Domain join rights

in reference to this

https://docs.software-univention.de/manual-4.4.html#domain-ldap:Subsequent_domain_joins_with_univention-join

is it actually really needed for a user to belong to group “DC Backup hosts” and “Domain Admins” to be able to pass that user credential to univention-domain-join-cli (for the purpose of joining a desktop to a domain)? Or is it enough for that user to be in “DC Backup Hosts”?

Mastodon