Saturday, June 6, 2015

Just-in-time Active Directory Prestaging with WDS Admin Approval Mode

I have been experiencing issues with automated domain join - I don't want to place admin credentials in clear text, but the WDS standard join doesn't seem to be working with a specialize-pass unattend file. I also didn't want to manually prestage computer accounts, because I have a sizable quantity of computers, so manually creating a bunch of accounts and typing in GUIDs would be a pain.

I did some reading, and WDS has a neat mode in which machines are not able to PXE boot to that server until an administrator approves the machine. That approval creates a prestaged Active Directory account for that computer with the network boot GUID attribute automatically filled. That mode can be entered by configuring the PXE Response tab on the WDS server properties window.

Then, machines should be able to automatically join the domain with the name the administrator approves the machine for - no need to type out GUIDs.

No comments:

Post a Comment