Microsoft Entra Provisioning Agent - Unable to install service account pgmsa_... after 6 retries

Cain, Alastair G 20 Reputation points
2023-10-31T17:06:04.93+00:00

I am trying to install the Entra Cloud Sync Provisioning Agent (v1.1.1370.0) on Windows Server 2019. This a test environment, single Domain, single DC. The install is on the DC.

Completing the connection to Entra ID, then connect to AD, then confirm, are successful.

On the Confirm page, it says that the gMSA is being created but fails with the following error:

"Error while creating group managed service account (gMSA). Error: Unable to install service account pGMSA_

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,629 questions
0 comments No comments
{count} votes

Accepted answer
  1. Givary-MSFT 30,931 Reputation points Microsoft Employee
    2023-11-01T05:42:39.5666667+00:00

    @Cain, Alastair G I'm glad that you were able to resolve your issue and thank you for posting your solution so that others experiencing the same thing can easily reference this! Since the Microsoft Q&A community has a policy that "The question author cannot accept their own answer. They can only accept answers by others Opens in new window or tab", I'll repost your solution in case you'd like to "Accept Opens in new window or tab" the answer.

    Issue: trying to install the Entra Cloud Sync Provisioning Agent (v1.1.1370.0) on Windows Server 2019. This a test environment, single Domain, single DC. The install is on the DC.

    Completing the connection to Entra ID, then connect to AD, then confirm, are successful.

    On the Confirm page, it says that the gMSA is being created but fails with the following error:

    "Error while creating group managed service account (gMSA). Error: Unable to install service account pGMSA_

    Solution: Resolved by @Cain, Alastair G have been doing some more digging and found the following comprehensive article "Migrating from AADConnect Sync to Entra Connect Cloud Sync Correctly" which includes this error.

    https://c7solutions.com/2023/09/migrating-from-aadconnect-sync-to-entra-connect-cloud-sync-correctly#:~:text=after%206%20retries-,The%20above%20error,-%2C%20if%20you%20get

    The issue is resolved after running the following command, followed by a reboot and a reinstall of the agent.

    "Set-ADServiceAccount -Identity CN=provAgentgMSA,CN=Managed Service Accounts,dc=... -KerberosEncryptionType AES128,AES256"

    If you have any other questions or are still running into more issues, please let me know.
    Thank you again for your time and patience throughout this issue.

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.

    1 person found this answer helpful.

2 additional answers

Sort by: Most helpful
  1. Cain, Alastair G 20 Reputation points
    2023-10-31T17:57:58.1633333+00:00

    We have been doing some more digging and found the following comprehensive article "Migrating from AADConnect Sync to Entra Connect Cloud Sync Correctly" which includes this error.

    https://c7solutions.com/2023/09/migrating-from-aadconnect-sync-to-entra-connect-cloud-sync-correctly#:~:text=after%206%20retries-,The%20above%20error,-%2C%20if%20you%20get

    The issue is resolved after running the following command, followed by a reboot and a reinstall of the agent.

    "Set-ADServiceAccount -Identity CN=provAgentgMSA,CN=Managed Service Accounts,dc=... -KerberosEncryptionType AES128,AES256"

    0 comments No comments

  2. Cain, Alastair G 20 Reputation points
    2023-10-31T17:58:50.3266667+00:00

    We have been doing some more digging and found the following comprehensive article "Migrating from AADConnect Sync to Entra Connect Cloud Sync Correctly" which includes this error.

    https://c7solutions.com/2023/09/migrating-from-aadconnect-sync-to-entra-connect-cloud-sync-correctly#:~:text=after%206%20retries-,The%20above%20error,-%2C%20if%20you%20get

    The issue is resolved after running the following command, followed by a reboot and a reinstall of the agent.

    "Set-ADServiceAccount -Identity CN=provAgentgMSA,CN=Managed Service Accounts,dc=... -KerberosEncryptionType AES128,AES256"

    0 comments No comments