In Windows Server 2016, you run the ADPREP /DOMAINPREP command to grant access to two new security principals that have the relative identifiers (RID) 526 and 527. These refer to the Key Admins and Enterprise Key Admins security groups. In this scenario, the 526 and 527 RIDs can't be resolved to friendly names until a Windows Server 2016 domain controller owns the primary domain controller (PDC) Flexible Single Master Operation (FSMO) role.
Additionally, both groups are given read and write access to the ms-DS-Key-Credential-Link attribute on all child objects from the domain root.
The RID 527/Enterprise Key Admins group has full control of the domain naming context (NC) head and all subordinate objects in the forest root domain and all child domains.