Active Directory: MachineAccountQuota 0 vs SeMachineAccountPrivilege and per-user computer account limits

Vishal Kumar 125 Reputation points
2026-10-01T04:44:20.7666667+00:00

Working on remediating "Non-privileged users can add computer accounts to the domain."

Current default:

  • ms-DS-MachineAccountQuota (MAQ) = 10
  • SeMachineAccountPrivilege granted to Authenticated Users

Requirement: one service-account group should be able to join machines, max 10 per account, while everyone else should have 0.

Proposed solution was MAQ=0 + GPO granting Add workstations to domain only to that group.

My understanding is that this won't work because SeMachineAccountPrivilege is still subject to MAQ. With MAQ=0, the group would also have a quota of 0.

The two approaches I see are:

A) MAQ=0 + delegate Create Computer Objects on a specific OU to the group. → Everyone else blocked, but the group effectively has unlimited creation rights in that OU.

B) Keep MAQ=10 + remove Authenticated Users from SeMachineAccountPrivilege and grant it only to the group. → Group gets 10 per user; everyone else gets 0.

Questions:

  1. Is MAQ=0 + GPO-only definitely a dead end?
  2. Is there any native per-user/per-group MAQ mechanism?
  3. Is the quota cumulative via mS-DS-CreatorSID, meaning deleting a computer doesn't necessarily free the quota?
  4. Which approach do you typically use in production: A or B?

I'm leaning toward A with OU scoping + monitoring, since the "10" requirement seems more like a security cap than a hard compliance requirement.

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
0 comments No comments

Answer accepted by question author
Scott Nguyen 2,130 Reputation points Independent Advisor
2026-10-01T06:07:17.14+00:00

Hi Vishal Kumar,

  1. Yes, MAQ=0 + GPO-only is a dead end for ordinary delegated users, because the Add workstations to domain right does not exempt them from ms-DS-MachineAccountQuota . Microsoft explains the behavior here: Default limit to number of workstations a user can join to the domain
  2. As far as I know, there is no native per-user or per-group MAQ setting so approach B is the native way to get approximately the policy you described.
  3. MAQ is based on existing computer objects attributed to the creator through mS-DS-CreatorSID; it is not a lifetime counter. Deleting an attributed computer object therefore frees that quota slot.
  4. If 10 is a hard control, use B; If the goal is primarily to prevent unauthorized computer creation, I would choose A.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

0 additional answers

Sort by: Oldest

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.