Can we use gMSA accounts for discovering Linux?

RavishShett
Tera Contributor

Hi all,

 

Can we use gMSA accounts for discovering Linux?

 

Link to gMSA: gMSA configuration for Discovery • Australia IT Operations Management • Docs | ServiceNow

 

Thanks,

Ravish

1 REPLY 1

Tanushree Maiti
Mega Patron

Hi @RavishShett 

 

gMSA accounts for discovering is only for Windows discovery: 

Refer: KB0750818 Using a Group Managed Service Account (gMSA) for Windows discovery 

 

After you configure Discovery to use gMSA, password management for that account is handled by the Windows operating system. So, you can run Windows Discovery without sharing credentials with the ServiceNow instance. Benefits include the following:
  • You don’t have to handle gMSA passwords on your own.
  • You can choose the cycle of gMSA password rotation for better security.
  • You don't need to store the password on the ServiceNow instance.
  • The gMSA user doesn't need to be member of a domain admin group.
  • The gMSA user used as the MID Server service account doesn't need to be on the local admin group of the MID Server.

Configure gMSA for Discovery

Use Group Managed Service Accounts (gMSA) to securely run MID Servers and perform Windows discovery without storing passwords locally. This configuration improves security and simplifies credential management by leveraging Active Directory for automatic password rotation and centralized control

Please mark this response as Helpful & Accept it as solution if it assisted you with your question.
Regards
Tanushree Maiti
ServiceNow Technical Architect
Linkedin: