Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >

KB-1788: Why domain admin authority is needed when running the adjoin command with option -T or --trust

Auditing and Monitoring Service ,   Authentication Service ,   Mac & PC Management Service ,  

12 April,16 at 11:11 AM

Applies to:

All versions of Centrify DirectControl


Why is the domain admin authority required to join machines with -T or --trust flag ?


-T flag of adjoin means "trust computer for delegation". An Active Directory user with delegated permissions to create and delete computer objects will not be
able to join machines with -T option. “Enable User and Computer account to be trusted for Delegation” AD permission needs to be granted to an AD user in order to use
-T option to specify a computer account to be trusted for delegation.

For reference please use the Knowledge Base article from Microsoft:

By default, domain admin has this permission. For non-admin user, enable the following group policy to grant this permission:

"Computer Configuration" > "Windows Settings" > "Security Settings" > "Local Policies" > "User Rights Assignment" > "Enable computer and user accounts to be trusted for delegation".