Domain Join User Permissions
This is by far the preferred method limited to the cases when it is absolutely necessary to do so as it only gives the minimum amount of permissions required to reach the goal.
Domain join user permissions. Delegating domain join access is quite a simple task to do in windows server using the delegation of control. Allow domain user to add computer to domain. Increase the permissions of the domain user on the local pc by adding the user in question in the local machine s power users or administrators group.
1 assign rights to the user group using the default domain group policy. Join computer to ad domain. Navigate to the ou right click on your target ou and select properties.
Specify a username that has permission to join computers to the active directory domain. Set permissions for the service account. Validate write to dns hostname.
There are 2 ways to allow domain user to add or join computer to domain. 2 delegate rights to user using active directory users and computers. Use the delegate control workflow in active directory to assign the following user account permissions to the username or to a group to which the user belongs.
It s recommended to set permissions on the parent ou depending on the companies ou structure.