AGPM MSA Service Account

Mario A. Hernandez 171 Reputation points
2021-04-06T02:41:24.423+00:00

Recently, I changed the service account for AGPM Servcice to an MSA account. When I did that, the service fails to start, the "Log On" settings tab is grayed out. The error message I receive says that the service started and then stopped. The event log says:
Service cannot be started. Microsoft.Agpm.AgpmException: Service startup was aborted because no matching SPN was found registered for the service account: CN=msa-account,CN=Managed Service Accounts,DC=domain,DC=net

I have tried to register the MSA account but it keeps doing the stopping everytime. Any ideas? Thanks.

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,746 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,127 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Fan Fan 15,291 Reputation points Microsoft Vendor
    2021-04-06T03:46:05.287+00:00

    Hi,
    Check the steps for DEPLOY & CONFIGURE AGPM USING A MSA service account.
    https://marklewis.blog/2017/07/17/deploy-configure-agpm/
    This response contains a third-party link. We provide this link for easy reference. Microsoft cannot guarantee the validity of any information and content in this link.
    Best Regards,

    0 comments No comments