Step-by-Step: How to work with Group Managed Service Accounts (gMSA)

Published Sep 25 2019 09:01 PM 52.5K Views
Senior Member

Services Accounts are recommended to use when install application or services in infrastructure. It is dedicated account with specific privileges which use to run services, batch jobs, management tasks. In most of the infrastructures, service accounts are typical user accounts with “Password never expire” option. Since these service accounts are not been use regularly, Administrators have to keep track of these accounts and their credentials. I have seen in many occasions where engineers face in to issues due to outdated or misplace service account credential details. Pain of it is, if you reset the password of service accounts, you will need to update services, databases, application settings to get application or services up and running again. Apart from it Engineers also have to manage service principle names (SPN) which helps to identify service instance uniquely.

 

After considering all these challenges Microsoft has introduced Managed Service Accounts with windows server 2008 R2. However, one managed service accounts only can use with one computer. But there are operation requirements which required to share same service account in multiple hosts. Microsoft network load balancer, IIS server farms are good example for these. All the hosts in these server groups required to use same service principal for authentications. Group Managed service accounts provides the same functionalities as managed service accounts but its extend its capabilities to host group levels. This is first introduced with windows server 2012.

 

Group managed service accounts got following capabilities,

  • No Password Management
  • Supports to share across multiple hosts
  • Can use to run schedule tasks (Managed service accounts do not support to run schedule tasks)
  • It is uses Microsoft Key Distribution Service (KDC) to create and manage the passwords for the gMSA.

Key Distribution Service was introduced with the windows server 2012. KDS shares a secret (root Key ID) among all the KDS instance in the domain. This value will change periodically. When gMSA required a password, windows server 2012 domain controller will be generated password based on common algorithm which includes root key ID. Then all the hosts which shares the gMSA will query from domain controllers to retrieve the latest password.

 

Requirements for gMSA

  • Windows server 2012 or higher forest level
  • Widows server 2012 or higher domain member servers (Windows 8 or upper domain joined computers also supported)
  • 64-bit architecture to run PowerShell command to manage gMSA

Tip – gMSA not supported for the Failover Clustering setup. But it is supported for services which is run upon Failover clusters.

 

In order to start the configuration process, we need to create KDS root key. This need to run from domain controller with domain admin or enterprise admin privileges.

 

Add-KdsRootKey –EffectiveImmediately

 

Once this is executed, it has default 10 hours’ time limit to replicate it to all the domain controllers and start response to gMSA requests. In testing environment with one domain controller, it can force to remove this waiting time and start to response gMSA immediately. This is NOT recommended for production environment.

 

Add-KdsRootKey –EffectiveTime ((get-date).addhours(-10))

 

After that we can create the first gMSA account. First I have created an AD group “IISFARM” and add all my IIS servers to it. This farm will be using the new gMSA account.

 

New-ADServiceAccount "Mygmsa1" -DNSHostName "web.rebeladmin.com" –PrincipalsAllowedToRetrieveManagedPassword "IISFARM"

 

In above Mygmsa1 is the service account and web.rebeladmin.com is the FQDN of the service. Once its processed we can verify the new account using,

 

Get-ADServiceAccount “Mygmsa1”

 

gmsa1.png

 

Next step is to install it on server in IIS Farm. It needs active directory PowerShell module to run it. It can be install using RSAT.

 

Install-ADServiceAccount -Identity "Mygmsa1"

 

Tip – If you created the server group recently and add the host, you need to restart the host computer to reflect the group membership. Otherwise above command will fail.

Once its executed we can test the service account by running,

 

Test-ADServiceAccount " Mygmsa1"

 

gmsa2.png

 

Similar to managed service account, when you configure the gMSA with any service, leave the password as blank.

 

Uninstall Service Account

 

There can be requirements to remove the managed service accounts. This can be done by executing,

 

Remove-ADServiceAccount –identity “Mygmsa1”

 

Above command will remove the service account Mygmsa1. This is applying to both type of managed service accounts.

8 Comments
Visitor

Do you need to assign permissions (through groups and file security)  to the gmsas?  I am looking particularly at SQL.

Senior Member

Thanks you Soo much sir it very useful for me. 

Microsoft

Thanks for the Details, however i'm looking for a solution / alternative to configure DB mail when SQL Server running on gMSA account.

