Quantcast
Channel: Directory Services forum
Viewing all articles
Browse latest Browse all 31638

Permissions for a dedicated user to join computers to a specific OU in domain

$
0
0

Hi all,

I need a dedicated user, who has permissions to join a computer to a specific OU in the domain. I am trying to join a Linux Computer to the domain with realm. (see here chapter 3.3.2. Joining an Active Directory Domain)

I tried these steps: (see here)

  1. Click Start, click Run, type dsa.msc, and then click OK.
  2. In the task pane, expand the domain node.
  3. Locate and right-click the OU that you want to modify, and then click Delegate Control.
  4. In the Delegation of Control Wizard, click Next.
  5. Click Add to add a specific user or a specific group to the Selected users and groups list, and then click Next.
  6. In the Tasks to Delegate page, click Create a custom task to delegate, and then click Next.
  7. Click Only the following objects in the folder, and then from the list, click to select theComputer objects check box. Then, select the check boxes below the list, Create selected objects in this folder and Delete selected objects in this folder.
  8. Click Next.
  9. In the Permissions list, click to select the following check boxes:
    • Reset Password
    • Read and write Account Restrictions
    • Validated write to DNS host name
    • Validated write to service principal name
  10. Click Next, and then click Finish.
  11. Close the "Active Directory Users and Computers" MMC snap-in

If I try to join the computer to the domain, then the computer account is created, but no DNS entry. If I add my user to the group Domain Admins or Account Operators the join works correctly. (Computer account and DNS entry created)

How do I need to set the permissions for the dedicated user so he can join a computer to a specific OU?

It is a freshly installed Active Directory on a Windows Server 2012 R2.




Viewing all articles
Browse latest Browse all 31638

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>