Does the service account have to be a member of Administrators or Domain Admins?
Not necessarily. An Account Operator can do most everything the service account requires (except update members of Administrative or Operator groups). You can even delegate the service account management permission to a single OU, if you wish. Keep in mind, if you cannot logon as the service account and make a change through Active Directory Users and Computers, then Directory Update or Directory Manager will NOT be able to make the update either.
Related Questions
- I can not access my domain after verifying IP Updater, DNS Service account data and DNS Service settings. What else should I do?
- When I add a user and a computer to the domain, is the user account added to the computer’s Local Admins group?
- Does the service account have to be a member of Administrators or Domain Admins?