1. Symptoms
Sometimes, when the client is added to the domain, the following prompt is displayed:
2. Problem Analysis
The client uses the Lightweight Directory Access Protocol (LDAP) server or domain controller that has not been copied to this account to delete, but does not modify the correct permissions of the account that is still retained.
3. Solutions
To solve this problem, you can use any of the following methods:
- Use another computer name.
- Wait for Active Directory to copy, or use the following command to force the copy:Repadmin/syncDomainDNTarget DSA GUID. _ MsdcsSource DSA GUID/Force
- Use the domain administrator account when you join the account.
- Grant additional permissions to the account you are using:
- Start Adsiedit. msc.
- Open "Domain NC, DC =Domain, CN = Computers "node.
- Click computer, and then click Properties ".
- On the Security tab, click Advanced ".
- Click Add, and then click the appropriate user account or group.
- In the apply to box, click computer objects ".
- In the "Permissions" pane, click to select the "write all attributes", "Reset Password", and "apply these permissions only to objects and/or containers in this container" check box.
- Click OK until the change is made.
- Wait for Active Directory to copy or force synchronization.
This article is from the "zhushui liunian" blog