# Separate cluster creator permissions from clustered-role object creation

> Which directory permissions are needed when cluster computer objects are prestaged?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-192-separate-cluster-creator-permissions-from-clustered-role-object-creation/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:13:59+00:00
- Modified: 2026-09-08T18:26:32+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Which directory permissions are needed when cluster computer objects are prestaged?

## Potentially affected

Directory and cluster administrators prestaging CNOs and VCOs in AD DS.

## DSE recommendation

Prepare a permission request naming the exact objects and identities involved.

## Article

## Source facts

Microsoft provides prestaging so a user or group can create a failover cluster without general permission to create computer objects in AD DS. The account creating the cluster must receive Full Control over the prestaged cluster name object, or CNO. For automatic creation of a clustered role computer object in the same OU, the CNO must be able to create computer objects there. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/failover-clustering/prestage-cluster-adds).

## Applicability

Identify the cluster creator, target OU, CNO, and planned client-access roles before requesting directory changes. Distinguish the human or service account creating the cluster from the computer identity that creates later role objects. Review the alternative of prestaging those role objects.

## DSE recommendation

Prepare a permission request naming the exact objects and identities involved. Ask the directory owner to review the cluster-creation permission separately from the ongoing role-object requirement. Preserve the original ACLs and document who will manage future clustered roles. Avoid granting a broad directory role merely because one of these specific permissions is missing.

## Verification

In an approved test, create the cluster using the intended account and confirm the expected CNO is used. Then validate one planned client-access role and inspect its directory object and ownership. Check that unrelated object creation remains outside the assigned permissions. Resolve unexpected OU placement or ownership before production setup.

## Official references

[Microsoft Learn: Prestage cluster computer objects in Active Directory Domain Services](https://learn.microsoft.com/en-us/windows-server/failover-clustering/prestage-cluster-adds). Source reviewed September 8, 2026.

## Primary reference

- Name: Prestage cluster computer objects in Active Directory Domain Services
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/failover-clustering/prestage-cluster-adds
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Separate cluster creator permissions from clustered-role object creation,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-192-separate-cluster-creator-permissions-from-clustered-role-object-creation/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
