Automic Workload Automation

 View Only

  • 1.  Automic login objects integrated with Microsoft gMSAs

    Posted Mar 16, 2023 03:12 AM

    Hi Team

    I received a query from one of our customers regarding Microsoft gMSA support on login objects.

    I see there were previous ideas posted but I can not get any detail.

    Ant feedback will be appreciated

    Regards

    Klaus Lintz



  • 2.  RE: Automic login objects integrated with Microsoft gMSAs

    Posted Dec 18, 2023 08:02 AM
    Edited by Michael A. Lowry Dec 18, 2023 08:02 AM

    I added a new idea about this:

    Windows Agent: add support for gMSA users

    If you like the idea, please vote for it.



  • 3.  RE: Automic login objects integrated with Microsoft gMSAs

    Posted Jun 24, 2025 07:04 AM

    Many organizations are pushing towards non-human/application user's passwords expiration, and gMSA is a great alternative.

    We are also looking forward to having it supported in login objects.




  • 4.  RE: Automic login objects integrated with Microsoft gMSAs

    Posted Jun 25, 2025 04:14 AM

    We also have a very strong recommendation from our security department to use gmsa account wherever possible.

    @Kaj Wierda: Any possible confirmation that Broadcom is working on implementing built-in support for gMSA accounts?
    Best regards,
    Thierry




  • 5.  RE: Automic login objects integrated with Microsoft gMSAs

    Broadcom Employee
    Posted Jun 26, 2025 10:23 AM

    Hi @Klaus Lintz

    A gMSA can be used when starting Automic Service Manager that starts an Agent (or Integration) on Microsoft Windows.
    In order to use this Service user, which starts the Agent also for executing a job or performing a file transfer, the OS-agent must be configured to allow anonymous executions by setting GLOBAL/logon = 0
    By doing that the specified user in the Login-object that is assigned to the job is not checked.


    see

    Michael



    ------------------------------
    Michael K. Dolinek

    Engineering Program Manager | Agile Operation Division
    Broadcom Software
    ------------------------------



  • 6.  RE: Automic login objects integrated with Microsoft gMSAs

    Posted Jun 26, 2025 10:57 AM

    Hello @Michael Dolinek

    Thank you for your reply.

    We actually use anonymous jobs already as a workaround, until gMSA are supported in login objects. One of the darwbacks of anonymous jobs is that all jobs executed by all agents on a machine's service manager will also run as the same gMSA, and there are also other incoveniences.

    Also we don't want to have multiple Service Manager on the same machine. Our organisation support having multiple agents in one unique Service Manager.

    Any clue if gMSA will be supported in login objects any time soon as a native feature ?

    Thanks.

    Philippe