Machine object is already in AD

Bonus12 1,116 Reputation points
2020-10-13T00:39:52.01+00:00

Hi All ,

A task sequence completed imaging windows 10 machine but the machine didn't join the domain , looking at the netsetup log I found the following error:

problem 4003 (INSUFF_ACCESS_RIGHTS), data 0

I'm sure the "domain join account" have sufficient permissions to create the machine object in the OU named "B" . but also I know this machine have an object in AD in a different OU "A" where the domain join account doesn't have permissions to.

I just don't understand , why the domain join account needs permissions to the OU where the machine currently exist "A" , why permissions to "B" is not enough?

Thanks

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,161 questions
Microsoft Configuration Manager Deployment
Microsoft Configuration Manager Deployment
Microsoft Configuration Manager: An integrated solution for for managing large groups of personal computers and servers.Deployment: The process of delivering, assembling, and maintaining a particular version of a software system at a site.
930 questions
Microsoft Configuration Manager
0 comments No comments
{count} votes

Accepted answer
  1. Jason Sandys 31,186 Reputation points Microsoft Employee
    2020-10-13T12:49:57.39+00:00

    No, it won't be moved. It is reused, as is, and in-place.

    If that's your intent, you need to implement an additional process to either move the account or delete it before the process begins to side-step your initial permissions issue also.

    0 comments No comments

2 additional answers

Sort by: Most helpful
  1. Jason Sandys 31,186 Reputation points Microsoft Employee
    2020-10-13T01:15:52.757+00:00

    Because that's the way it works. If an object for the system already exists, then that object will be reused and thus the account used must have permissions on the existing object.

    0 comments No comments

  2. Bonus12 1,116 Reputation points
    2020-10-13T01:38:09.95+00:00

    So when you say the machine object will be reused , do you mean it will be moved ?

    so if I grant the domain join account a permission to the old OU , now I expect the machine object will be moved from old OU to the new OU ?

    0 comments No comments