Hi Vishal Kumar,
- Yes,
MAQ=0 + GPO-onlyis a dead end for ordinary delegated users, because theAdd workstations to domainright does not exempt them fromms-DS-MachineAccountQuota. Microsoft explains the behavior here: Default limit to number of workstations a user can join to the domain - As far as I know, there is no native per-user or per-group MAQ setting so approach B is the native way to get approximately the policy you described.
- MAQ is based on existing computer objects attributed to the creator through
mS-DS-CreatorSID; it is not a lifetime counter. Deleting an attributed computer object therefore frees that quota slot. - If 10 is a hard control, use B; If the goal is primarily to prevent unauthorized computer creation, I would choose A.