Limiting Users' Ability to Add a Workstation to the Domain

Disable Add workstation to the domain right in the Default Domain Controller Policy GPO, and make sure the Create Computer permission isn't granted to a broad user group.

ITPro Today

February 20, 2006

1 Min Read
ITPro Today logo in a gray background | ITPro Today

My Default Domain Policy Group Policy Object (GPO) shows Add workstation to the domain right as disabled. However, I was able to add a workstation to my domain with a regular user account. What gives?

First you need to check the Default Domain Controller Policy GPO which, for domain controllers (DCs), takes precedence over the Default Domain Policy GPO. DCs are where this right is enforced.

Second, users can also gain the authority to create computers in the domain through the Create Computer permission. Check the permissions on the root of your domain and its organizational units (OUs) to see whether Create Computer is currently granted to Everyone, Authenticated Users, Domain Users, or a similar broad group.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like