Create a group Managed Service Account  |  Managed Microsoft AD Documentation  |  Google Cloud (2024)

Stay organized with collections Save and categorize content based on your preferences.

This topic shows you how to create a group Managed Service Account (gMSA) inManaged Service for Microsoft Active Directory. You should followthese standard instructions for setting up the account and incorporate the following special considerationsfor Managed Microsoft AD.

Do not create KDS root key

Usually, the first time you create a gMSA in a domain, you need to generate aKey Distribution Service (KDS) root key. Managed Microsoft AD generates a KDSroot key for you when you create the domain, so you can skip that step fromthe standard instructions.

View the KDS root key

Before you begin, be sure that the Active Directory Sites and Services tool isinstalled fromRemote Server Administration Tools (RSAT).

To view the KDS root key, complete the following steps:

  1. In Windows, launch the Active Directory Sites and Services tool. To launchthis tool, you can open the Run command dialog box, and then enterdssite.msc.
  2. In the Active Directory Sites and Services tool, select the View tab.
  3. In the View menu, select Show Services Node.
  4. In the left pane, select Services > Group Key Distribution Service > MasterRoot Keys.
  5. The right pane shows a list of keys for your domain. Select a key to view itsdetails.

Note that running the Get-KdsRootKey PowerShell cmdlet returns an emptyresponse even though a valid KDS root key exists. You can only see the key whenyou run the Get-KdsRootKey cmdlet as the Domain Admin.

Create account under Managed Service Accounts container

For a Managed Microsoft AD domain, new gMSAs should be createdunder the Managed Service Accounts container. By default,the New-ADServiceAccount cmdlet creates new gMSAs in this location. For more information, seeNew-ADServiceAccountcmdlet.

Delegate administration of Managed Service Accounts

You can delegate the administration of the Managed Service Accounts container to a user byadding them to Cloud Service Managed Service Account Administrators group.For more information about the groups that Managed Microsoft AD creates for you, see Groups.

Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.

Last updated 2024-03-18 UTC.

Create a group Managed Service Account  |  Managed Microsoft AD Documentation  |  Google Cloud (2024)
Top Articles
Latest Posts
Article information

Author: Mr. See Jast

Last Updated:

Views: 6520

Rating: 4.4 / 5 (55 voted)

Reviews: 86% of readers found this page helpful

Author information

Name: Mr. See Jast

Birthday: 1999-07-30

Address: 8409 Megan Mountain, New Mathew, MT 44997-8193

Phone: +5023589614038

Job: Chief Executive

Hobby: Leather crafting, Flag Football, Candle making, Flying, Poi, Gunsmithing, Swimming

Introduction: My name is Mr. See Jast, I am a open, jolly, gorgeous, courageous, inexpensive, friendly, homely person who loves writing and wants to share my knowledge and understanding with you.