This article clarifies whether DX Unified Infrastructure Management (UIM) supports the use of Windows Group Managed Service Accounts (gMSA) for service account configuration and its impact on NTLM authentication dependencies.
Is gMSA supported in UIM?
No. At this time, DX UIM components and probes are designed to operate with standard Active Directory service accounts.
Why gMSA is not currently compatible:
data_engine, various probes) require an explicit, shareable password to be entered within the product configuration interface. gMSA accounts do not have a shareable password and manage credentials automatically via Kerberos; therefore, they cannot be entered into these configuration fields.Recommendation We recommend continuing the use of standard Active Directory service accounts for UIM services. Ensure these accounts adhere to your organization’s security policy regarding strong password complexity and regular, automated rotation.