Enhanced security joining or resetting machine account in Windows 2000 domain (238793)
The information in this article applies to:
- Microsoft Windows 2000 Server
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2000 Professional
- Microsoft Windows 2000 Datacenter Server
This article was previously published under Q238793 SUMMARY
The process of creating a machine account has been enhanced in Windows to provide a more secure environment. When a new computer object is created, the Administrator can set which user or group has permissions to join the computer to the domain. By default, only members of the Authenticated Users global group have the requisite authority to join computers to a domain. By changing this information from the default, you are changing the security permissions on the computer object by giving the user or group Reset Password permission. When you join a Windows-based workstation or server to the domain, you are prompted for a password. You must supply the user name and password for an account that has permission to add the computer to the domain.
In Microsoft Windows NT 4.0, after the Administrator creates a machine account, anyone can add the account to the domain. This addition to the creation process increases network security.
The following section of this article describes how to create a machine account in Windows and to join the domain from a Windows client.
Modification Type: | Minor | Last Reviewed: | 8/31/2006 |
---|
Keywords: | kbinfo KB238793 |
---|
|