HSLockdown for domain controllers

richard scott 106 Reputation points
2020-08-25T16:28:17.897+00:00

Afternoon All

i am currently trying to build a case to add scom agents on to domain controllers with the help of HSLockldown tool, however i cannot confirm whether this Lockdown tool can be defined against a GMSA Account.

Has anybody tried this ?

scom version is OM2019 UR1 (soon to be 2)

Many Thanks

Richard

Operations Manager
Operations Manager
A family of System Center products that provide infrastructure monitoring, help ensure the predictable performance and availability of vital applications, and offer comprehensive monitoring for datacenters and cloud, both private and public.
1,420 questions
0 comments No comments
{count} votes

Accepted answer
  1. Crystal-MSFT 44,406 Reputation points Microsoft Vendor
    2020-08-26T02:49:18.657+00:00

    Hi Richard,

    Based as I know, when deploying SCOM Agents to Domain controllers, we might see it goes into a heartbeat failed state.We need to remove the explicit deny for Local System, and add it to the allowed list by the following command:
    HSLockdown.exe /A “NT AUTHORITY\SYSTEM”

    Here is an article for the reference: (Although the article is for SCOM 2016, it is also applied to SCOM 2019 UR1)
    https://kevinholman.com/2016/11/04/deploying-scom-2016-agents-to-domain-controllers-some-assembly-required/
    Note: Non-Microosft link, just for the reference.

    From your description, I know you want to use lockdown tool to define permission for GMSA account.If the error on DC is also with this account, we can add it to the allowed list. Based on my test, the answer for your question is yes.

    For the Account used in HSLockdown, it need to be specified in one of the following fully qualified domain name (FQDN) formats:

    • NetBios : DOMAIN\username
    • UPN : username@fqdn.com

    We can check the msDS-PrincipleName of the GMSA account and assign the permission using the following command:
    HSLockdown.exe /A <msDS-PrincipleName of the GMSA account>
    Note: please change the infromation to the one in the environment.

    20391-image.png

    Hope it can help.


    If the response is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. CyrAz 5,181 Reputation points
    2020-08-26T16:54:36.057+00:00

    I see one issue here : I don't believe it is supported to run the SCOM agent using a GMSA in the first place...

    0 comments No comments