By default, what is the lowest permission needed to join computers to an Active Directory domain?
- Schema Admin
- Domain Admins
- Authenticated Users
- Enterprise Admins
EXPLANATION
By default any Authenticated User can add up to 10 computers to a domain. The risk with this could be that a user sets up a new workstation and give themselves an admin account on the computer, then add it to the domain using their domain account.With these elevated permissions they could do many things. Most notably, but not limited to, the higher chance of getting a virus on the system to an inexperienced user.
0 comments:
Post a Comment