Glossary
Group managed service account (gMSA)
A gMSA is an Active Directory account type with an automatically rotated, randomly generated password managed by the domain itself.
A Group Managed Service Account (gMSA) is a special Active Directory account type designed for running services, scheduled tasks, and applications without a human-managed password. The domain controller automatically generates and rotates a 240-byte (120-character) random password on a configurable schedule, and only the specific computer accounts authorized in the gMSA's configuration are permitted to retrieve and use it, removing the need for administrators to know, store, or manually change the credential.
This matters because service accounts are a prime target for credential theft and Kerberoasting, and gMSAs directly remove the two weaknesses attackers rely on: static, often weak passwords and broad account knowledge across administrators. Migrating eligible service accounts to gMSA (or, on Windows Server 2025, migrating hard-to-re-point accounts in place to a delegated managed service account, dMSA) significantly reduces the attack surface with minimal operational overhead, and is one of the highest-value, lowest-effort hardening steps available.