Domain Join Service Account
Delegating domain join access is quite a simple task to do in windows server using the delegation of control.
Domain join service account. The directory service has exhausted the pool of relative identifiers. Next right click on the computers organisation. Domain join account minimum rights this falls under another one of those items that i have had in my private notes for a while but can t remember where i found it.
The account specified for this service is different from the account specified for other services running in the same process. Right click the desired domain and select delegate control. Method 1 assign rights to the user group using the default domain group policy.
Ensure that the domain controller through which you are trying to perform the domain join has the windows time service started. The service has whatever local and network access is granted to the account or to any groups of which the account is a member. Right click the ou you want the account to be able to join computer objects to this could be the to level domain if you would like and click properties open the security tab and click advanced.
When setting up the account in a configmgr task sequence to join the new computer account to the domain you must give that account rights in order for it to work. First create a standard windows user account. 2 delegate rights to user using active directory users and computers.
1 assign rights to the user group using the default domain group policy. Open active directory users computers. Set the service account password to password never expires.
A domain user account enables the service to take full advantage of the service security features of windows and microsoft active directory domain services. This is a quick post to describe the process of creating a dedicated account for joining machines to an active directory ad domain. Delegate domain join rights to a user in active directory.