AD v2 Spoke Authentication Failed When Using MID Server Service Account (gMSA)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
2 hours ago
Hi Community,
We are integrating Active Directory with ServiceNow using the Microsoft Active Directory v2 Spoke.
Our MID Server is running under a gMSA (Group Managed Service Account). For the Windows Credential record, we selected "Use MID Server Service Account" and left the Username and Password fields blank.
However, when running Test Credential, we receive the following error: Authentication failed
We would like to understand:
- Is this authentication failure expected when the MID Server service account is a gMSA?
- Does the Microsoft AD v2 Spoke support using a gMSA through the "Use MID Server Service Account" option?
- Does the AD v2 Spoke require a dedicated AD service account with an explicit username and password stored in the ServiceNow Credential record?
We have already verified:
- MID Server is operational and online.
- Network connectivity to the Domain Controller over ADWS (port 9389) is available.
- The MID Server service is running under a gMSA account.
Has anyone successfully configured AD v2 Spoke using a gMSA, or is a traditional AD service account with username and password mandatory?
Any guidance would be appreciated.
Thank you.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
23m ago
Group Managed Service Accounts (gMSA) are not supported for use with the Microsoft Active Directory v2 Spoke.
gMSA relies on Windows‑level authentication and automatic password management mechanisms that are not compatible with how the AD v2 Spoke consumes credentials. Due to this architectural limitation from the Microsoft side, the AD v2 Spoke cannot use gMSA accounts.
Please mark the answer as Correct , if it helps you.
