Skip to main content
Answer

LDAP Service Account Permissions

  • June 21, 2012
  • 4 replies
  • 29 views

Forum|alt.badge.img+10

I'm setting up an Active Directory connection and it is asking for a service account. What are the minimum permissions the account needs in AD for LDAP functionality?

Best answer by jarednichols

The simple existence of the account being there should be sufficient. You shouldn't need any privs. I use the same account as my casper install account as it's an AD-based service account.

4 replies

Forum|alt.badge.img+24
  • Valued Contributor
  • Answer
  • June 21, 2012

The simple existence of the account being there should be sufficient. You shouldn't need any privs. I use the same account as my casper install account as it's an AD-based service account.


Forum|alt.badge.img+10
  • Author
  • Contributor
  • June 21, 2012

Excellent. Thanks.


Forum|alt.badge.img+13
  • Contributor
  • June 21, 2012

Would that service account need JOIN privileges if you were trying to do authenticate binds to AD? It depends on your AD security settings.

- Justin


Forum|alt.badge.img+24
  • Valued Contributor
  • June 22, 2012

In most environments, AD accounts need specific permission to create the computer object when joining. Most environments will require a pre-created computer object before binding. Best practice is to allow a particular service account to create the object when joining, but to limit it to particular OUs and not the entire directory.

I believe OP was simply asking about the ability to do the user info lookups required so that AD users can log into the JSS.