Configure Managed Service Account for Active Directory
Microsoft Active Directory guide
Run NIM with a managed service account (MSA) to grant only the permissions it needs—without using a highly privileged interactive account.
Before you beginDirect link to Before you begin
Microsoft's group managed service account guidance provides background on managed credentials and service account ownership. This guide creates a single-computer MSA with -RestrictToSingleComputer; confirm which managed account type your environment requires before following the commands. In either case, delegate directory rights separately to the scope NIM manages.
Run these commands in an elevated PowerShell session on the NIM server.
Choose an account name and identify the NIM server that will use it.
Plan the Active Directory organizational units that NIM needs to manage.
Create and install the service accountDirect link to Create and install the service account
1. Create the managed service accountDirect link to 1. Create the managed service account
New-ADServiceAccount -Name <NAMEOFACCOUNT> -RestrictToSingleComputer
By default, the MSA is created in CN=Managed Service Accounts. Use the -Path parameter to select a different organizational unit. -RestrictToSingleComputer limits the account to one server.
2. Link the account to the NIM serverDirect link to 2. Link the account to the NIM server
Replace <NIMSERVERNAMEHERE> with the name of the NIM server and <NAMEOFACCOUNT> with the MSA you created.
$TargetServer = Get-ADComputer -Identity <NIMSERVERNAMEHERE>
Add-ADComputerServiceAccount -Identity $TargetServer -ServiceAccount <NAMEOFACCOUNT>
3. Verify and install the accountDirect link to 3. Verify and install the account
Get-ADServiceAccount <NAMEOFACCOUNT>
Install-ADServiceAccount -Identity <NAMEOFACCOUNT>
Test-ADServiceAccount <NAMEOFACCOUNT>
Test-ADServiceAccount should return True. After installation, follow the Configure connection guide to assign the account to the NIM Windows service.
Delegate Active Directory permissionsDirect link to Delegate Active Directory permissions
- Create an Active Directory group for the MSA and add the MSA as a member.
- In Active Directory Users and Computers, right-click the domain root or the relevant organizational unit, then select Delegate Control.
- Add the group you created and delegate the tasks NIM requires. Common permissions include:
- Create, delete, and manage user accounts
- Reset user passwords and force password change at next sign-in
- Read all user information
- Modify group membership
- On the NIM server, grant that group Full control to:
C:\ProgramData\Tools4ever\NIMC:\Program Files\Tools4ever\NIM\sysconfig