MECM 2207 gMSA support

Bojan Zivkovic 606 Reputation points
2022-10-15T09:58:56.667+00:00

Hi, can any of many accounts used by Configuration Manager 2207 be replaced with gMSA?

From what I see a little effort has been put in this by MS unlike SCOM where practically all accounts can be replaced with gMSA starting with SCOM 2019 UR1.

Thanks in advance.

Microsoft Security | Intune | Configuration Manager | Other
0 comments No comments
{count} votes

Accepted answer
  1. Jason Sandys 31,411 Reputation points Microsoft Employee Moderator
    2022-10-17T21:30:24.76+00:00

    (+1) to @Simon Ren-MSFT 's response. This isn't about effort, it's about technical reality. As called out, there are no truly configurable service accounts in ConfigMgr, i.e., none of the accounts in ConfigMgr actually run services, thus you can't use a managed service account construct.

    3 people found this answer helpful.
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Simon Ren-MSFT 40,346 Reputation points Microsoft External Staff
    2022-10-17T07:39:09.06+00:00

    Hi,

    Per my experience, only the SQL Service account in MECM is a service account so that's the only one that can be configured with a managed service account.

    For other accounts, for example Client Push account, Network Access account and Domain Join account for OSD, as they are not really service accounts, so none of those accounts can be gMSA.

    Thanks for your time. Have a nice day!

    Best regards,
    Simon


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    2 people found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.