Thanks for an answer. This KB is for kerberos way of integration with AD - in this case Juniper needs to be joined to AD. But using LDAP service there is no need to join the domain. So it seems it is not necessary to give "Create Computer Objects" and "Delete Computer Objects" privilege to this account, etc.. For the security reasons we can not use domain administrator as service account. Please could you determine exactly what privilege should this account has? Is it enough to be only Domain User for AdminDN account for AD LDAP? Your help is really appreciated.. Thanks,
... View more