Closed david-sieg closed 2 months ago
Potentially there are some extra properties that need to be set for a MSA that New-ADServiceAccount
does automatically. The msDS-GroupMSAMembership states that it is an NT-Sec-Desc
object which is an SDDL string rather than an identity. While it is possible to build this manually it is very complex and at this point I think we just need to write a module that wraps the *-ADServiceAccount
cmdlets that do this all for you automatically.
SUMMARY
I want to create an Managed Service Account.
ISSUE TYPE
COMPONENT NAME
ANSIBLE VERSION
COLLECTION VERSION
STEPS TO REPRODUCE
EXPECTED RESULTS
An created managed service account.
ACTUAL RESULTS