 




<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: AD &#8211; Domain Users can join computers to Domain.</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/itanswers/ad-domain-users-can-join-computers-to-domain/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/itanswers/ad-domain-users-can-join-computers-to-domain/</link>
	<description></description>
	<lastBuildDate>Thu, 23 May 2013 01:41:43 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: maclanachu</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/ad-domain-users-can-join-computers-to-domain/#comment-43481</link>
		<dc:creator>maclanachu</dc:creator>
		<pubDate>Mon, 27 Nov 2006 15:32:19 +0000</pubDate>
		<guid isPermaLink="false">#comment-43481</guid>
		<description><![CDATA[Thanks everyone,

Quite surprised that any valid login can add a computer to the domain. Could have sworn that was restricted to Admins only.
The issue arose when someone with VPN access form home, added their home PC to the Domain. Not having that!
We are also rolling out a new ISA and VPN solution whereby we will be quarantining PCs that do not meet patchesAV requirements. But even still I don&#039;t think it&#039;s something users should be able to do without checking with Admins first.

rgds

Mac]]></description>
		<content:encoded><![CDATA[<p>Thanks everyone,</p>
<p>Quite surprised that any valid login can add a computer to the domain. Could have sworn that was restricted to Admins only.<br />
The issue arose when someone with VPN access form home, added their home PC to the Domain. Not having that!<br />
We are also rolling out a new ISA and VPN solution whereby we will be quarantining PCs that do not meet patchesAV requirements. But even still I don&#8217;t think it&#8217;s something users should be able to do without checking with Admins first.</p>
<p>rgds</p>
<p>Mac</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mortree</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/ad-domain-users-can-join-computers-to-domain/#comment-43482</link>
		<dc:creator>mortree</dc:creator>
		<pubDate>Wed, 22 Nov 2006 21:39:26 +0000</pubDate>
		<guid isPermaLink="false">#comment-43482</guid>
		<description><![CDATA[Something to worry about if rogue user servers are potential problem. Most people aren&#039;t going to do that as it is expensive.

But think about what an unauthorized workstation means - given that they still need a valid user logon to start with. OK they could bring a home machine into work and add it to the domain...and receive any GPO restrictions too. Problems? Hopefully your network has multiple layers of protection against malware (wroms/virii, etc), monitoring and intrusion devices anyway. The biggest threat is that they download data onto the home computer and take it home. You need a clear written well publized policy that any hardware or writeable media that comes to work is automatically donated to the company. It cannot leave except if the user is fired and all media undergoes Gutman overwrites of all data before release (loss of OS and personal data not reimbursed).

But other than that is this your biggest security issue? Bravo if so. ]]></description>
		<content:encoded><![CDATA[<p>Something to worry about if rogue user servers are potential problem. Most people aren&#8217;t going to do that as it is expensive.</p>
<p>But think about what an unauthorized workstation means &#8211; given that they still need a valid user logon to start with. OK they could bring a home machine into work and add it to the domain&#8230;and receive any GPO restrictions too. Problems? Hopefully your network has multiple layers of protection against malware (wroms/virii, etc), monitoring and intrusion devices anyway. The biggest threat is that they download data onto the home computer and take it home. You need a clear written well publized policy that any hardware or writeable media that comes to work is automatically donated to the company. It cannot leave except if the user is fired and all media undergoes Gutman overwrites of all data before release (loss of OS and personal data not reimbursed).</p>
<p>But other than that is this your biggest security issue? Bravo if so. </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: gphalpin</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/ad-domain-users-can-join-computers-to-domain/#comment-43483</link>
		<dc:creator>gphalpin</dc:creator>
		<pubDate>Wed, 22 Nov 2006 10:35:23 +0000</pubDate>
		<guid isPermaLink="false">#comment-43483</guid>
		<description><![CDATA[By default, all users can add ten PCs to the domain.  After that they will be denied access.  

You can change that in the Default Domain policy and specify which groups can add PCs, say domain admins and IT staff.  But be very careful. It&#039;s located under:
Computer Configuration &#124; Windows settings &#124; Security Settings &#124; User Rights Assignment &#124; Add Workstations to the Domain

You can also change the location of where computer accounts get created when they are added to the domain so that they don&#039;t sit in the Computers container.  You could have them automatically get created in an OU which has policies applied to it--so that the PCs get whatever firewall or software policies they need.  

Regards,

Greg]]></description>
		<content:encoded><![CDATA[<p>By default, all users can add ten PCs to the domain.  After that they will be denied access.  </p>
<p>You can change that in the Default Domain policy and specify which groups can add PCs, say domain admins and IT staff.  But be very careful. It&#8217;s located under:<br />
Computer Configuration | Windows settings | Security Settings | User Rights Assignment | Add Workstations to the Domain</p>
<p>You can also change the location of where computer accounts get created when they are added to the domain so that they don&#8217;t sit in the Computers container.  You could have them automatically get created in an OU which has policies applied to it&#8211;so that the PCs get whatever firewall or software policies they need.  </p>
<p>Regards,</p>
<p>Greg</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tommski</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/ad-domain-users-can-join-computers-to-domain/#comment-43484</link>
		<dc:creator>tommski</dc:creator>
		<pubDate>Wed, 22 Nov 2006 10:24:29 +0000</pubDate>
		<guid isPermaLink="false">#comment-43484</guid>
		<description><![CDATA[In &quot;Domain Security Polcies&quot;, under &quot;User Rights&quot; you will see &quot;Add 
workstations to domain&quot;.
Define this right for administrators only.]]></description>
		<content:encoded><![CDATA[<p>In &#8220;Domain Security Polcies&#8221;, under &#8220;User Rights&#8221; you will see &#8220;Add<br />
workstations to domain&#8221;.<br />
Define this right for administrators only.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached
Database Caching 3/8 queries in 0.036 seconds using memcached
Object Caching 311/312 objects using memcached

Served from: itknowledgeexchange.techtarget.com @ 2013-05-23 02:45:52 -->