 

Thanks in Advance

Occasional Visitor

"Windows server 2012 or higher forest level" is ambiguous as a requirement. Does this meean Forest Functional level or does it mean that all DCs in a forest need to be on 2012 or later? Also is this a Domain thing or a Forest thing?
You also fail to mention whether the KDS Root Key requirement is Domain or Forest level thing.

Frequent Visitor

@Lorribot Forest functional level must be Server 2012. Domain member servers where this is configured must be Server 2012. Considering that Server 2008 is deprecated, you should safely assume that this is not supported on anything lower than a 2012 functional level. And, since you need to be EITHER a Domain Admin or Enterprise Admin, assume this is a Domain setting.

Established Member

Is the step Install-ADServiceAccount -Identity "Mygmsa1" required for a gMSA?  This article: Install-ADServiceAccount (ActiveDirectory) | Microsoft Docs says that Install-ADServiceAccount "Installs an Active Directory managed service account on a computer or caches a group managed service account on a computer."  What does the "install" actually do?

Occasional Visitor

@TerryZolinskiThe lack of clarity over whether something is domain or forrest dependant is something I have to deal with on a day to day basis, yes we should not have set up our Forrest as we did but it was done in 2000 and that was different times with different versions of Exchange and business needs, now we have to live with it as the pain of moving would be immense (don't get me satrted on O365 problems we run in to). We have a root domain and 7 geo-based sub domains, I have no control over the root (Forrest) or other subdomains so it is important to me that the differences between where stuff is configured is explicitly and clearly stated such as if it has to be that the FFL is set 2012 or the DFL is 2012 or later. Whether yo need to be an Enterprise Admin or domain Admin is also important, many articles say Enterprise Admin but if you are only running stuff against a domain it is only Domain Admin you need, or say Domain admin but they actually need Enterprise Admin again these terms seem to be interchangable to some writers.
If you are in the happy place of only having a single domain/forrest over which you have total control lucky you as this stuff will be unimportant.

Frequent Visitor

@Lorribot If you need definitive answers, why are you reading a community article and asking the community? Not that community members are here to serve you, but I found the answer to what you are looking for in about 30 seconds of Googling over on Getting Started with Group Managed Service Accounts | Microsoft Docs. In this article you will see the scope is domain, so this means the domain schema matters, not the forest schema.

 

If you have a problem with free information, perhaps you should take it upon yourself to find the answers you are looking for rather than complain to people who are just trying to help. My comment was merely to help steer you in the right direction. You're not the only one dealing with a complex environment, so don't assume community members are below you.

 

You're welcome for the free information.

