Is log on as a batch job required for gMSA accounts?

Daniel 61 Reputation points
2023-02-01T10:36:44.1033333+00:00

I am looking for the definitive answer on this one.

This article says you have to add the account to the "log on as a batch job" privilegie

https://woshub.com/group-managed-service-accounts-in-windows-server-2012/

The creator of this forum thread seem to have stumbled upon that it isn't required. But there are no answers.

https://learn.microsoft.com/en-us/answers/questions/922156/gmsa-and-log-on-as-batch-job-privilege-to-run-a-sc?source=docs

What is the answer to this one? And if it is not required, what makes it work?

Is it a combination of the parameters -DNSHostName and -PrincipalsAllowedToRetrieveManagedPassword ? Or is it one of them? Or is it something completely different that is happening behind the scenes in active directory?

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,111 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Thameur-BOURBITA 32,496 Reputation points
    2023-02-03T13:06:49.2633333+00:00

    Hi,

    PrincipalsAllowedToRetrieveManagedPassword is required to allow GMSA password retrieved on target server. Without that the GMSA password cannot be used even if GMSA account has permissions to logon as the barch and logob as service permission.

    Please don't forget to mark helpful answer as accepted