Document minimal required permissions for the domain join user
@netapp-lenida is already working on this.
Since Dec 23, 2025.
- Dominant language
- No language data
- Stars
- 39
- Forks
- 87
- Avg merge
- 27m
- Merged PRs (30d)
- 11
Description
Page URL
https://docs.netapp.com/us-en/ontap/smb-config/create-server-active-directory-domain-task.html
Page title
Create SMB servers in an ONTAP Active Directory domain
Summary
vserver cifs create requires the administrator to specify Active Directory credentials for an AD user or AD service account user. This user needs permissions to join the SVM to the specified AD or organisational unit. Security sensitive users will not use Domain Admin credentials, but create a dedicated domain join user with least possible permissions. We need to document what are the minimal permissions.
Here is the Microsoft page on what is required to join Windows systems: https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/active-directory-domain-join-permissions
AFAIK ONTAP requires a few more permissions compared to a Windows host to successfully join a domain. Please document the AD permissions required for a minimal domain join service account.
Public issues must not contain sensitive information
- This issue contains no sensitive information.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.