The next step in configuring the child zone is to delegate administrative authority to the Zone Administrators group. The steps are the same for the child zone as the parent zone, except that you expand the Child Zones node and select the name of the child zone before selecting the Delegate Zone Control command. You should still assign the Zone Administrators group All permissions.
You also have the option of assigning the permissions to join or leave to the Join Operators Active Directory group. If you pre-create computer accounts and allow the computer to join itself to the Active Directory domain, you can skip this step.
If you don’t want to pre-create the computer account and allow the self-service join, you must give members of the Join Operators group the following administrative tasks:
- Join Computers to the Zone
- Remove Computers from the Zone
- Modify Computer Profiles