August 2019
Intermediate to advanced
786 pages
20h 22m
English
In the previous section, we talked about MSAs. One MSA can be used with one computer only. But there are operational requirements that require the same service account to be shared in multiple hosts. Microsoft's Network Load Balancing (NLB) feature and Internet Information Services (IIS) server farms are good examples of this. All the hosts in these server groups are required to use the same service principal for authentication. gMSAs provide the same functionalities as MSAs, but they extend the higher AD forest level. This was first introduced with Windows Server 2012.
The gMSA has the following capabilities: