Finish

How to grant delegate rights to add machines to the domain via group policy (Default Domain Policy). Note, this policy will allow permissions through your AD structure if the Default Domain Policy has been allowed to apply.

1) Launch group policy
2) Right click default domain policy and click edit

3) Expand Computer Configuration > Policies > Windows Settings > Security Settings > User Rights Assignment and double click Add workstations to domain located in the right pane



4) Click Define these policy settings, click browse and locate your user/group. For the purpose of this demo I am selecting a user. Click Apply and OK when done


How to prevent authenticated users from joining workstations to a domain (Disabling the default limit to allow users to add 10 machines to the domain

As mentioned earlier in this blog post, by default, Windows domain users can join 10 machine accounts to the domain.

  1. Launch ADSI Edit or access via Start > Run > adsiedit.msc

2) Right click ADSI Edit and click connect to

3) Click ok, ensure Default naming context is selected if not already done so by default

4) Expand, right click on the domain folder and click properties

5) Scroll down and locate ms-DS-MachineAccountQuota

6) Click Edit and set the quota from 10 to 0, click OK and close

Posted in Active Directory Windows Virtual Desktop
Tagged configure WVD domain join account without domain admin permissions grant delegate control to add machines to the domains on an OU within Active Directory grant users permissions to add machines to the domain via group policy prevent authenticated users from joining workstations to a domain prevent domain users from adding machines to the domain stop users from adding machines to the domain
Leave a comment

Search

Top 50 Azure Blogs

Subscribe to new posts

Keep up to date on the latest articles. We will never spam you or forward your details to third parties.

Name

Email


Certifications

  • azure-solutions-architect-expert-600×600
  • azure-security-engineer-associate600x600
  • azure-administrator-associate
  • microsoft365-messaging-administrator-associate-600×600
  • NCDA-7-Mode_352x352
  • Designing+and+Deploying+Microsoft+Exchange+Server+2016-01
  • Microsoft_Exam533
  • Microsoft_Exam534
  • MCSA-Cloud-Platform-2018
  • azure-solutions-architect-expert-600×600
  • CERT-Associate-Microsoft365-Teams-Administrator
  • MS-100-exam

Recent Posts

  • Increase One Drive For Business default 30 day retention Limit
  • Revoke Office Apps activation from user device
  • Prevent users from uploading videos to Microsoft Stream
  • Top 50 Azure Blogs
  • Enable Self Service Password Reset in Azure
  • Configure Conditional Access Policy in Azure
  • How to assign licenses for Microsoft 365 using a security group
  • Create a Modern SharePoint Site Microsoft 365 Part 1
  • Monitor Windows Virtual Desktop with Azure Monitor
  • How to set passwords to expire in Azure
  • Change Azure Subscription Name
  • Create and Optimise a Windows Virtual Desktop image
  • Add a domain to Microsoft 365 Step by Step
  • FSLogix Application Masking in Windows Virtual Desktop
  • How to allow Domain Users to add computers to the domain
  • Deploy VM in Azure via Powershell using Azure CloudShell
  • Backup Azure Files Share
  • Use Azure Files for FSLogix User Profile Data with Window Virtual Desktop
  • Configure FSLogix Group Policy and install FSLogix App
  • How to install and configure Windows Desktop client

Recently Viewed

  • About Me - 6,353 views
  • Contact Us - 6,011 views
  • Upgrade Windows Server 2012 to Server 2019 - 5,949 views
  • Terms - 5,364 views
  • How to build a server in Azure - 4,133 views
  • Empty Recycle Bin Upon log off - 3,949 views
  • The target server is already a domain controller - 3,466 views
  • Create an Azure Log Analytics workspace and add a Virtual Machine - 3,205 views
  • How to add Avaya 242 option into DHCP Server - 2,961 views
  • Windows Core: Move Page File via PowerShell - 2,849 views
  • Use Azure Files for FSLogix User Profile Data with Window Virtual Desktop - 2,846 views
  • 2012 R2 servers hanging on welcome screen - 2,150 views
  • MS-700 Managing Teams Exam Preparation - 2,090 views
  • How to install AZ Module within PowerShell - 1,881 views
  • Backup Azure Files Share - 1,810 views
  • Deploying Windows Virtual Desktop in Microsoft Azure - 1,739 views
  • How to install Terraform - 1,731 views
  • Twitter

Cloud Build

© All rights reserved.

Powered by WordPress

Subscribe to new posts

Name

Email


Recent Posts

  • Increase One Drive For Business default 30 day retention Limit
  • Revoke Office Apps activation from user device
  • Prevent users from uploading videos to Microsoft Stream

Cloud Build

  • About Me
  • Contact Us
  • Terms

Subscribe

Subscribe to new tech posts.
We will never send you spam email or forward your details to third parties.


Name

Email


This will close in 0 seconds

error: Content is protected !!