Creating non-interactive via Computer accounts


hi all,

i have been looking @ using kerberos auth our exchange 2010. documenation reccommends creation of computer accounts spns  "because computer account doesn’t allow interactive logon" http://technet.microsoft.com/en-us/library/ff808312.aspx

can leverage computer accounts all service accounts stops interactive logon? seems better solution system wide gpo , our forest not @ correct level 2008 r2 managed service accounts.

thanks

josh

hi josh

in principle sounds idea use computer accounts service accounts.  caveat can think of whether application using service account going happy computer account.  might want testing common uses within environment (e.g. windows services, schedule tasks, etc.)

2008 r2 msas can used on single machine no cas array (which requires same account computers in array). group managed service accounts (gmsas) feature introduced windows server 2012 on other hand trick nicely.  need microsoft update exchange supportability matrix to understand 2012 fits in (if @ all). 


alexei



Windows Server  >  Directory Services



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client