We use cookies on this website. To find out more about cookies and how they are used on this website, see our Privacy Policy.
By clicking ‘Continue’, you hereby agree with our use of cookies.

Knowledge Base

How to Fix AD Join Failure Due to Insufficient User Permissions?

Last modified date: Thu, 24 Oct 2024 15:58:21 GMT+8

Symptom

Failed to join AD server using a non-administrative account.

Diagnosis

This issue is related to permission settings in the AD server and cannot be solved from the GS side.

Solution

Set the necessary permissions and related settings for the account in the AD server. Follow these steps:

  • In Active Directory Users and Computers:
    1. Open the Delegation of Control Wizard.
    2. Add the user account.
  • Create a Custom Task to Delegate:
    1. Select “Create a custom task to delegate”.
    2. Select “only the following objects in the folder” and check “Computer objects”.
    3. Check “Create selected objects in this folder” and “Delete selected objects in this folder”.
  • Set Permissions:
    Under permissions, select “General” and check the following:
    1. “Reset password”
    2. “Read and write account restrictions”
    3. “Validated write to DNS host name”
    4. “Validated write to service principal name”
      Set Permissions

By following these steps, you can ensure that the user account has the necessary permissions to join the AD server successfully.

Was this article helpful?Yes | No

Thank you for your feedback!

Do you have any other feedback for this article?

{{ vm.showErrorMessage }}