mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-06-17 19:33:37 +00:00
Merge remote-tracking branch 'refs/remotes/origin/master' into vs-10202987
This commit is contained in:
@ -107,10 +107,10 @@ When you run Windows ICD, you have several options for creating your package.
|
||||
|
||||
> [!WARNING]
|
||||
> If you don't create a local administrator account and the device fails to enroll in Active Directory for any reason, you will have to reimage the device and start over. As a best practice, we recommend:
|
||||
|
||||
- Use a least-privileged domain account to join the device to the domain.
|
||||
- Create a temporary administrator account to use for debugging or reprovisioning if the device fails to enroll successfully.
|
||||
- [Use Group Policy to delete the temporary administrator account](https://blogs.technet.microsoft.com/canitpro/2014/12/10/group-policy-creating-a-standard-local-admin-account/) after the device is enrolled in Active Directory.
|
||||
>
|
||||
>- Use a least-privileged domain account to join the device to the domain.
|
||||
>- Create a temporary administrator account to use for debugging or reprovisioning if the device fails to enroll successfully.
|
||||
>- [Use Group Policy to delete the temporary administrator account](https://blogs.technet.microsoft.com/canitpro/2014/12/10/group-policy-creating-a-standard-local-admin-account/) after the device is enrolled in Active Directory.
|
||||
|
||||
9. Click **Finish**.
|
||||
10. Review your settings in the summary. You can return to previous pages to change your selections. Then, under **Protect your package**, toggle **Yes** or **No** to encrypt the provisioning package. If you select **Yes**, enter a password. This password must be entered to apply the encrypted provisioning package.
|
||||
|
Reference in New Issue
Block a user