Forum Discussion
Michele D'Angelantonio
Jul 09, 2020Copper Contributor
empty timeline, no alerts detected
Hi all. After a good number of implementations with normal service account I tried the first one using gMSA. In the past, when AD Connect had the first sync after the sensor installations, I immedi...
Jonathan Green
Jul 17, 2020Brass Contributor
My Guess -> Don't add gMSA to domain admins or delegated permissions set.
Make sure your gMSA is correctly set before next step.
Remove AATP Installation.
Remove anything you've added including prior WinPCaps whether it was for Nmap, Suricata, etc.
- Make sure your gMSA is correctly set before next step.
- Confirm Portal is correct
- Confirm gMSA has permissions
- Confirm gMSA is allowed to retrieve managed passwords from the group "Domain Controllers".
Reinstall it using a fresh pull from the portal.
Do not go to Services and change anything like the user account. It needs to say as the Local Service.
Hope this helps.