Skip to content

Commit

Permalink
Update create-and-manage-ad-objects.md
Browse files Browse the repository at this point in the history
  • Loading branch information
ty-abbott authored Feb 7, 2025
1 parent 29eb992 commit 308e499
Showing 1 changed file with 9 additions and 0 deletions.
9 changes: 9 additions & 0 deletions content/windows/create-and-manage-ad-objects.md
Original file line number Diff line number Diff line change
Expand Up @@ -26,3 +26,12 @@ A managed service account is an AD DS object class that enables:
- Simplified SPN management.

Group managed service accounts
- basically takes managed acounts and goes one step further allowing the service account to be used on more than one server.

Use cases for computer accounts
- A computer account in a domain is primarily used to authenticate and manage access to network resources for individual computers within a domain, allowing for centralized control over which computers can access shared files, printers, and other network services, while also enabling security policies to be applied based on the computer's identity and group memberships; essentially acting as a security principal for each device on the network.
- You must create a KDS root key on a domain controller in the domain for group managed service accounts to work

Group types
- security - Security groups are security-enabled, and you use them to assign permissions to various resources. You can use security groups in permission entries in access control lists (ACLs) to help control security for resource access. If you want to use a group to manage security, it must be a security group.
- distribution - Email applications typically use distribution groups, which are not security-enabled. You also can use security groups as a means of distribution for email applications.

0 comments on commit 308e499

Please sign in to comment.