FAQ: Joining AD without Domain Admin

A domain admin needs to give these rights to a user who doesn't have domain admin privileges to join a computer to the domain.

1. Create a new computer Object.

2. Start ADSI Edit

3. Find and select the Computer Object you just created.

4. Right Click on Properties and select the Security Tab.

5. Add the User that is going to be used to join the domain on the Nexenta Host.

6. Click Advanced.

7. Select the user that is going to join the domain from the Nexenta host, and click Edit.

8. Click on the properties tab.

9. Enable Write userPrincipalName and Write userAccountControl

Now you can go into NMV and join the domain using a non domain admin account.