Server - Domain Users can join computers to domain (up to 10) #It is a default domain policy

Few months I discovered that normal AD users are able to join computers to domain (up to 10) without particular grants or settings.

It was a very unexpected news for me.

Default limit to number of workstations a user can join to the domain

"By default, Windows 2000 allows authenticated users to join ten machine accounts to the domain.

This default was implemented to prevent misuse, but can be overridden by an administrator by making a change to an object in Active Directory.

Note that users in the Administrators or Domain Administrators groups, and those users who have delegated permissions on containers in Active Directory to create and delete computer accounts, are not restricted by this limitation."



Here it is AD attribute that define 10 maximum join numbers (you need to to use ADSIEdit.msc):

MS-DS-Machine-Account-Quota

https://docs.microsoft.com/en-us/windows/win32/adschema/a-ms-ds-machineaccountquota?redirectedfrom=MSDN

It is highly recommended to disable this features due to obviously security reasons:

https://docs.microsoft.com/en-us/archive/blogs/dubaisec/who-can-add-workstation-to-the-domain

REMEDIATION:

Due to security reasons is preferable that Authenticated Users cannot join domain computers.

You must modify "Default Domain Policy" permitting domain joins to specifics user or group.

Rafal Sosnowski (Microsoft Dubai Security PFE Team's member) says:

During my numerous Security Audits and Assessments I deliver to customers, I usually discover too wide permissions and user rights configured in Active Directory. One of them is “Add Workstation to the Domain”

It is important to control who can add new machines to our AD environment. Although we can enforce various security settings via GPO on newly added machines, user could join machine which is not configured according to our security standards and at the same time having ownership of various objects in the system (local admin account, ACLs on file system etc.).

<==================>

Here it is full article:

https://www.devadmin.it/2017/07/25/consentire-ad-utenti-non-amministratori-di-aggiungere-computer-a-dominio/


[update 2022.11.02]

KB5020276—Netjoin: Domain join hardening changes


Extra IT - Legnovivo #carpentry company

Oggi vorrei raccomandare questo sito web ed azienda di falegnameria

www.falegnamefirenze.it

I loro prodotti di alta qualita' e la loro professionalita' sono due punti chiave di quest'azienda.

Ho gia' acquistato, nei precedenti anni, diversi prodotti con grande soddisfazione. 

Mi sento di raccomandarli fortemente 

<====================>

Today I would like to endorse below website and carpentry company:

www.falegnamefirenze.it

High quality wood products and professionalism are their two company key points strength.

I already purchased, in previous years, several products with excellent satisfaction. I strongly suggest them:





201X - Print Server migration/fault/DR management

If you want manage Windows 200X/201X print server fault and relative DR (without having to reconfigure all clients) you have to proceed in this way:

  1. Create a properly DNS alias (on DC) pointing to old print server 
    for example: PrintersMilan

  2. Configure a new print server. (201X)

  3. Export all printers on old print server.

    2003 migration - How to migrate print server from 2003 server to 2008/2008 R2/2012

  4. Import previous printer queues on new Server:

    2003 migration - How to migrate print server from 2003 server to 2008/2008 R2/2012

  5. To avoid below error trying to add new printers (using DNS Alias):

    \\PrintersMilan\







  6. On old and new server you must add this register key:

    reg add HKLM\SYSTEM\CurrentControlSet\Control\Print /v DnsOnWire /t REG_DWORD /d 1



  7. Restart Print spooler service:


  8. On your PC add new printers and check that is working properly (you still are pointing to old print server)
    \\PrintersMilan\

  9. Change DNS Alias PrintersMilan (on your DC) to point new print server.

  10. If everything is working fine DR and print server fault management was succesfully done

[Original Article]


Tuning - Patch My PC

In previously years I used several tools to check no O.S. software updates.

Unfortunately FileHippo App Manager is no longer working fine as in the past.

So I found that Patch My Pc Updater is working excellently, user interface is not so easy but, after you configured properly it work very fine.

About Enterprise companies easily extend Microsoft Configuration Manager to deploy and patch an extensive list of third-party applications.

About SCCM here they are old blog articles

https://www.alessandromazzanti.com/search/label/SCCM%202012


Here it is lifewire article where are indicated similar software.

11 Best Free Software Updater Programs

https://www.lifewire.com/free-software-updater-programs-2625200

Freeware - ebook Reader - Adobe Digital Editions

If you need to open ebook using computer, Apple and Android devices Adobe Digital Editions is freeware and it work fine.

Here it is relative link