I'm planning to separate DHCP from DNS and the domain controller and want to follow current least-privilege guidance. How should administrative access and DNS registration credentials be configured on a standalone Windows Server 2025 DHCP server? Does the DHCP service already run with an appropriately restricted account, or are there additional hardening steps for the service and the people managing scopes and reservations?
5 Answers
For administration, install the DHCP role and complete the security-group setup, such as running Add-DhcpServerSecurityGroup if needed. Add operators to the server’s DHCP Administrators group so they can manage scopes and reservations through the management tools without being local administrators or having broad directory privileges. DHCP Users can be used for read-only access. Authorizing the server in the directory is a separate, usually one-time task that requires Enterprise Admin or delegated permission on the NetServices container.
Whether DHCP belongs on a domain controller, a dedicated server, or a firewall is partly an availability and operational decision. Keeping it separate can reduce role concentration, but the bigger security gain comes from limiting who can administer DHCP and using a narrowly scoped DNS-update credential. In small environments, DHCP on a domain controller can still function, provided it is properly secured and monitored.
The DHCP service itself already runs under a built-in restricted service identity, so you normally do not create or reduce a service account for running DHCP. The important distinction is between the account running the service and the credential DHCP uses for secure dynamic DNS updates.
Create a dedicated ordinary domain account for DHCP-to-DNS updates and configure it with Set-DhcpServerDnsCredential. Give it no extra privileges. This avoids relying on the server computer account, which can have excessive ability to modify records in integrated DNS zones. Also enable DNS name protection with Set-DhcpServerv4DnsSetting -NameProtection $true, and avoid placing the server in DnsUpdateProxy when using a dedicated credential.
Be careful when moving DHCP away from a domain controller. Existing records may still be owned by the old server’s computer account, so the new DHCP credential might not be able to update them immediately. Stale A and PTR records may need to age out, and DNS scavenging should be reviewed. Mixed Windows, Linux, macOS, or other clients are another reason to use a consistent DHCP DNS-update credential across all DHCP nodes.
For systems that cannot perform secure dynamic updates, it is safer to keep nonsecure updates disabled and create their DNS records manually rather than weakening the whole zone.

If you have multiple DHCP servers or failover partners, configure the same DNS-update credential on each one. Otherwise, records created by one server may not be modifiable by the other.