Group Managed Service Accounts
Add-KdsRootKey -EffectiveTime (Get-Date).AddHours(-10)
New-ADServiceAccount -Name 'gMSA_ADCS_prod' -DNSHostName 'ca.boxcreator.htb'
Set-ADServiceAccount -Identity 'gMSA_ADCS_prod' -PrincipalsAllowedToRetrieveManagedPassword 'Infrastructure Managers'Last updated