<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic gMSA integration with AD2016, creating computer account in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/gmsa-integration-with-ad2016-creating-computer-account/m-p/208936#M61117</link>
    <description>&lt;P&gt;I'm working with our AD admin, and we are trying to replace our DCAdmin account with a service account on our firewall. With AD2016, the MSA/gMSA accounts require that you link the account to a computer object.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've seen in a couple documents that it eludes to the fact that MSA's can be used, but it doesn't give any information how. What we are wanting to know is, can the PAN firewall create a computer object on the Domain Controller, and how is that done if it can?&lt;/P&gt;</description>
    <pubDate>Thu, 05 Apr 2018 20:58:13 GMT</pubDate>
    <dc:creator>JohPalmer</dc:creator>
    <dc:date>2018-04-05T20:58:13Z</dc:date>
    <item>
      <title>gMSA integration with AD2016, creating computer account</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gmsa-integration-with-ad2016-creating-computer-account/m-p/208936#M61117</link>
      <description>&lt;P&gt;I'm working with our AD admin, and we are trying to replace our DCAdmin account with a service account on our firewall. With AD2016, the MSA/gMSA accounts require that you link the account to a computer object.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've seen in a couple documents that it eludes to the fact that MSA's can be used, but it doesn't give any information how. What we are wanting to know is, can the PAN firewall create a computer object on the Domain Controller, and how is that done if it can?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Apr 2018 20:58:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gmsa-integration-with-ad2016-creating-computer-account/m-p/208936#M61117</guid>
      <dc:creator>JohPalmer</dc:creator>
      <dc:date>2018-04-05T20:58:13Z</dc:date>
    </item>
    <item>
      <title>Re: gMSA integration with AD2016, creating computer account</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gmsa-integration-with-ad2016-creating-computer-account/m-p/209121#M61153</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/78672"&gt;@JohPalmer&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In which documents did you find information that this is possible?&lt;/P&gt;&lt;P&gt;Because I cannot think of a way this is possible, as the service account credentials are static in the firewall configuration and the only way to change these credentials is if you do it manually (or automatically, but this you have to automate by yourself).&lt;/P&gt;</description>
      <pubDate>Sat, 07 Apr 2018 15:36:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gmsa-integration-with-ad2016-creating-computer-account/m-p/209121#M61153</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-04-07T15:36:45Z</dc:date>
    </item>
    <item>
      <title>Re: gMSA integration with AD2016, creating computer account</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gmsa-integration-with-ad2016-creating-computer-account/m-p/209309#M61204</link>
      <description>&lt;P&gt;I spoke with PAN TAC on Friday afternoon, and they also confirmed that this isn't an option.&amp;nbsp; We are going with a standard service account for this.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Apr 2018 20:14:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gmsa-integration-with-ad2016-creating-computer-account/m-p/209309#M61204</guid>
      <dc:creator>JohPalmer</dc:creator>
      <dc:date>2018-04-09T20:14:18Z</dc:date>
    </item>
  </channel>
</rss>

