<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Granular permissions used by the Windows account used to join CIFS to the domain in AFF</title>
    <link>https://community.netapp.com/t5/AFF/Granular-permissions-used-by-the-Windows-account-used-to-join-CIFS-to-the-domain/m-p/438736#M1106</link>
    <description>&lt;P&gt;Hi there!&lt;/P&gt;&lt;DIV class=""&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any user who is authorized to create machine accounts in the AD domain to which you are joining the SMB server can create the SMB server on the SVM. This can include users from other domains.&lt;/P&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Beginning with ONTAP 9.7, your AD administrator can provide you with a URI to a keytab file as an alternative to providing you with a name and password to a privileged Windows account. When you receive the URI, include it in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;-keytab-uri&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;parameter with the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;vserver cifs&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;commands.&lt;/P&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;We have more information at&amp;nbsp;&lt;A href="https://docs.netapp.com/us-en/ontap/smb-config/create-server-active-directory-domain-task.html" target="_blank" rel="noopener"&gt;https://docs.netapp.com/us-en/ontap/smb-config/create-server-active-directory-domain-task.html&lt;/A&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;From memory, "create machine account" is a permission that can be set in ADUC.&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Hope this helps!&lt;/DIV&gt;</description>
    <pubDate>Thu, 29 Sep 2022 03:00:46 GMT</pubDate>
    <dc:creator>AlexDawson</dc:creator>
    <dc:date>2022-09-29T03:00:46Z</dc:date>
    <item>
      <title>Granular permissions used by the Windows account used to join CIFS to the domain</title>
      <link>https://community.netapp.com/t5/AFF/Granular-permissions-used-by-the-Windows-account-used-to-join-CIFS-to-the-domain/m-p/438719#M1105</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know the granular permissions used by the Windows account used to join CIFS to the domain during the initial filer setup? We are being tasked with removing "Domain Admins" membership from the account we used. I was directed to an article that indicated this should not effect filer operations. But, we'd like to know the permissions required by the Windows account used during CIFS getting joined to the domain. Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 21:19:45 GMT</pubDate>
      <guid>https://community.netapp.com/t5/AFF/Granular-permissions-used-by-the-Windows-account-used-to-join-CIFS-to-the-domain/m-p/438719#M1105</guid>
      <dc:creator>NetAppPhiler</dc:creator>
      <dc:date>2022-09-28T21:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: Granular permissions used by the Windows account used to join CIFS to the domain</title>
      <link>https://community.netapp.com/t5/AFF/Granular-permissions-used-by-the-Windows-account-used-to-join-CIFS-to-the-domain/m-p/438736#M1106</link>
      <description>&lt;P&gt;Hi there!&lt;/P&gt;&lt;DIV class=""&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any user who is authorized to create machine accounts in the AD domain to which you are joining the SMB server can create the SMB server on the SVM. This can include users from other domains.&lt;/P&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Beginning with ONTAP 9.7, your AD administrator can provide you with a URI to a keytab file as an alternative to providing you with a name and password to a privileged Windows account. When you receive the URI, include it in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;-keytab-uri&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;parameter with the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;vserver cifs&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;commands.&lt;/P&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;We have more information at&amp;nbsp;&lt;A href="https://docs.netapp.com/us-en/ontap/smb-config/create-server-active-directory-domain-task.html" target="_blank" rel="noopener"&gt;https://docs.netapp.com/us-en/ontap/smb-config/create-server-active-directory-domain-task.html&lt;/A&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;From memory, "create machine account" is a permission that can be set in ADUC.&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Hope this helps!&lt;/DIV&gt;</description>
      <pubDate>Thu, 29 Sep 2022 03:00:46 GMT</pubDate>
      <guid>https://community.netapp.com/t5/AFF/Granular-permissions-used-by-the-Windows-account-used-to-join-CIFS-to-the-domain/m-p/438736#M1106</guid>
      <dc:creator>AlexDawson</dc:creator>
      <dc:date>2022-09-29T03:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: Granular permissions used by the Windows account used to join CIFS to the domain</title>
      <link>https://community.netapp.com/t5/AFF/Granular-permissions-used-by-the-Windows-account-used-to-join-CIFS-to-the-domain/m-p/438748#M1107</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here are the AD permissions required to delegate on the Organizational Unit for your computer Objects to enable the SVM to successfully join the domain.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.microsoft.com/en-au/help/932455/error-message-when-non-administrator-users-who-have-been-delegated-con" target="_blank"&gt;https://support.microsoft.com/en-au/help/932455/error-message-when-non-administrator-users-who-have-been-delegated-con&lt;/A&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Create Computer Objects&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Reset Password&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Read and write Account Restrictions&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Validated write to DNS host name &lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Validated write to service principal name&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Hope that helps&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/Matt&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 11:22:21 GMT</pubDate>
      <guid>https://community.netapp.com/t5/AFF/Granular-permissions-used-by-the-Windows-account-used-to-join-CIFS-to-the-domain/m-p/438748#M1107</guid>
      <dc:creator>mbeattie</dc:creator>
      <dc:date>2022-09-29T11:22:21Z</dc:date>
    </item>
  </channel>
</rss>

