Interested in a ServiceNow event built for developers? Registration for now[dev]26 is officially open!

AD v2 Spoke Authentication Failed When Using MID Server Service Account (gMSA)

Subalakshmi P2
Tera Contributor

Hi Community,

We are integrating Active Directory with ServiceNow using the Microsoft Active Directory v2 Spoke.

Our MID Server is running under a gMSA (Group Managed Service Account). For the Windows Credential record, we selected "Use MID Server Service Account" and left the Username and Password fields blank.

However, when running Test Credential, we receive the following error: Authentication failed

We would like to understand:

  1. Is this authentication failure expected when the MID Server service account is a gMSA?
  2. Does the Microsoft AD v2 Spoke support using a gMSA through the "Use MID Server Service Account" option?
  3. Does the AD v2 Spoke require a dedicated AD service account with an explicit username and password stored in the ServiceNow Credential record?

We have already verified:

  • MID Server is operational and online.
  • Network connectivity to the Domain Controller over ADWS (port 9389) is available.
  • The MID Server service is running under a gMSA account.

Has anyone successfully configured AD v2 Spoke using a gMSA, or is a traditional AD service account with username and password mandatory?

Any guidance would be appreciated.

Thank you.

1 REPLY 1

Mehta
Tera Contributor

@Subalakshmi P2 , 

 

Group Managed Service Accounts (gMSA) are not supported for use with the Microsoft Active Directory v2 Spoke.

gMSA relies on Windows‑level authentication and automatic password management mechanisms that are not compatible with how the AD v2 Spoke consumes credentials. Due to this architectural limitation from the Microsoft side, the AD v2 Spoke cannot use gMSA accounts.

 

gMSA Support for Microsoft Active Directory v2 Spoke Password Reset Operations - Support and Trouble...

 

Please mark the answer as Correct , if it helps you.