GuideInformationBusiness ContinuityIT

Separate cluster creator permissions from clustered-role object creation

Which directory permissions are needed when cluster computer objects are prestaged?

Paired infrastructure paths converging on a stable recovered service.
DSE visual intelligenceContinuity & recoveryGuide · 2 min read
Executive summary

What you need to know

Which directory permissions are needed when cluster computer objects are prestaged?

Potentially affected

Directory and cluster administrators prestaging CNOs and VCOs in AD DS.

DSE recommendation

Prepare a permission request naming the exact objects and identities involved.

Source facts

Microsoft provides prestaging so a user or group can create a failover cluster without general permission to create computer objects in AD DS. The account creating the cluster must receive Full Control over the prestaged cluster name object, or CNO. For automatic creation of a clustered role computer object in the same OU, the CNO must be able to create computer objects there. Microsoft Learn.

Applicability

Identify the cluster creator, target OU, CNO, and planned client-access roles before requesting directory changes. Distinguish the human or service account creating the cluster from the computer identity that creates later role objects. Review the alternative of prestaging those role objects.

DSE recommendation

Prepare a permission request naming the exact objects and identities involved. Ask the directory owner to review the cluster-creation permission separately from the ongoing role-object requirement. Preserve the original ACLs and document who will manage future clustered roles. Avoid granting a broad directory role merely because one of these specific permissions is missing.

Verification

In an approved test, create the cluster using the intended account and confirm the expected CNO is used. Then validate one planned client-access role and inspect its directory object and ownership. Check that unrelated object creation remains outside the assigned permissions. Resolve unexpected OU placement or ownership before production setup.

Official references

Microsoft Learn: Prestage cluster computer objects in Active Directory Domain Services. Source reviewed September 8, 2026.

Primary reference

Review the official source

Prestage cluster computer objects in Active Directory Domain Services · Verified September 8, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE