Symptom
Failed to join AD server using a non-administrative account.
Diagnosis
This issue is related to permission settings in the AD server and cannot be solved from the GS side.
Solution
Set the necessary permissions and related settings for the account in the AD server. Follow these steps:
- In Active Directory Users and Computers:
- Open the Delegation of Control Wizard.
- Add the user account.
- Create a Custom Task to Delegate:
- Select “Create a custom task to delegate”.
- Select “only the following objects in the folder” and check “Computer objects”.
- Check “Create selected objects in this folder” and “Delete selected objects in this folder”.
- Set Permissions:
Under permissions, select “General” and check the following:- “Reset password”
- “Read and write account restrictions”
- “Validated write to DNS host name”
- “Validated write to service principal name”

By following these steps, you can ensure that the user account has the necessary permissions to join the AD server successfully.