The Samba-Bugzilla – Bug 9978
SEC_PRIV_MACHINE_ACCOUNT is not honored
Last modified: 2015-10-13 21:23:29 UTC
Default domain policy for domain controller grants this privilege to all authenticated users, as we don't parse GPO for the moment this is not set.
But even if you modify manually the privilege.ldb to grant this privilege to authenticatedusers then a simple users can't create a computer using for instance an LDAP add request (in windows 2012 this is working).
More detail is in this later bug, so marked as duplicate
*** This bug has been marked as a duplicate of bug 10656 ***