Forum Discussion

manuelll1310's avatar
manuelll1310
Copper Contributor
May 11, 2021

Defender ATP doesnt remove old service account when switched te new account

Good day all,

 

Last week i wanted to setup a gmsa account instead of a user account for ATP Defender for identity service.
I had a test account which i later changed to the new one. 
The new gMSA account works fine now. 
But the thing is:

I have removed the old testgmsa account but the old account somehow are still being reported that the credentials are not correct. The issues keeps popping up in our portal.
Does anyone have seen this behaviour? And is there a fix for this?

  • Close the alert, if it says closed it's OK, if it reopens let me know.
    We close the alert if we see the credentials fixed, but in this case you removed it while they were in error, so we are not reporting it fixed to auto close this.
    • manuell665's avatar
      manuell665
      Copper Contributor
      Thanks for your quick reply! unfortunatly the alert immediatly re-opens when i close the alert.
      • EliOfek's avatar
        EliOfek
        Icon for Microsoft rankMicrosoft
        this account is no longer in the credentials list in the MDI portal ? can you make sure?
        are all sensors currently reporting healthy ?
        is it possible not all sensors can pull the gmsa's password for the new credentials ?

Resources