gMSA for ATP Directory service

%3CLINGO-SUB%20id%3D%22lingo-sub-979805%22%20slang%3D%22en-US%22%3EgMSA%20for%20ATP%20Directory%20service%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-979805%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20a%20question%20relating%20to%20the%20service%20accounts%3C%2FP%3E%3CP%3E1.%20Does%20the%20ATP%20Directory%20Services%20Read%20account%20or%20the%20agent%20software%20service%20account%20support%20group%20managed%20service%20account%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-981761%22%20slang%3D%22en-US%22%3ERe%3A%20gMSA%20for%20ATP%20Directory%20service%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-981761%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F363955%22%20target%3D%22_blank%22%3E%40jbchris%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20D%3CSPAN%3Eirectory%20Services%20account%20does%20not%20support%20gMSA%20at%20this%20time--%20we%20are%20looking%20into%20how%2Fwhen%20we%20can%20add%20this%20to%20the%20product.%20Thanks%20for%20the%20feedback!%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EThe%20Sensor%20services%20themselves%20do%20not%20run%20under%20user%20context%20--%20The%20Azure%20ATP%20sensor%20service%20runs%20in%20system%20context%20using%20the%20LocalService%20account%20and%20the%20Azure%20ATP%20Sensor%20Updater%20service%20runs%20in%20the%20system%20context%20using%20LocalSystem%20account.%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

I have a question relating to the service accounts

1. Does the ATP Directory Services Read account or the agent software service account support group managed service account?

 

 

Thanks 

1 Reply
Highlighted

@jbchris 

 

The Directory Services account does not support gMSA at this time-- we are looking into how/when we can add this to the product. Thanks for the feedback!

 

The Sensor services themselves do not run under user context -- The Azure ATP sensor service runs in system context using the LocalService account and the Azure ATP Sensor Updater service runs in the system context using LocalSystem account.