Permissions Difference between Service Account delegation & Domain Admin Group membership

Permissions Difference between Service Account delegation & Domain Admin Group membership

Hello everyone.  I'm currently working through configuring ADManage and a couple other Manage Engine products.  I'm not really thrilled about putting a svc account user in the DA group, and am looking into the user delegation strategy to achieve the rights that are required.

So my question... does anyone know what functionality will not work by using the delegation method suggested by Manage Engine, compared to making the user a full Domain Admin?

I know so far that the "Restore Deleted Users" will not work as only DAs can do this natively.  If anyone knows the fix for that, or a more detailed list of what is lost by not making your user a domain admin, I would appreciate it!

Regards,
Daniel

                New to ADSelfService Plus?