<?xml version="1.0"?>
<rss version="2.0">
<channel>
<title>Thycotic Community - Secret Server - Windows Managed Service accounts in 2008 R2 - Messages</title>
<link>http://www.thycotic.com/forums/messages.aspx?TopicID=279</link>
<description>Thycotic Community - Secret Server - Windows Managed Service accounts in 2008 R2 - Messages</description>
<language>en-us</language>
<docs>http://blogs.law.harvard.edu/tech/rss</docs>
<generator>Jitbit AspNetForum</generator>
<pubDate>Tue, 24 Aug 2010 11:37:51 GMT</pubDate>
<lastBuildDate>Tue, 24 Aug 2010 11:37:51 GMT</lastBuildDate>
<item>
<link>http://www.thycotic.com/forums/messages.aspx?TopicID=279</link>
<title>Message from Adam D</title>
<description><![CDATA[Thank you Jonathan, this is great information.]]></description>
<pubDate>Tue, 24 Aug 2010 11:37:51 GMT</pubDate>
</item>
<item>
<link>http://www.thycotic.com/forums/messages.aspx?TopicID=279</link>
<title>Message from Jonathan</title>
<description><![CDATA[Thanks to David and Kevin on the technical team for putting together these notes:<br/><br/>Managed Service Accounts are a new feature that is available in Windows 7 and Server 2008 R2.  They are special domain accounts that have automatic password management. They exist in the "Managed Service Accounts" container in AD and have their own samAccountName (like groups and users).<br/><br/>Creating new managed service accounts and installing them on local computers can only be done through powershell scripts.<br/>Once created and installed on a machine, a managed service account can be used to run services or application pools by entering DOMAIN\Managed Service Account name (with a dollar sign at the end) as the account name and leaving the password field blank.<br/>Usually, managed service accounts are delegated to have service administrator privileges. However, this can not be done through powershell and must be done through AD DS (or as a Dsacls script).<br/><br/>Managed service account passwords can be reset through powershell (and only powershell), but the password can not be specified since it is automatically managed. Under normal circumstances, the AD DS will automatically reset the password based on domain security principles.<br/>From what I gather, the main benefits are isolation of accounts and automated password resets. They are good for running services and application pools.<br/><br/>The downside is the inconvenience having to create a different account for each machine and the set up time required for each account. It is also time consuming to move a service account from one machine to another. The biggest security downside is that the password is never actually required by the user, so a local admin on a machine with a managed service account installed has complete control over that account.<br/><br/>Right now, Secret Server has no support for managed service accounts but we are looking at integration for a future release.<br/>]]></description>
<pubDate>Tue, 20 Jul 2010 14:46:17 GMT</pubDate>
</item>
<item>
<link>http://www.thycotic.com/forums/messages.aspx?TopicID=279</link>
<title>Message from Adam D</title>
<description><![CDATA[ok, thank you.]]></description>
<pubDate>Wed, 14 Jul 2010 15:33:12 GMT</pubDate>
</item>
<item>
<link>http://www.thycotic.com/forums/messages.aspx?TopicID=279</link>
<title>Message from Jonathan</title>
<description><![CDATA[Adam,<br/><br/>Sorry for the long delay here.  The technical team did some research and sent me their notes - I just haven't had a chance to compile and post them yet.  Will do so soon.<br/><br/>Best.]]></description>
<pubDate>Tue, 22 Jun 2010 04:50:55 GMT</pubDate>
</item>
<item>
<link>http://www.thycotic.com/forums/messages.aspx?TopicID=279</link>
<title>Message from Adam D</title>
<description><![CDATA[Hey Jonathan,<br/>There is a new feature in Windows Server 2008 R2 called Windows Managed Service accounts. I was curious if your team has looked into this and may be incorporating this feature.]]></description>
<pubDate>Fri, 28 May 2010 16:08:03 GMT</pubDate>
</item>
</channel>
</rss>
