Unable to give a non Domain Admin access to rename a Computer through delegated permissions

Anonymous
2024-10-03T15:56:47+00:00

We have given our Service Desk permissions to be able to rename a domained laptop through delegated permissions on computer objects to a container which contains all of our hybrid joined Laptops however when they try to rename a laptop they get the error message:

Can't change the PC name using this account.

The delegated permissions that have been given are the below:

Write All Properties

Validated write to DNS host name

Validated write to service principal name

The users are part of a Security group which is included as Local Admin on the laptop and we have verified that works as they are able to elevate using UAC. The only issue we are having is the renaming a PC part.

On the DC we have also updated the local security policy (Security Settings > Local Policies > Security Options > Network access: Restrict clients allowed to make remote calls to SAM) to include the above security group but that also hasn't worked.

Does anyone know what else we can try to get this part working? The only thing that has worked is temporarily giving them Domain Admin which we do not want to do permanently.

Windows Server Identity and access Active Directory

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question. To protect privacy, user profiles for migrated questions are anonymized.

0 comments No comments
{count} vote

5 answers

Sort by: Most helpful
  1. Anonymous
    2024-10-04T10:10:06+00:00

    Hello Stokesy_889,

    Thank you for posting in Microsoft Community forum.

    You can try the following four permissions and check if it helps.

    Image

    You can also give the user or group permissions below via Security tab, then check if it helps.

    Image

    I hope the information above is helpful.

    If you have any question or concern, please feel free to let us know.

    Best Regards,
    Daisy Zhou

    0 comments No comments
  2. Anonymous
    2024-10-04T11:48:36+00:00

    Hi Daisy,

    Thanks for coming back to me,

    I have tried this with all the settings you have mentioned and asked the Service Desk to test this again however we are still getting the same error message:

    Can't change the PC name using this account.

    Is there anything else to try?

    Thanks

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2024-10-07T08:44:07+00:00

    Hello

    Greetings!

    You can try the permissions below and check if it helps.

    If it does not work, it seems it needs "Full Control" permission.

    Best Regards,
    Daisy Zhou

    0 comments No comments
  4. Anonymous
    2024-10-15T10:08:46+00:00

    Hi Daisy,

    We have tried this but this still doesn't allow the user to rename a domain laptop.

    I'm sure in the past we have given them Full Control over the OU containing the laptops and that still hasn't allowed them to do it. The only way seems to be giving Domain Admin access which obviously we want to avoid doing.

    Thanks

    0 comments No comments
  5. Anonymous
    2024-10-15T12:38:25+00:00

    Hello

    Good day!

    If you have given user or user group Full Control over the OU containing the domain machines, you still cannot change the machine name.

    1.Please check the option "Protect object from accidental deletion". Do not check the option.

    2.Please check if this user has Full Control permissions on this machine via Effective Access tab.

    3.If it is not the case about 1 and 2, I suggest you let one account in Domain Admins to rename the machines.

    Best Regards,
    Daisy Zhou

    0 comments No comments