I delete computer from active directory and
I ran from the computer "net join -U regular_user%password -I DC_IP -S DC_NAME -w DOMAIN_NAME -s smb.conf_path" by root and it succeed
My question how . Can any user create new computer in domain controller
No, when running in security=ads only accounts that have full domain admin rights can join. When running in security=domain, any account that has the "join" privilege can join machines to the domain.
The fact that security=ads requires high permissions is another bug that we might fix soon.