Managed Microsoft AD 用於管理網域的服務帳戶。這個帳戶是供系統使用的,因此請勿直接使用、修改或刪除。
委派的管理員
表 7 列出您在佈建網域時,自動授予委派管理員帳戶的 Active Directory 權限。這些權利是由帳戶的群組成員資格授予,因此如果您從其中一個群組中移除帳戶,可能會影響其權利和可用的動作。這個帳戶的預設名稱為 setupadmin。如果您變更了帳戶名稱,但不記得值,可以擷取。詳情請參閱「使用委派的管理員帳戶」。
委派的管理員帳戶沒有 Domain Admins、Enterprise Admins 和 BUILTIN\Administrators 權限,因為受管理的 Microsoft AD 是受管理的服務,Google 保留使用這些權限的權利。因此,您無法在受管理的 Microsoft AD 中使用需要這些權限的 Active Directory 功能,例如 分散式檔案系統 (DFS)、DHCP、在網域層級設定 GPO、複製目錄變更、提高林功能層級,以及其他林層級變更。
[[["容易理解","easyToUnderstand","thumb-up"],["確實解決了我的問題","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["難以理解","hardToUnderstand","thumb-down"],["資訊或程式碼範例有誤","incorrectInformationOrSampleCode","thumb-down"],["缺少我需要的資訊/範例","missingTheInformationSamplesINeed","thumb-down"],["翻譯問題","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["上次更新時間:2025-09-04 (世界標準時間)。"],[],[],null,["# Default Active Directory objects in Managed Microsoft AD\n\nWhen you create a new domain with Managed Service for Microsoft Active Directory, some Active Directory\nobjects are automatically created for you. These help you administer your AD\ndomain, and make it easier to manage AD tasks typically delegated to other users\nor groups.\n\nThe following diagram provides an overview. Refer to the tables below for a\ncomplete list and description of each object.\n\nOrganizational units\n--------------------\n\nTable 1 shows the organizational units (OU) created for you.\n\nGroups\n------\n\nThe following groups are created under the `Cloud Service Objects` OU.\n\nManaged Microsoft AD doesn't support providing time-limited group\nmemberships to users by using [Privileged Access Management for Active Directory\nDomain\nServices](https://learn.microsoft.com/en-us/microsoft-identity-manager/pam/privileged-identity-management-for-active-directory-domain-services).\n\nGroup Policy Objects\n--------------------\n\nManaged Microsoft AD automatically creates some Group Policy Objects (GPO) to\nsupport certain Group Policy features.\n\nYou can [create custom\nGPOs](https://learn.microsoft.com/en-us/windows/security/threat-protection/windows-firewall/create-a-group-policy-object)\nand link them to the `Cloud` OU or to any of the child OUs within the `Cloud`\nOU. For information about linking a GPO to an OU, see [Link the GPO to the\nDomain](https://learn.microsoft.com/en-us/windows/security/threat-protection/windows-firewall/link-the-gpo-to-the-domain).\n\nPassword Settings Objects\n-------------------------\n\nManaged Microsoft AD automatically creates ten password settings objects\n(PSO). You cannot change the name or precedence of these PSOs. Table 4 shows\nthe names and precedences of these PSOs.\n\nDefault values are assigned to the password policy settings for each PSO. You\ncan change these values. Table 5 shows these default settings.\n\nUsers\n-----\n\nManaged Microsoft AD automatically creates the users shown in table 6.\n\nDelegated administrator\n-----------------------\n\nTable 7 shows the Active Directory rights that are automatically granted to\nthe delegated administrator account when you provision the domain. These rights\nare granted by the account's group memberships, so if you remove the account\nfrom one of those groups, that may affect its rights and available actions. This\naccount has the default name `setupadmin`. If you changed the account name but\ndo not remember the value, you can\n[retrieve it](/managed-microsoft-ad/docs/how-to-use-delegated-admin#get-name). For more information, see\n[Use delegated administrator account](/managed-microsoft-ad/docs/how-to-use-delegated-admin).\n\nThe delegated administrator account doesn't have the `Domain Admins`,\n`Enterprise Admins`, and `BUILTIN\\Administrators` permissions because\nManaged Microsoft AD is a managed service and Google reserves the right to\nuse these permissions. So you can't use Active Directory features that require\nthese permissions in Managed Microsoft AD, such as [Distributed File System\n(DFS)](https://learn.microsoft.com/en-us/windows-server/storage/dfs-namespaces/dfs-overview),\n[DHCP](https://learn.microsoft.com/en-us/windows-server/networking/technologies/dhcp/dhcp-top),\nconfiguring GPOs at the domain level, replicating directory changes, raising\nforest functional levels, and other forest-wide changes.\n\nWhat's next\n-----------\n\n- [Manage Active Directory objects](/managed-microsoft-ad/docs/manage-active-directory-objects)"]]