Domain Joined Account Delegate Control

Namless Shelter 216 Reputation points
2021-12-06T05:10:40.67+00:00

Hi Friends,

Please help.

I created a Ad jOin account "ADjoin", and assigned the delegate control with create Computers objects rights under the certain OU..I thought Users who have delegated permissions on containers in Active Directory to create and delete computer accounts will not have any quotations on how many times the machine can join the domain???

But seems after a certain times after creation, this user still get errors "Exceeded Quotations to join domain"

Any tips?

Thanks
ML

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,109 questions
0 comments No comments
{count} votes

Accepted answer
  1. Gary Reynolds 9,391 Reputation points
    2021-12-06T08:55:04.493+00:00

    Hi @Namless Shelter

    If you have assigned to permissions to a specific OU, and you are using the standard join method from the computer properties dialog, the new computer object will be created in the Computers container, if the join delegated permissions have not been assigned to this container, then the join will count towards the user's default quote of 10. You need to add the addition delegated permissions to the Computer container as well.

    Gary.

    0 comments No comments

0 additional answers

Sort by: Most helpful