Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Updated links in the proper manner.

In order to join your SoftNAS instance to Active Directory, you must first create a user with adequate permissions to perform the task.


Method 1:

You can create Create a domain user with the appropriate credentials by creating a domain user, and adding it to the default group found in Windows Server domains called Account Operators. This group carries and provides its users with all the required permissions.

Method 2:

An alternative method is to assign Assign the rights to the domain user or group by using the Default Domain Group policy. To assign the appropriate rights, follow the below steps: 

  •  Login to the domain controller and launch the Group Policy Management console.

  •  Right-click the Default Domain Policy and click Edit.

Image RemovedImage Added

  •  Navigate through Computer Configuration > Windows Settings > Security Settings > Local Policies > User Rights Assignment.

  •  Expand User Rights Assignment.

  •  On the right hand side double-click Add workstations to Domain domain policy.

Image RemovedImage Added

  •  Check the box Define these policy settings.

  •  Click Add User or Group and select the user or group.

  •  Click Apply and OK. Next, it

Note
It is a good idea to also set up permissions using AD Users and Computers.


  •  Open the Active Directory Users and Computers snap-in. Right

  •  Right-click the container under which you want the computers to be added (for example, the Computers container) and click .

  •  Click on Delegate Control.

Image RemovedImage Added

  •  You will now see the Delegation of Control Wizard. Click Next.

  •  To add a user or group click click the Add... button.

  •  Once you are done click Nextdone, click the Next button.

Image RemovedImage Added

  •  In Tasks to Delegate,  click Create a custom task to delegate. Click Next

  •  Once done, click the Next button.

Image RemovedImage Added

  •  Choose Only the following objects in the folder and check the box Computer Objects.  Click Next 

  •  Once done, click the Next button.

Image Modified

  •  In Permissions Show these permissions, check the Property-specific check-box and select .

  •  Under Permissions, check Read userPrincipalName and Write userPrincipalName in the Permissions section. Click Finish

  •  Once done, click the Next and Finish button

Image AddedImage Removed