Domain Join Delegation
Start the delegate control wizard.
Domain join delegation. Click add and select the group supporters and click next. Open the active directory users and computers aduc console as domain administrator. Here s how you delegate the permissions.
To enable the supporters group to join and remove machines to and from the domain. Find the user you just created. Select the properties as shown in the picture.
Method 1 assign rights to the user group using the default domain group policy. Now you can use the cm dj user to domain to your ou from mdt or sccm. Click start click run type dsa msc and then click ok.
Right click to the computer container and select delegate control. There are 2 ways to allow domain user to add or join computer to domain. If you delegate the permission or manually add it using the security tab both of the above will be bypassed.
Locate and right click the ou that you want to modify and then click delegate control. As part of that i want to delegate joining of computers to the helpdesk so that a sysadmin doesn t have to do it. Open active directory users computers.
Create a new group supporters. In the task pane expand the domain node. 2 delegate rights to user using active directory users and computers.