Active directory

Siddhesh Mayekar 75 Reputation points
2025-04-16T19:09:27.03+00:00

We observed that normal domain users without administrative rights are still able to join or remove systems from the domain. How is this possible, and what are the ways to restrict this behavior? Also let me know the best practices.

Windows for business | Windows Server | User experience | Other
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Hoang Phan0701 75 Reputation points Independent Advisor
    2025-08-11T07:37:24.96+00:00

    Dear Siddhesh Mayekar,

    My name is Hoang Phan, and I understand that you are having some query concern related to domain join.

    In my experience, standard users are typically able to join devices to a domain unless specific restrictions are in place.

    To prevent this, configure the "Add Workstations to Domain" Group Policy setting. This policy lets you define which users are permitted to join devices to the domain. Remember, it must be applied to domain controllers for the changes to take effect.

    I hope this information proves helpful. Please don’t hesitate to reach out if you need further clarification—I’ll be happy to assist 🙂


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    Best regards,

    Hoang Phan

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.