An Active Directory account for services, shareable across several servers, whose long random password is generated and changed automatically by Windows. The forest has to have a KDS root key.
Also called group managed service account.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains gMSA in context, with comparison tables and the common traps.
Terms in this definition
- AD
Short for Active Directory, the directory service built into Windows Server (AD DS). Entra Connect synchronises on-premises forests to Microsoft Entra ID.
- Forest
The highest-level AD container and security boundary. Its domain trees, one or more, all use one schema, configuration and global catalog.
- KDS root key
Needed once per forest before you create the first gMSA; domain controllers derive gMSA passwords from it. Leave time for replication after creating it.
Related terms
- Standalone managed service account
An AD account for one server only, whose SPNs and password are looked after automatically. If the service can use a group managed service account, choose that.