While joining (for the first time) workstations to the domain provided by our server running Windows Server Essentials, I've encountered the following subtle behavior:
The account that I would use to join the domain, using the Windows Server Connector invariably becomes a member of the Local Administrators group, thus inherits privileges I didn't want it to inherit in first instance.
Basically I first tried to join the workstation using an account from the Domain Administrators group but received a warning from the wizard in using such account, therefore I've used one of the standard account that would be later used by users.
Question: shall one use a 'domain-joining-specific' or some 'domain-operator' account for joining a workstation to a domain, or is there a better workflow for such task ?