Ripleys Posted June 7, 2016 Posted June 7, 2016 Hi guys. Basically we have an account that we use to join our computers to the domain. We haven't made any changes to it at all. If I were to delegate control to this account, would anything happen the PCs that have joined the domain with this account. Is there anyway to stop it from been logged on with but still be used to perform only this task. Or would be better to make a new account from scratch with delegated controls and start phasing the old account out over time? Any advice would be much appreciated. Cheers
Guest obsidianpillar Posted June 11, 2016 Posted June 11, 2016 Hi, we do similar (for MDT) using User Rights Assignment allowing a security group with the user object contained within it to join the Domain. Using a delegation of control will not (in my experience) do anything to the PC's that have used the account to join the Domain. In regards to stopping it being logged into, I think you'd still need to give it login rights to one/all of your DC's to allow it to work properly(?) I have it set to allow login to just all my DC's and it works fine. I also disable the account when it's not in use (ie deploying an OS in our case) which prevents it being used any other time. Hope this helps. Best, Tom
Ripleys Posted June 13, 2016 Author Posted June 13, 2016 So I could just temp disable the account now and no PCs would be affected? Because that, to me, sounds like a better option for me now.
Guest obsidianpillar Posted June 13, 2016 Posted June 13, 2016 Yup, that won't affect any of the already joined PC's. Feel free to disable it.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now