MDI Sensor service terminated unexpectedly Problem is gMSA Account

%3CLINGO-SUB%20id%3D%22lingo-sub-3370088%22%20slang%3D%22en-US%22%3EMDI%20Sensor%20service%20terminated%20unexpectedly%20Problem%20is%20gMSA%20Account%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3370088%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20want%20to%20Install%20the%20MDI%20Sensors%20on%20Domain%20Controllers%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDC01%26nbsp%3B%26nbsp%3B%22objectVersion%26nbsp%3B%26nbsp%3B%2087%22%20Server%202016%20Datacenter%20-%26nbsp%3B%3C%2FP%3E%3CP%3EDC02%26nbsp%3B%22objectVersion%26nbsp%3B%26nbsp%3B%2087%22%20Server%202016%20Datacenter%20-%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20I%20use%20a%20regular%20user%20with%20credentials.%20MDI%20services%20work%20without%20problems%20on%20both%20Servers.%3C%2FP%3E%3CP%3EWhen%20I%20use%20gMSA%20account%20for%20MDI%20sensor%20on%20DC02.%20MDI%20Sensor%20is%20not%20starting.%20Error%201067%3C%2FP%3E%3CP%3EThe%20Problem%20is%20MDI%20Sensor%20with%20gMSA%20Account%20works%20on%20DC01.%20But%20on%20DC02%20it%20is%20not%20starting.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPowershell%20script%20I%20used%20for%20gMSA%20Account%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENew-ADServiceAccount%20-Name%20username%20-DNSHostName%20username.domain.local%20%E2%80%93KerberosEncryptionType%20AES256%20%E2%80%93ManagedPasswordIntervalInDays%2060%20%E2%80%93SamAccountName%20username%20-PrincipalsAllowedToRetrieveManagedPassword%20DC01%2C%20DC02%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20checked%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ETest-ADServiceAccount%20-Identity%20username%3C%2FP%3E%3CP%3EPS%20C%3A%5CWindows%5Csystem32%26gt%3B%20Test-ADServiceAccount%20-Identity%20username%3CBR%20%2F%3ETrue%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EEvent%20Viewer%26nbsp%3Bon%20DC01%3A%3C%2FP%3E%3CP%3EThe%20Open%20Procedure%20for%20service%20%22.NETFramework%22%20in%20DLL%20%22C%3A%5CWindows%5Csystem32%5Cmscoree.dll%22%20failed.%20Performance%20data%20for%20this%20service%20will%20not%20be%20available.%20The%20first%20four%20bytes%20(DWORD)%20of%20the%20Data%20section%20contains%20the%20error%20code.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20Open%20Procedure%20for%20service%20%22WmiApRpl%22%20in%20DLL%20%22C%3A%5CWindows%5Csystem32%5Cwbem%5Cwmiaprpl.dll%22%20failed.%20Performance%20data%20for%20this%20service%20will%20not%20be%20available.%20The%20first%20four%20bytes%20(DWORD)%20of%20the%20Data%20section%20contains%20the%20error%20code.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20Same%20Errors%20I%20have%20seen%20also%20in%20DC02.%20But%20It%20works%20without%20Problem.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20don't%20know%20if%20these%20errors%20related%20to%20MDI%20issue%3F!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20Idea%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%2C%3C%2FP%3E%3CP%3EFarhad%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3378487%22%20slang%3D%22en-US%22%3ERe%3A%20MDI%20Sensor%20service%20terminated%20unexpectedly%20Problem%20is%20gMSA%20Account%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3378487%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F943757%22%20target%3D%22_blank%22%3E%40fkh090%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EVerify%20that%20the%20gMSA%20has%20the%3CSTRONG%3E%26nbsp%3BLogon%20as%20a%20Service%3C%2FSTRONG%3E%26nbsp%3Brights%20assignment%20as%20described%20in%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fdefender-for-identity%2Fdirectory-service-accounts%23verify-that-the-gmsa-account-has-the-required-rights-if-needed%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fdefender-for-identity%2Fdirectory-service-accounts%23verify-that-the-gmsa-account-has-the-required-rights-if-needed%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3378521%22%20slang%3D%22en-US%22%3ERe%3A%20MDI%20Sensor%20service%20terminated%20unexpectedly%20Problem%20is%20gMSA%20Account%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3378521%22%20slang%3D%22en-US%22%3EHi%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F401822%22%20target%3D%22_blank%22%3E%40Martin_Schvartzman%3C%2FA%3E%2C%3CBR%20%2F%3E%3CBR%20%2F%3EThank%20you%20for%20your%20response.%3CBR%20%2F%3EI%20have%20checked%20also%20the%20Logon%20as%20a%20Service%20rights.%3CBR%20%2F%3EUnfortunately%2C%20it%20doesn't%20help.%3CBR%20%2F%3E%3CBR%20%2F%3EI%20also%20checked%20the%20all%20steps%20were%20written%20in%20this%20post.%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fanswers%2Fquestions%2F758863%2Fazure-atp-doesn39t-start-in-dc-with-gmsa-account.html%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fanswers%2Fquestions%2F758863%2Fazure-atp-doesn39t-start-in-dc-with-gmsa-account.html%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EDoesn't%20help%20%3A(%3C%2Fimg%3E%3CBR%20%2F%3E%3CBR%20%2F%3ERegards%2C%3CBR%20%2F%3EFarhad%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3378894%22%20slang%3D%22en-US%22%3ERe%3A%20MDI%20Sensor%20service%20terminated%20unexpectedly%20Problem%20is%20gMSA%20Account%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3378894%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F943757%22%20target%3D%22_blank%22%3E%40fkh090%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EPlease%20open%20a%20support%20case.%20They%20should%20be%20able%20to%20help%20you%20troubleshot%20the%20issue.%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

Hello,

 

I want to Install the MDI Sensors on Domain Controllers:

 

DC01  "objectVersion   87" Server 2016 Datacenter - 

DC02 "objectVersion   87" Server 2016 Datacenter - 

 

When I use a regular user with credentials. MDI services work without problems on both Servers.

When I use gMSA account for MDI sensor on DC02. MDI Sensor is not starting. Error 1067

The Problem is MDI Sensor with gMSA Account works on DC01. But on DC02 it is not starting.

 

Powershell script I used for gMSA Account:

 

New-ADServiceAccount -Name username -DNSHostName username.domain.local –KerberosEncryptionType AES256 –ManagedPasswordIntervalInDays 60 –SamAccountName username -PrincipalsAllowedToRetrieveManagedPassword DC01, DC02

 

 

I have checked:

 

Test-ADServiceAccount -Identity username

PS C:\Windows\system32> Test-ADServiceAccount -Identity username
True

 

Event Viewer on DC01:

The Open Procedure for service ".NETFramework" in DLL "C:\Windows\system32\mscoree.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.

 

 

The Open Procedure for service "WmiApRpl" in DLL "C:\Windows\system32\wbem\wmiaprpl.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.

 

The Same Errors I have seen also in DC02. But It works without Problem.

 

I don't know if these errors related to MDI issue?!

 

 

Any Idea?

 

Regards,

Farhad

 

 

 

 

 

 

 

 

 

 

3 Replies
Hi @Martin_Schvartzman,

Thank you for your response.
I have checked also the Logon as a Service rights.
Unfortunately, it doesn't help.

I also checked the all steps were written in this post.

https://docs.microsoft.com/en-us/answers/questions/758863/azure-atp-doesn39t-start-in-dc-with-gmsa-a...

Doesn't help :(

Regards,
Farhad


@fkh090 

Please open a support case. They should be able to help you troubleshot the issue.