How do I setup an AD account that is only used during Windows 7 unattended rollouts to join the machine to a domain? Is there a best practice regarding this? Many thanks.