Granting permission to re-add a computer account

  • Thread starter Thread starter kj2n
  • Start date Start date
K

kj2n

I am trying to grant access to our help desk to have the
ability to add computers to our domain. I have done the
following:

Delegated Authority at the domain level to the following:
- Create Computer objects
- Delete Computer objects

They can add new computers to the domain, but can not
remove and then re-add a computer to the domain. Could
this have something to do with resetting the computer
account within AD and not having the appropriate
permissions for that task? What security settings do I
need to allow?

Thanks.
 
I wouldn't recommend deleting and recreating the account. I would instead
recommend resetting the account and having the machine rejoin, this can be
done by simply delegating reset password on the computer objects (more
specifically on the OU with the ace inherited to computer objects).
 
Back
Top