SOLVED AD service fails to start, unless account is in "Domain Admin" group

Status
Not open for further replies.

jharm73

Cadet
Joined
Oct 30, 2015
Messages
6
I CAN get the AD service to start when making the user part of the "Domain Admins" group. As most system admins, I like to follow least privilege scenario. What rights do I need to delegate to my service account to be able start the AD service. I have already tried giving it access to add computer objects to the domain, but it must need something more.
 

jharm73

Cadet
Joined
Oct 30, 2015
Messages
6
I created à standard service account (normal account with service name) , and give full control over computer account corresponding to freenas computer under security tab of computer account properties

(got this from another user on another thread)
 
Status
Not open for further replies.
Top