# Distinguish a cluster name object from the administrator who creates it

> Which Active Directory computer objects are created for a domain failover cluster?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-145-distinguish-a-cluster-name-object-from-the-administrator-who-creates-it/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:14:46+00:00
- Modified: 2026-09-08T18:23:27+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

Which Active Directory computer objects are created for a domain failover cluster?

## Potentially affected

Administrators reviewing Active Directory identities used by Windows failover clusters.

## DSE recommendation

Maintain an inventory separating the administrator account, CNO, and role-specific computer objects.

## Article

## Source facts

For the documented domain cluster, the creation wizards generate computer objects and assign required permissions. The cluster itself receives a cluster name object, or CNO. Most clustered services and applications receive additional computer accounts; Hyper-V VMs do not require a dedicated account through this process. The user who runs the cluster-creation wizard supplies the initial permission context from which the cluster account is created. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/failover-clustering/failover-cluster-accounts-overview).

## Applicability

Identify the intended cluster, its domain location, creation account, and clustered roles. Review the required permissions and any prestaging procedure before changing objects or directory delegation.

## DSE recommendation

Maintain an inventory separating the administrator account, CNO, and role-specific computer objects. Have the directory and cluster owners agree on who manages each object and its permissions. Before modifying an existing account, record the current access control and the cluster role that depends on it.

## Verification

After approved creation or permission maintenance, inspect the expected objects and test the relevant network-name resources and role access. Correlate directory changes with cluster observations. Treat an unexpected missing account or altered permission as a finding to resolve rather than creating replacement identities without understanding the dependency.

## Official references

[Microsoft Learn: Failover cluster accounts overview](https://learn.microsoft.com/en-us/windows-server/failover-clustering/failover-cluster-accounts-overview). Source reviewed September 8, 2026.

## Primary reference

- Name: Failover cluster accounts overview
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/failover-clustering/failover-cluster-accounts-overview
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Distinguish a cluster name object from the administrator who creates it,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-145-distinguish-a-cluster-name-object-from-the-administrator-who-creates-it/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
