{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-192-separate-cluster-creator-permissions-from-clustered-role-object-creation/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-192-separate-cluster-creator-permissions-from-clustered-role-object-creation/",
        "slug": "dse-20260908-192-separate-cluster-creator-permissions-from-clustered-role-object-creation",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-192-separate-cluster-creator-permissions-from-clustered-role-object-creation/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-192-separate-cluster-creator-permissions-from-clustered-role-object-creation.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-192-separate-cluster-creator-permissions-from-clustered-role-object-creation/"
        },
        "title": "Separate cluster creator permissions from clustered-role object creation",
        "summary": "Which directory permissions are needed when cluster computer objects are prestaged?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:13:59+00:00",
        "modified_at": "2026-09-08T18:26:32+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 2,
        "word_count": 231,
        "potentially_affected": "Directory and cluster administrators prestaging CNOs and VCOs in AD DS.",
        "dse_recommendation": "Prepare a permission request naming the exact objects and identities involved.",
        "primary_source": {
            "name": "Prestage cluster computer objects in Active Directory Domain Services",
            "url": "https://learn.microsoft.com/en-us/windows-server/failover-clustering/prestage-cluster-adds",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft provides prestaging so a user or group can create a failover cluster without general permission to create computer objects in AD DS. The account creating the cluster must receive Full Control over the prestaged cluster name object, or CNO. For automatic creation of a clustered role computer object in the same OU, the CNO must be able to create computer objects there. <a href=\"https://learn.microsoft.com/en-us/windows-server/failover-clustering/prestage-cluster-adds\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Identify the cluster creator, target OU, CNO, and planned client-access roles before requesting directory changes. Distinguish the human or service account creating the cluster from the computer identity that creates later role objects. Review the alternative of prestaging those role objects.</p>\n<h2>DSE recommendation</h2>\n<p>Prepare a permission request naming the exact objects and identities involved. Ask the directory owner to review the cluster-creation permission separately from the ongoing role-object requirement. Preserve the original ACLs and document who will manage future clustered roles. Avoid granting a broad directory role merely because one of these specific permissions is missing.</p>\n<h2>Verification</h2>\n<p>In an approved test, create the cluster using the intended account and confirm the expected CNO is used. Then validate one planned client-access role and inspect its directory object and ownership. Check that unrelated object creation remains outside the assigned permissions. Resolve unexpected OU placement or ownership before production setup.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/failover-clustering/prestage-cluster-adds\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Prestage cluster computer objects in Active Directory Domain Services</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nMicrosoft provides prestaging so a user or group can create a failover cluster without general permission to create computer objects in AD DS. The account creating the cluster must receive Full Control over the prestaged cluster name object, or CNO. For automatic creation of a clustered role computer object in the same OU, the CNO must be able to create computer objects there. Microsoft Learn.\nApplicability\nIdentify the cluster creator, target OU, CNO, and planned client-access roles before requesting directory changes. Distinguish the human or service account creating the cluster from the computer identity that creates later role objects. Review the alternative of prestaging those role objects.\nDSE recommendation\nPrepare a permission request naming the exact objects and identities involved. Ask the directory owner to review the cluster-creation permission separately from the ongoing role-object requirement. Preserve the original ACLs and document who will manage future clustered roles. Avoid granting a broad directory role merely because one of these specific permissions is missing.\nVerification\nIn an approved test, create the cluster using the intended account and confirm the expected CNO is used. Then validate one planned client-access role and inspect its directory object and ownership. Check that unrelated object creation remains outside the assigned permissions. Resolve unexpected OU placement or ownership before production setup.\nOfficial references\nMicrosoft Learn: Prestage cluster computer objects in Active Directory Domain Services. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft provides prestaging so a user or group can create a failover cluster without general permission to create computer objects in AD DS. The account creating the cluster must receive Full Control over the prestaged cluster name object, or CNO. For automatic creation of a clustered role computer object in the same OU, the CNO must be able to create computer objects there. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/failover-clustering/prestage-cluster-adds).\n\n## Applicability\n\nIdentify the cluster creator, target OU, CNO, and planned client-access roles before requesting directory changes. Distinguish the human or service account creating the cluster from the computer identity that creates later role objects. Review the alternative of prestaging those role objects.\n\n## DSE recommendation\n\nPrepare a permission request naming the exact objects and identities involved. Ask the directory owner to review the cluster-creation permission separately from the ongoing role-object requirement. Preserve the original ACLs and document who will manage future clustered roles. Avoid granting a broad directory role merely because one of these specific permissions is missing.\n\n## Verification\n\nIn an approved test, create the cluster using the intended account and confirm the expected CNO is used. Then validate one planned client-access role and inspect its directory object and ownership. Check that unrelated object creation remains outside the assigned permissions. Resolve unexpected OU placement or ownership before production setup.\n\n## Official references\n\n[Microsoft Learn: Prestage cluster computer objects in Active Directory Domain Services](https://learn.microsoft.com/en-us/windows-server/failover-clustering/prestage-cluster-adds). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-192-separate-cluster-creator-permissions-from-clustered-role-object-creation/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-192-separate-cluster-creator-permissions-from-clustered-role-object-creation/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-192-separate-cluster-creator-permissions-from-clustered-role-object-creation/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Separate cluster creator permissions from clustered-role object creation",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-192-separate-cluster-creator-permissions-from-clustered-role-object-creation/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-192-separate-cluster-creator-permissions-from-clustered-role-object-creation/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-192-separate-cluster-creator-permissions-from-clustered-role-object-creation/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-192-separate-cluster-creator-permissions-from-clustered-role-object-creation/",
                "headline": "Separate cluster creator permissions from clustered-role object creation",
                "description": "Which directory permissions are needed when cluster computer objects are prestaged?",
                "abstract": "Which directory permissions are needed when cluster computer objects are prestaged?",
                "articleBody": "Source facts\nMicrosoft provides prestaging so a user or group can create a failover cluster without general permission to create computer objects in AD DS. The account creating the cluster must receive Full Control over the prestaged cluster name object, or CNO. For automatic creation of a clustered role computer object in the same OU, the CNO must be able to create computer objects there. Microsoft Learn.\nApplicability\nIdentify the cluster creator, target OU, CNO, and planned client-access roles before requesting directory changes. Distinguish the human or service account creating the cluster from the computer identity that creates later role objects. Review the alternative of prestaging those role objects.\nDSE recommendation\nPrepare a permission request naming the exact objects and identities involved. Ask the directory owner to review the cluster-creation permission separately from the ongoing role-object requirement. Preserve the original ACLs and document who will manage future clustered roles. Avoid granting a broad directory role merely because one of these specific permissions is missing.\nVerification\nIn an approved test, create the cluster using the intended account and confirm the expected CNO is used. Then validate one planned client-access role and inspect its directory object and ownership. Check that unrelated object creation remains outside the assigned permissions. Resolve unexpected OU placement or ownership before production setup.\nOfficial references\nMicrosoft Learn: Prestage cluster computer objects in Active Directory Domain Services. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:13:59+00:00",
                "dateModified": "2026-09-08T18:26:32+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-192-separate-cluster-creator-permissions-from-clustered-role-object-creation/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-192-separate-cluster-creator-permissions-from-clustered-role-object-creation/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Separate cluster creator permissions from clustered-role object creation"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 231,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Prestage cluster computer objects in Active Directory Domain Services",
                    "url": "https://learn.microsoft.com/en-us/windows-server/failover-clustering/prestage-cluster-adds"
                }
            }
        ]
    }
}