Minimum requirements priveliged account (Windows)

Hi Jasper,


This can depend on a few things, namely:

  • For the 'Read' account, generally this only needs to be in Domain Users in order to read AD attributes for accounts. But some customers lock down their AD environment, and you may need greater privileges i.e. a Domain Users account may not be able to read attributes of Domain Admin accounts. So we generally recommend using Domain Users first, and then Account Operators after this. You can also do some testing of this on the screen Administration -> Security Groups, Debug AD Security Groups, to see if there any issues after making changes to this account
  • With the 'Write' account, used for performing password resets, generally Account Operators is required, but again, possibly more depending on the type of account being reset.

I hope this helps a little.



Click Studios