%3CLINGO-SUB%20id%3D%22lingo-sub-329864%22%20slang%3D%22en-US%22%3EStep-by-Step%3A%20How%20to%20work%20with%20Group%20Managed%20Service%20Accounts%20(gMSA)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-329864%22%20slang%3D%22en-US%22%3E%3CP%3EServices%20Accounts%20are%20recommended%20to%20use%20when%20install%20application%20or%20services%20in%20infrastructure.%20It%20is%20dedicated%20account%20with%20specific%20privileges%20which%20use%20to%20run%20services%2C%20batch%20jobs%2C%20management%20tasks.%20In%20most%20of%20the%20infrastructures%2C%20service%20accounts%20are%20typical%20user%20accounts%20with%20%E2%80%9CPassword%20never%20expire%E2%80%9D%20option.%20Since%20these%20service%20accounts%20are%20not%20been%20use%20regularly%2C%20Administrators%20have%20to%20keep%20track%20of%20these%20accounts%20and%20their%20credentials.%20I%20have%20seen%20in%20many%20occasions%20where%20engineers%20face%20in%20to%20issues%20due%20to%20outdated%20or%20misplace%20service%20account%20credential%20details.%20Pain%20of%20it%20is%2C%20if%20you%20reset%20the%20password%20of%20service%20accounts%2C%20you%20will%20need%20to%20update%20services%2C%20databases%2C%20application%20settings%20to%20get%20application%20or%20services%20up%20and%20running%20again.%20Apart%20from%20it%20Engineers%20also%20have%20to%20manage%20service%20principle%20names%20(SPN)%20which%20helps%20to%20identify%20service%20instance%20uniquely.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAfter%20considering%20all%20these%20challenges%20Microsoft%20has%20introduced%20Managed%20Service%20Accounts%20with%20windows%20server%202008%20R2.%20However%2C%20one%20managed%20service%20accounts%20only%20can%20use%20with%20one%20computer.%20But%20there%20are%20operation%20requirements%20which%20required%20to%20share%20same%20service%20account%20in%20multiple%20hosts.%20Microsoft%20network%20load%20balancer%2C%20IIS%20server%20farms%20are%20good%20example%20for%20these.%20All%20the%20hosts%20in%20these%20server%20groups%20required%20to%20use%20same%20service%20principal%20for%20authentications.%20Group%20Managed%20service%20accounts%20provides%20the%20same%20functionalities%20as%20managed%20service%20accounts%20but%20its%20extend%20its%20capabilities%20to%20host%20group%20levels.%20This%20is%20first%20introduced%20with%20windows%20server%202012.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EGroup%20managed%20service%20accounts%20got%20following%20capabilities%2C%3C%2FP%3ENo%20Password%20Management%20Supports%20to%20share%20across%20multiple%20hosts%20Can%20use%20to%20run%20schedule%20tasks%20(Managed%20service%20accounts%20do%20not%20support%20to%20run%20schedule%20tasks)%20It%20is%20uses%20Microsoft%20Key%20Distribution%20Service%20(KDC)%20to%20create%20and%20manage%20the%20passwords%20for%20the%20gMSA.%3CP%3EKey%20Distribution%20Service%20was%20introduced%20with%20the%20windows%20server%202012.%20KDS%20shares%20a%20secret%20(root%20Key%20ID)%20among%20all%20the%20KDS%20instance%20in%20the%20domain.%20This%20value%20will%20change%20periodically.%20When%20gMSA%20required%20a%20password%2C%20windows%20server%202012%20domain%20controller%20will%20be%20generated%20password%20based%20on%20common%20algorithm%20which%20includes%20root%20key%20ID.%20Then%20all%20the%20hosts%20which%20shares%20the%20gMSA%20will%20query%20from%20domain%20controllers%20to%20retrieve%20the%20latest%20password.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERequirements%20for%20gMSA%3C%2FP%3EWindows%20server%202012%20or%20higher%20forest%20level%20Widows%20server%202012%20or%20higher%20domain%20member%20servers%20(Windows%208%20or%20upper%20domain%20joined%20computers%20also%20supported)%2064-bit%20architecture%20to%20run%20PowerShell%20command%20to%20manage%20gMSA%3CP%3ETip%20%E2%80%93%20gMSA%20not%20supported%20for%20the%20Failover%20Clustering%20setup.%20But%20it%20is%20supported%20for%20services%20which%20is%20run%20upon%20Failover%20clusters.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20order%20to%20start%20the%20configuration%20process%2C%20we%20need%20to%20create%20KDS%20root%20key.%20This%20need%20to%20run%20from%20domain%20controller%20with%20domain%20admin%20or%20enterprise%20admin%20privileges.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAdd-KdsRootKey%20%E2%80%93EffectiveImmediately%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOnce%20this%20is%20executed%2C%20it%20has%20default%2010%20hours%E2%80%99%20time%20limit%20to%20replicate%20it%20to%20all%20the%20domain%20controllers%20and%20start%20response%20to%20gMSA%20requests.%20In%20testing%20environment%20with%20one%20domain%20controller%2C%20it%20can%20force%20to%20remove%20this%20waiting%20time%20and%20start%20to%20response%20gMSA%20immediately.%20This%20is%20NOT%20recommended%20for%20production%20environment.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAdd-KdsRootKey%20%E2%80%93EffectiveTime%20((get-date).addhours(-10))%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAfter%20that%20we%20can%20create%20the%20first%20gMSA%20account.