-
Notifications
You must be signed in to change notification settings - Fork 1.9k
Update manage-group-managed-service-accounts.md #8107
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
|
Learn Build status updates of commit ac4202f: ✅ Validation status: passed
For more details, please refer to the build report. |
|
#assign: @robinharwood, @dknappettmsft @robinharwood @dknappettmsft #label:"aq-pr-triaged" |
|
@WAftring : Thanks for your contribution! The author(s) and reviewer(s) have been notified to review your proposed change. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Pull request overview
This PR adds documentation about Kerberos encryption type requirements for systems using group-managed service accounts (gMSAs).
- Adds a new requirement bullet point explaining that systems must support required Kerberos encryption types to use gMSAs
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
...ged-service-accounts/group-managed-service-accounts/manage-group-managed-service-accounts.md
Outdated
Show resolved
Hide resolved
|
|
||
| - All systems involved in the authentication process must have synchronized clocks. Kerberos is sensitive to time configuration, and discrepancies can cause authentication failures. | ||
|
|
||
| - All systems that are intended to logon as, or be installed with a gMSA must support Kerberos encryption types required by gMSA. Systems that do not meet this requirement cannot log on or install gMSA. |
Copilot
AI
Dec 9, 2025
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The phrasing "cannot log on or install gMSA" is unclear. It should be "cannot log on as a gMSA or have a gMSA installed" to maintain parallel structure and clarity with the first part of the sentence.
| - All systems that are intended to logon as, or be installed with a gMSA must support Kerberos encryption types required by gMSA. Systems that do not meet this requirement cannot log on or install gMSA. | |
| - All systems that are intended to log on as a gMSA or have a gMSA installed must support the Kerberos encryption types required by gMSA. Systems that do not meet this requirement cannot log on as a gMSA or have a gMSA installed. |
…accounts/group-managed-service-accounts/manage-group-managed-service-accounts.md Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
|
Learn Build status updates of commit 9a744d6: ✅ Validation status: passed
For more details, please refer to the build report. |
No description provided.