If the domain that the managed computer is joining does not have at least one Windows Server 2008 R2 domain controller, you must manually grant write permission for the Operating System Version and msDS-supportedEncryptionTypes attributes to the user account used to join the computer to the domain.
- Open Active Directory Users Computers or ADSI Edit.
- Expand the Computers container and select the computer that is joining the domain, right-click, then click Properties.
- Click the Security tab, then click Advanced.
- Click Add.
- In the “Enter the object name to select” field, type the name of the Active Directory user who will join the computer to the domain and click OK.
Click the Properties tab, select This object only from the Apply to list, then scroll down and click Allow for the following attributes:
- Write msDS-supportedEncryptionType
- Write Operating System Version attributes
- Click OK in each dialog box to close the dialog and save the new permissions.