Security
Set-CrossForestOuDelegation.ps1now grants only Microsoft's least-privilege
domain-join permission set on descendant computer objects instead of the broad
Write all properties right. The delegated writes are scoped to Validated
write to DNS host name, Validated write to servicePrincipalName and Write
Account Restrictions (userAccountControl), plus the existing Reset Password
extended right and Create Child: computer on the OU. Verified end-to-end in a
cross-forest test environment.
Full changelog: v1.7.1...v1.7.2