Forum Discussion

CHRIS_chipotle's avatar
CHRIS_chipotle
Copper Contributor
Feb 15, 2022

MDI GMSA Forest/Multi Domain

Trying to get a GMSA to work in Child Domain.  I have it setup, working, with sensor Running in the Forest Root.

I followed the advise to create a Universal Group and add Domain Controllers in Forest Root and Child Domain,  DC's have been restarted.

GMSA in Forest Root has been configured with Universal Group to Retrieve Password.

A couple of issues, a GMSA is only Domain centric, Test-ADServiceAccount will not work in Child Domain.

Sensor Setup in Child Domain has been installed, but sensor will not start.

Microsoft.Tri.Sensor.Log shows that the GMSA failed to retrieve password

 

I have read this, but there is no proof that this actually works.

Has anyone actually got the MDI Sensor to work in a multi-domain environment?  If so, can you provide your testing steps and if any of your steps were different from below?

 

Thanks.

 

Resources