Server 2022 Support

%3CLINGO-SUB%20id%3D%22%5C%26quot%3Blingo-sub-3066607%5C%26quot%3B%22%20slang%3D%22%5C%26quot%3Ben-US%5C%26quot%3B%22%3EServer%202022%20Support%26lt%3B%5C%2Flingo-sub%26gt%3B%3CLINGO-BODY%20id%3D%22%5C%26quot%3Blingo-body-3066607%5C%26quot%3B%22%20slang%3D%22%5C%26quot%3Ben-US%5C%26quot%3B%22%3E%3CP%3EWe've%20replaced%20one%20of%20our%20DC's%20with%20a%202022%20server.%20The%20server%20is%20a%20member%20of%20the%20group%20that%20is%20able%20to%20read%20gmsa%20service%20account.%20The%20error%20that%20is%20generated%20by%20the%20tri.sensor%20is%20that%20it%20cannot%20read%20the%20gmsa%20password.%20At%20a%20loss%20as%202019%20servers%20configured%20the%20same%20way%20work%20fine.%20The%202022%20is%20our%20first%20DC%2C%20the%202019%20servers%20host%20adfs%20roles.%20Is%202022%20not%20supported%20for%20Azure%20ATP%20yet%3F%26lt%3B%5C%2FP%26gt%3B%26lt%3B%5C%2Flingo-body%26gt%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3C%2FLINGO-SUB%3E
New Contributor

We've replaced one of our DC's with a 2022 server. The server is a member of the group that is able to read gmsa service account. The error that is generated by the tri.sensor is that it cannot read the gmsa password. At a loss as 2019 servers configured the same way work fine. The 2022 is our first DC, the 2019 servers host adfs roles. Is 2022 not supported for Azure ATP yet?

3 Replies

Officially not supported yet, as we did not complete full testing, but effectively I can say we are not blocking the install and telemetry shows we have hundreds of sensors running on 2022 already.
Most likely the issue is coming some place else, but I can't be sure until we officially support it after testing all use cases...

@ChrisMaiura 

 

Adding to @Eli Ofek's comment;
Please make sure you restarted the server after adding its computer account to the group that is allowed to retrieve the gmsa's password (as group membership is evaluated at logon), or run the following command on it:

 

klist -li 0x3e7 purge

 

 

If this still doesn't work, please open a support case.

@Martin_Schvartzman 

 

Thanks. We ran Test-ADServiceAccount ourserviceaccount from the DC in question and the result was true. We reinstalled the ATP Sensor client, but downloaded a new version. The original one we started with was 2.167.14829.39882. When we reinstalled this morning we used 2.168.14865.25114. The install completed without any issues. Thanks again for your time.