%20First%20I%20have%20created%20an%20AD%20group%20%E2%80%9CIISFARM%E2%80%9D%20and%20add%20all%20my%20IIS%20servers%20to%20it.%20This%20farm%20will%20be%20using%20the%20new%20gMSA%20account.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENew-ADServiceAccount%20%22Mygmsa1%22%20-DNSHostName%20%22web.rebeladmin.com%22%20%E2%80%93PrincipalsAllowedToRetrieveManagedPassword%20%22IISFARM%22%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20above%20Mygmsa1%20is%20the%20service%20account%20and%20web.rebeladmin.com%20is%20the%20FQDN%20of%20the%20service.%20Once%20its%20processed%20we%20can%20verify%20the%20new%20account%20using%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EGet-ADServiceAccount%20%E2%80%9CMygmsa1%E2%80%9D%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENext%20step%20is%20to%20install%20it%20on%20server%20in%20IIS%20Farm.%20It%20needs%20active%20directory%20PowerShell%20module%20to%20run%20it.%20It%20can%20be%20install%20using%20RSAT.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EInstall-ADServiceAccount%20-Identity%20%22Mygmsa1%22%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ETip%20%E2%80%93%20If%20you%20created%20the%20server%20group%20recently%20and%20add%20the%20host%2C%20you%20need%20to%20restart%20the%20host%20computer%20to%20reflect%20the%20group%20membership.%20Otherwise%20above%20command%20will%20fail.%3C%2FP%3E%3CP%3EOnce%20its%20executed%20we%20can%20test%20the%20service%20account%20by%20running%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ETest-ADServiceAccount%20%22%20Mygmsa1%22%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESimilar%20to%20managed%20service%20account%2C%20when%20you%20configure%20the%20gMSA%20with%20any%20service%2C%20leave%20the%20password%20as%20blank.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EUninstall%20Service%20Account%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThere%20can%20be%20requirements%20to%20remove%20the%20managed%20service%20accounts.%20This%20can%20be%20done%20by%20executing%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERemove-ADServiceAccount%20%E2%80%93identity%20%E2%80%9CMygmsa1%E2%80%9D%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAbove%20command%20will%20remove%20the%20service%20account%20Mygmsa1.%20This%20is%20applying%20to%20both%20type%20of%20managed%20service%20accounts.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-329864%22%20slang%3D%22en-US%22%3E%3CP%3EServices%20Accounts%20are%20recommended%20to%20use%20when%20install%20application%20or%20services%20in%20infrastructure.%20It%20is%20dedicated%20account%20with%20specific%20privileges%20which%20use%20to%20run%20services%2C%20batch%20jobs%2C%20management%20tasks.%20In%20most%20of%20the%20infrastructures%2C%20service%20accounts%20are%20typical%20user%20accounts%20with%20%E2%80%9CPassword%20never%20expire%E2%80%9D%20option.%20Since%20these%20service%20accounts%20are%20not%20been%20use%20regularly%2C%20Administrators%20have%20to%20keep%20track%20of%20these%20accounts%20and%20their%20credentials.%20I%20have%20seen%20in%20many%20occasions%20where%20engineers%20face%20in%20to%20issues%20due%20to%20outdated%20or%20misplace%20service%20account%20credential%20details.%20Pain%20of%20it%20is%2C%20if%20you%20reset%20the%20password%20of%20service%20accounts%2C%20you%20will%20need%20to%20update%20services%2C%20databases%2C%20application%20settings%20to%20get%20application%20or%20services%20up%20and%20running%20again.%20Apart%20from%20it%20Engineers%20also%20have%20to%20manage%20service%20principle%20names%20(SPN)%20which%20helps%20to%20identify%20service%20instance%20uniquely.%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-329864%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EDishan%20Francis%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EPowerShell%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWindows%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWindows%20Server%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1424523%22%20slang%3D%22en-US%22%3ERe%3A%20Step-by-Step%3A%20How%20to%20work%20with%20Group%20Managed%20Service%20Accounts%20(gMSA)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1424523%22%20slang%3D%22en-US%22%3E%3CP%3EDo%20you%20need%20to%20assign%20permissions%20(through%20groups%20and%20file%20security)%26nbsp%3B%20to%20the%20gmsas%3F%26nbsp%3B%20I%20am%20looking%20particularly%20at%20SQL.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1552691%22%20slang%3D%22en-US%22%3ERe%3A%20Step-by-Step%3A%20How%20to%20work%20with%20Group%20Managed%20Service%20Accounts%20(gMSA)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1552691%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20you%20Soo%20much%20sir%20it%20very%20useful%20for%20me.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Version history
Last update:
‎Sep 20 2019 04:19 AM
Updated by: