Managed Service Accounts

Managed Service Accounts

 This article needs work. Please help update and extend it. If you add new managed service account topics, please add a link to the new topic at the bottom of this page.

Managed service accounts in Windows Server 2008 R2 and Windows 7 are managed domain accounts that provide the following features to simplify service administration:

  • Automatic password management.
  • Simplified SPN management, including delegation of management to other administrators. Additional automatic SPN management is available at the Windows Server 2008 R2 domain functional level.

Use of managed service accounts is considered a security best practice (ref: Microsoft Virtualization: The Complete Solution: Master Microsoft Server).

To use managed service accounts, the client computer on which the application or service is installed must be running Windows Server 2008 R2 or Windows 7. In addition, a hotfix as described in KB 2494158: “Managed service account authentication fails after its password is changed in Windows 7 or in Windows Server 2008 R2" must be applied to the computer where the managed service account exists. One managed service account can be used for services on a single computer. Managed service accounts cannot be shared between multiple computers and cannot be used in server clusters where a service is replicated on multiple cluster nodes.

For more information about application requirements and configuration instructions for using managed service accounts, see the Service Account Step-by-Step Guide 

For additional information, see:

 

Leave a Comment
  • Please add 2 and 4 and type the answer here:
  • Post
Wiki - Revision Comment List(Revision Comment)
Sort by: Published Date | Most Recent | Most Useful
Comments
  • Carsten Siemens edited Revision 16. Comment: Added tag: has comment

  • TNJMAN edited Revision 13. Comment: Addded a note that use of managed service accounts is a security best practice

  • FZB edited Revision 10. Comment: space

  • Pantelis44999 edited Revision 9. Comment: Added needs work template

  • Eric Mitchell MSFT edited Revision 7. Comment: Added information about a hot fix.

  • Yuri Diogenes [MSFT] edited Revision 6. Comment: Adding new tag to reflect on Security Tech Center

  • Ed Price MSFT edited Original. Comment: Removed dead link.

Page 1 of 1 (7 items)
Wikis - Comment List
Sort by: Published Date | Most Recent | Most Useful
Posting comments is temporarily disabled until 10:00am PST on Saturday, December 14th. Thank you for your patience.
Comments
  • Ed Price MSFT edited Original. Comment: Removed dead link.

  • Yuri Diogenes [MSFT] edited Revision 6. Comment: Adding new tag to reflect on Security Tech Center

  • Eric Mitchell MSFT edited Revision 7. Comment: Added information about a hot fix.

  • Pantelis44999 edited Revision 9. Comment: Added needs work template

  • Useful, thanks.

  • Muito util

  • FZB edited Revision 10. Comment: space

  • Very good

  • Excelent!

  • TNJMAN edited Revision 13. Comment: Addded a note that use of managed service accounts is a security best practice

  • Excellent entry point for a broader set of articles on the specifics and/or links like you've done in the article. Thanks.

  • Carsten Siemens edited Revision 16. Comment: Added tag: has comment

Page 1 of 1 (12 items)