Group Managed Service Accounts - Cross Domain - Cross Forest

Chrisagardner63 1 Reputation point
2021-04-01T12:05:03.437+00:00

Working with GMSA's.

We have a mult-Forest, multi-Domain environment.

I am having problems finding, understanding the following, making sure I am not doing something wrong.

Can I create a GMSA in the Forest Root and have servers in the Child Domains set for password retrieval? My testing is telling me no.

If I create a GMSA in Forest A, can a server in Forest B (Two-Way Trust) be set for password retrieval for the GMSA in Forest A?

The documentation I have found with Microsoft doesn't address this.

Windows for business | Windows Server | User experience | Other
{count} votes

2 answers

Sort by: Most helpful
  1. Anonymous
    2021-04-02T03:17:19.26+00:00

    Hello @Chrisagardner63 ,

    Thank you for posting here.

    After my research, we can see Gmsa is domain-wide.

    83800-domain.png

    Reference
    Getting Started with Group Managed Service Accounts
    https://learn.microsoft.com/en-us/windows-server/security/group-managed-service-accounts/getting-started-with-group-managed-service-accounts

    Hope the information above is helpful.

    Should you have any question or concern, please feel free to let us know.

    Best Regards,
    Daisy Zhou

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments

  2. Hawk Zhang 0 Reputation points Microsoft External Staff
    2023-12-20T02:41:22.56+00:00

    Hi guys,

    I had the same question these days. After investigation through the updated document. I found a huge update of the scope of gMSA.

    It turns out that "Use of the gMSA is scoped to any machine that is able to use LDAP to retrieve the gMSA's credentials.".

    So, it'll work even across bi-directional trust forests now.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.