Pre-Staging Computer Accounts

| | No TrackBacks
When you join a computer to a domain, its account gets placed into Computers container. However, that container isn't an organizational unit (OU) and, as such, can't be linked to a group policy object (GPO). It is a possible security breach (an unmanaged area).

It can be solved by pre-creating user accounts for computers prior to joining them. Use Active Directory Users and Computers to create a computer account within an OU. Afterwards, when computer is being joined, it will look for the same-name account and thus can be controlled by group policy. This process is called pre-staging.

No TrackBacks

TrackBack URL: /blog/mt-tb.cgi/34

blog comments powered by Disqus

About this Entry

This page contains a single entry by Konstantin Boyandin published on December 14, 2009 7:27 PM.

User Accounts And Domain Password Policies was the previous entry in this blog.

How To: Prevent Users From Installing Software is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.