In WDS, does it really work while joining domain unattended with JoinRights set to JoinOnly?


i've been experimenting windows deployment services on windows server 2012 r2, trying deploy server core , join domain unattended.

however, when performing unsecure join, "test-user" can succeed when joinrights set full following command:

wdsutil /set-device /device:test-wds-client /joinrights:full /user:test-user

whereas setting joinrights joinonly result in failure 0x80070005, i.e. access denied. wdsutil doc says, 

joinonly requires administrator reset computer account before user can join computer domain.

i've reset computer account in both wds mmc console , active directory users , computers, neither way worked.

inspecting computer account, acl has 2 more deny aces "test-user" in beginning, when joinrights set joinonly compared full. 1 ace changing password , other resetting password.

therefore, these deny aces seems impossible "test-user" join computer domain. interpretation correct?



hi,

>>i've reset computer account in both wds mmc console , active directory users , computers, neither way worked.

a user has join rights cannot join domain without administrator assistance (an administrator proper permissions on computer account object must reset computer account before the client installation , domain join). user has full rights can reset account , join domain without administrator assistance.

please make sure reset has been performed before installation , domain join.

best regards.


steven lee please remember mark replies answers if , unmark them if provide no help. if have feedback technet support, contact tnmff@microsoft.com.



Windows Server  >  Setup Deployment



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS