How to Limit AD Domain Users from Joining Computers to the Domain

active-directorydomainwindows

We are trying to prevent users from willy-nilly joining VMs and outside machines to our domain. The default is any user can join up to 10 machines. Is there a way to limit this to only Account Operators, Domain Admins, and Enterprise Admins?

Best Answer

Go into your Domain Security Policy>Local Policy>User Rights Assignment and change the "Add workstations to domain" to just the groups you want.

enter image description here