NetAppDocs / NetAppDocs/ontap

Document minimal required permissions for the domain join user

Open
#1,853 0 comments 0 reactions 1 assignee View on GitHub

@netapp-lenida is already working on this.

Since Dec 23, 2025.

Dominant language
No language data
Stars
39
Forks
87
Avg merge
27m
Merged PRs (30d)
11

Description

Page URL

https://docs.netapp.com/us-en/ontap/smb-config/create-server-active-directory-domain-task.html

Page title

Create SMB servers in an ONTAP Active Directory domain

Summary

vserver cifs create requires the administrator to specify Active Directory credentials for an AD user or AD service account user. This user needs permissions to join the SVM to the specified AD or organisational unit. Security sensitive users will not use Domain Admin credentials, but create a dedicated domain join user with least possible permissions. We need to document what are the minimal permissions.

Here is the Microsoft page on what is required to join Windows systems: https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/active-directory-domain-join-permissions
AFAIK ONTAP requires a few more permissions compared to a Windows host to successfully join a domain. Please document the AD permissions required for a minimal domain join service account.

Public issues must not contain sensitive information
  • This issue contains no sensitive information.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.