Domain Join Account
From the menu choose delegate control.
Domain join account. If you click on start in windows 10 click on the setting icon the gear icon then click on accounts you ll an option called access work or school in the left hand column. Delegate domain join rights to a user in active directory. Create a standard user domain account new accounts are better to ensure they re not used by anything else but the auto domain join process set the password to a strong password that includes upper lower case symbols etc.
When windows settings scroll down to and click accounts. Next right click on the computers organisation unit ou within your ad domain. At your account info details click access work or school.
There are 2 ways to allow domain user to add or join computer to domain. 1 assign rights to the user group using the default domain group policy. Delegating domain join access is quite a simple task to do in windows server using the delegation of control.
Open active directory users computers. Then click connect and wait for the details to load when set up work or school account screen loads beneath alternative actions click join this device to a local active directory domain. I often experience that a domain admin account is used for this job which is a huge security breach.
Because the join domain account is often visible in your deployment answer file unattend xml of sysprep inf during the winpe phase it is important that this specific account does not have any more permission than the bare minimum. Both overlap in many areas and it s a bit confusing. First create a standard windows user account.
Right click the desired domain and select delegate control. Method 1 assign rights to the user group using the default domain group policy. Then enter the domain name and click next.