Domain Join Quota
By default an authenticated user account may join up to ten computers to the domain without any additional permissions or rights.
Domain join quota. The number of workstations a user can join to a domain is configured by the ms ds machineaccountquota attribute. By default its set to 10. Enabled members of domain administrators are exempt from both local administrators membership and the quota and can join unlimited computers so long as the correct authentication information is used.
This makes it possible to join computers to a domain in locations where there is no connectivity to a corporate network. Now there s a setting for allowing certain users or ou s a limited number of times that they are allowed to join new machines on to the domain without making them a domain admin. 5 once list is open find the attribute called ms ds machineaccountquota this is the attribute responsible for above limit.
Using the active directory service interfaces editors adsi edit you can manage. How do i do that. Offline domain join scenario overview offline domain join is a new process that computers that run windows 10 or windows server 2016 can use to join a domain without contacting a domain controller.
Quota if the ldif file was named change computer quota ldf you would then run the following command. This works great with windows machines but presents a slightly different problem when joining non windows machines to a domain. In the following ldif code replace domaindn with the distinguished name of the domain you want to change and replace quota with the new machine account quota.
Since the era of windows 7 and windows server 2008 r2 microsoft has added offline domain join to the administrator s tools. By default windows 2000 allows authenticated users to join 10 machine accounts to the domain. The number of joins which includes all computers not unix linux are determined by the ms ds machineaccountquota attribute of the domain.
So at my company i m a domain admin. One user had 10 but used them up and i m looking to reset that because they use multiple vm s etc.