Delegation of Control to enable Offline Domain Join

This document provides step-by-step instructions for delegating control to a domain user, enabling them to perform offline domain joins beyond the default limit of 10 computers without requiring domain admin privileges. The process involves configuring permissions in Active Directory Users and Computers for the relevant Organizational Units. For further details on domain join installation and configuration, refer to the BigFix MCM Help Center.

About this task

Below steps are required to be performed on the domain controller from Active Directory Users and Computers console. Execute below steps on all the required Organizational Units (OUs) to which the computers are Hybrid AD joined.

Procedure

  1. Right click on the Organizational Unit (OU) and select Delegate Control option to open the Delegation of Control wizard
  2. Add the user, for whom the Offline Domain Join permission should be enabled.
    Graphical user interface, text, application Description automatically generated
  3. Choose custom task option to delegate

    Graphical user interface, text, application Description automatically generated

  4. Select only computer objects and allow create, delete objects.

    Graphical user interface, text, application Description automatically generated

  5. Grant full control and complete the wizard

    Graphical user interface, application Description automatically generated

    For complete information about Domain join installation and configuration, refer to the BigFix MCM Help Center at Domain join installation and configuration