I work for a large company that has acquired multiple additional sites over the last 5 years. We're fully integrated these sites into our corporate site. The problem I'm running into now is, most of the sites have a local admin, and these admins don't always play nice with us.
So what's happening is, sometimes we have new servers added and old servers decommissioned at these sites without involving the server team. I'm looking for a way to restrict the join domain privilege based on operating system type. So I want to restrict all server domain join functions to the server team only. The site people still need to be able to add workstations to the domain.