Forum Discussion

Burke's avatar
Burke
Copper Contributor
Dec 15, 2023
Solved

Server VNext Build 26010 - dMSA - PrincipalsAllowedToRetrieveManagedPassword not populating

Hello, 

 

Trying to test dMSAs in a lab environment and notice that the PrincipalsAllowedToRetrieveManagedPassword (msDS-GroupMSAMembership) attribute is not populating with the server name that I've configured a service to run under the context of a normal service account. 

 

The msDS-DelegatedMSAState is 1, msDS-ManagedAccountPrecededByLink is populated with the DN of the regular account, etc. 

 

The regular account was automatically granted Write access to the msDS-GroupMSAMembership as part of the migration process but is not being populated on service restart. I can manually populate the attribute, however after completing the ADServiceAccountMigration, the service will no longer restart. I've also experienced this issue with Build 25997.

 

Thanks for any troubleshooting assistance you can provide.

 

  • Please try using a build later than 26043. This feature was enabled recently
  • Please try using a build later than 26043. This feature was enabled recently

Resources