domain方式連接問題

來源: f64 2004-04-09 12:03:51 [] [舊帖] [給我悄悄話] 本文已被閱讀: 次 (1566 bytes)
First, understand this:
A member of local administrators group can do any and all on the local machine. The built in account administrator is a member of local adminstrators group.

Second, understand what exactly happens when a machines joins a domain.

Who can join a pc to a domain:
1. he must be member of local admin gruop.
2. he must be member of domain group that has rights to add machines to the domain - usually this is domain admin group. This right is needed because a security account for the machine must be created in the domain when the machine joins the domain. If you are only a local admin, you cannot join a machine to a domain, unless the domain admin has already created the machine account for you beforehand (with the same machine name).

note any domain group does not reside on any local machine. they reside on domain controller/active directory.

That's why when you set up a new machine, and join it to a domain, it will prompt you for another username/password. This user must be able to add machine to domain (i.e. create machine accoutn in the domain).

Similarly, a local admin can disjoin his machine from domain. but if he does not he rights to remove the machine account from the domain, the machine account is still there even after disjoint. next time the local admin can join it again w/o the help of domain admin because the machine acccount want deleted last time. If a domain admin disjoins the machine, the machine account is gone. Rejoining needs "add to domain" rights again.

所有跟帖: 

domain方式連接問題CONT. -f64- 給 f64 發送悄悄話 (963 bytes) () 04/09/2004 postreply 12:16:43

domain方式連接問題CONT. -f64- 給 f64 發送悄悄話 (830 bytes) () 04/09/2004 postreply 12:24:50

domain方式連接問題CONT. -f64- 給 f64 發送悄悄話 (527 bytes) () 04/09/2004 postreply 12:39:02

請您先登陸,再發跟帖!

發現Adblock插件

如要繼續瀏覽
請支持本站 請務必在本站關閉/移除任何Adblock

關閉Adblock後 請點擊

請參考如何關閉Adblock/Adblock plus

安裝Adblock plus用戶請點擊瀏覽器圖標
選擇“Disable on www.wenxuecity.com”

安裝Adblock用戶請點擊圖標
選擇“don't run on pages on this domain”