Support for Group Managed Service Accounts (gMSA) in DX Unified Infrastructure Management (UIM)
search cancel

Support for Group Managed Service Accounts (gMSA) in DX Unified Infrastructure Management (UIM)

book

Article ID: 451413

calendar_today

Updated On:

Products

DX Unified Infrastructure Management (Nimsoft / UIM)

Issue/Introduction

This article clarifies whether DX Unified Infrastructure Management (UIM) supports the use of Windows Group Managed Service Accounts (gMSA) for service account configuration and its impact on NTLM authentication dependencies.

 

Environment

  • Product: DX Unified Infrastructure Management (UIM) all supported versions
  • Component: Service account configuration, Probe authentication, Database connectivity

Resolution

Is gMSA supported in UIM?
 No. At this time, DX UIM components and probes are designed to operate with standard Active Directory service accounts.

Why gMSA is not currently compatible:

  1. Credential Management: Many UIM components (e.g., data_engine, various probes) require an explicit, shareable password to be entered within the product configuration interface. gMSA accounts do not have a shareable password and manage credentials automatically via Kerberos; therefore, they cannot be entered into these configuration fields.
  2. Authentication Protocols: UIM database connectivity and probe authentication frequently rely on Windows Authentication mechanisms that may require interactive or service-specific logon rights. gMSA accounts may not provide the necessary privileges required for these interactions.

Recommendation We recommend continuing the use of standard Active Directory service accounts for UIM services. Ensure these accounts adhere to your organization’s security policy regarding strong password complexity and regular, automated rotation.