Confuse of Admin account.

Ka Ho Cheng 435 Reputation points
2025-01-14T06:50:25.61+00:00

May I ask a question to clear my confusion.

If I want to implement below servers in child domain, which account I can use.

                          Enterprise Admin          Domain Admin of child domain

DC server Y ?

DHCP server Y ?

DNS server Y ?

Since I sound a message that some of above server may need connect to parent so that the "Domain Admin of child domain" is not enough. However, I cannot find related information in KB or Q&A.

Thanks

Windows for business | Windows Server | User experience | Other
0 comments No comments
{count} votes

Accepted answer
  1. Anonymous
    2025-01-14T13:35:01.5933333+00:00

    Hello Ka Ho Cheng,

    Thank you for posting in Q&A forum.

    In general, for tasks within a child domain, the Domain Admin account of the child domain should suffice. However, there are certain operations where you might need Enterprise Admin privileges, especially if the task requires making changes that affect the entire forest or involves interactions with the parent domain.

    Here’s a more detailed breakdown:

    Domain Controller Installation:

    When you create a new domain controller in the child domain, you can perform this with the child domain's Domain Admin account. However, if the new domain controller needs to establish trust relationships or replicate certain data from the parent domain initially, you might need Enterprise Admin credentials to complete the setup.

    DNS Server:

    If you are configuring a DNS server within the child domain, the Domain Admin account of the child domain should normally be sufficient. However, if the DNS server needs to replicate or interact with DNS servers in the parent domain, you may require additional permissions.

    DHCP Server:

    For implementing a DHCP server in the child domain, the Domain Admin account for the child domain is usually adequate.

    To ensure seamless integration, it is sometimes necessary to have Enterprise Admin rights, especially if:

    1.Creating or modifying objects at the forest level.

    2.Initial replication or interaction between parent and child domains during setup.

    3.Configuring DNS delegation or replication where configurations span across domains.

    If you are encountering specific issues or require specific integration steps between the child and parent domains, you might need to momentarily escalate privileges with an Enterprise Admin account.

    Always refer to your organization's security policies and best practices when elevating privileges.

    I hope the information above is helpful.

    If you have any questions or concerns, please feel free to let us know.

    Best Regards,

    Daisy Zhou

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.