Good morning, I’d like to see what the group thinks about this. We have a vendor who prepares PCs for us with our image, and then ships them out to our field locations pre-configured. They’d like to take that a step further, and actually pre-join the PC to the domain before it leaves their facility. To do this, we would have to set up a secure connection between our facility and the vendor’s. If we do this, I’d obviously like to make this as limited as possible in terms of what the user at the vendor is allowed to do.

 

My initial thoughts are:

  1. see if I can determine what ports are needed for a PC to join a domain, and limit the ports to those
  2. see if I can limit the rights of the vendor “user” to be able to do nothing but join a PC to the domain

 

Right now, I have no idea if this is a good idea, common practice, etc., so I’m very interested in the advice from this list – especially if there might be a good solution to this problem other than the way we’re considering. Thanks as always,

 

Mark Creamer

Systems Engineer

Cintas Corporation

Honesty and Integrity in Everything We Do

 

Reply via email to