cancel
Showing results for 
Search instead for 
Did you mean: 

What AD privileges are required to join domain?

What AD privileges are required to join domain?

Anonymous
Not applicable

Hi,

What account privileges are required to join the A3 to the domain?

With ExtremeControl there is a definitive set of privileges that are required for joining the domain. Its not generally going to be Ok to get full domain privileges account, hence be good to know exactly what is required - maybe it is even the same as the below?

 

https://extremeportal.force.com/ExtrArticleDetail?an=000090980&q=nac%20ntlm%20privalages

 

Many thanks in advance

1 ACCEPTED SOLUTION

OscarK
Extreme Employee

The account needs to be able to create a computer account, similar to adding a computer to a domain.

It would need the same privileges and it is only once for the add, after that a normal user account is used for checking.

View solution in original post

4 REPLIES 4

Bill_Handler
Contributor II

Martin,

An AD account that has ‘Account Operator’ privileges works for this purpose.

OscarK
Extreme Employee

The account needs to be able to create a computer account, similar to adding a computer to a domain.

It would need the same privileges and it is only once for the add, after that a normal user account is used for checking.

Anonymous
Not applicable

Hi Oscar,

Thanks for responding, sorry, the latter is what what I meant.

Is there a set of privileges that you aware of that would be needed for this, as asking for a full domain admin account usually creates an issue, for obvious reasons.

With Extreme Control I could provide the link above and the domain admins could create a cut down version account that didn’t essentially give me the keys to the kingdom, which is the root of the problem.

Cheers

OscarK
Extreme Employee

Hi Martin, in the authentication source the account used does not have to be an admin account.

The distinguished name for the user account that A3 will use to conduct user lookups; this does not need to be the Administrator’s account.

When you create and join the Domain in Active Directory you need an administrator account as it needs to add A3 as computer to the domain.

 

GTM-P2G8KFN