Can't create gMSA account after sync quit working

Bill 1 Reputation point

B:32:1EB93889E40C45DF9F0C64D23BBB6237:CN=Managed Service Accounts\0ADEL:e5f8637
e-7e61-4ece-967a-58418f7f54c9,CN=Deleted Objects,DC=TRI,DC=local

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,576 questions
0 comments No comments
{count} votes

5 answers

Sort by: Most helpful
  1. rr-4098 986 Reputation points

    What is the error message you are getting? Also what OS are the DC's running?

    0 comments No comments

  2. Bill 1 Reputation point

    When running Microsoft Azure Active Directory Connect Provisioning.

    Agent. Sync has been working for 2 years and started failing about 3 weeks ago.

    2012r2 and 2012

    Error while creating group managed service account (gMSA). Error: there is no such object on the server.

    Both domain and forest levels are 2012. no errors in AzureADConnect event log

    No errors in application filter "Directory Synchronization" event logs

    Thanks for your reply!


    0 comments No comments

  3. Gary Reynolds 9,376 Reputation points

    Hi @Bill

    From the output of the otherWellKnownObjects, the CN=Managed Service Accounts container has been deleted. You should probably try and restore the container first , you can use this article to restore the container -


  4. Bill 1 Reputation point

    Sorry, broke my left foot. I'll attempt suggestions tomorrow morning when I'm onsite. I do appreciate the response and help offered!


    0 comments No comments

  5. Bill 1 Reputation point

    So I was able to finally fix issue.

    AD recycle bin was not enabled so I re-ran adprep to recreate missing objects. "Managed Services Accounts" and "otherWellKnowObjects" "B:32:1E(etc)

    created KDS key etc.

    Using AD powershell: New-ADServiceAccount -Name gMSA365 -Path "CN = Managed Service Accounts, DC=something, DC=local" -DNSHostName domain-controller01.something.local

    I now have a gMSA365 "msDS-GroupManagedServiceAccount" object in my "Managed Services Accounts" container.

    Thanks everyone!

    0 comments No comments