Does DHCP DNS Dynamic update registration credentials support the use of GMSA on Windows Server 2016?

Blueidgirl74 21 Reputation points
2022-08-23T13:31:40.063+00:00

I am trying to find an automated method for all of our service accounts within the domain. One account is the DHCP service account used for dynamic registrataion of objects. I would like to convert this to a Group Managed Service Account so the password on the Advance Tab/Credentials no longer has to be updated? Is this possible and if so What is the process to configure it? If GMSA can't be used is there another method that can be used to automatically update the password for this service?

Windows DHCP
Windows DHCP
Windows: A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.DHCP: Dynamic Host Configuration Protocol (DHCP). A communications protocol that lets network administrators manage centrally and automate the assignment of Internet Protocol (IP) addresses in an organization's network.
1,021 questions
0 comments No comments
{count} votes

Accepted answer
  1. Limitless Technology 39,336 Reputation points
    2022-08-26T07:30:59.543+00:00

    Hello

    Thank you for your question and reaching out. I can understand you are having query related to DHCP DNS Dynamic update registration credentials.

    I believe for DHCP it will not work as you have to specify a password for the DNS Dynamic Update Credentials in DHCP console while gMSA does not provide a password

    ------------------------------------------------------------------------------------------------------------------------------------

    --If the reply is helpful, please Upvote and Accept as answer--

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Arnaud 1 Reputation point
    2023-01-20T06:24:22.8233333+00:00

    Hi,

    The easy way to give DHCP permissions to update DNS is to put the account inside the DNSUpdateProxy group.

    Cheers

    0 comments No comments