{"id":10382,"date":"2023-11-30T10:56:30","date_gmt":"2023-11-30T09:56:30","guid":{"rendered":"https:\/\/blog.capdata.fr\/?p=10382"},"modified":"2023-12-13T10:53:06","modified_gmt":"2023-12-13T09:53:06","slug":"les-managed-service-account-msa-et-gmsa-se-simplifier-la-vie-pour-gerer-ses-comptes-de-service-sql-server","status":"publish","type":"post","link":"https:\/\/blog.capdata.fr\/index.php\/les-managed-service-account-msa-et-gmsa-se-simplifier-la-vie-pour-gerer-ses-comptes-de-service-sql-server\/","title":{"rendered":"Les Managed Service Account (MSA et gMSA) : se simplifier la vie pour g\u00e9rer ses comptes de service SQL Server"},"content":{"rendered":"<a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-twitter nolightbox\" data-provider=\"twitter\" target=\"_blank\" rel=\"nofollow\" title=\"Share on Twitter\" href=\"https:\/\/twitter.com\/intent\/tweet?url=https%3A%2F%2Fblog.capdata.fr%2Findex.php%2Fwp-json%2Fwp%2Fv2%2Fposts%2F10382&#038;text=Article%20sur%20le%20blog%20de%20la%20Capdata%20Tech%20Team%20%3A%20\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img loading=\"lazy\" decoding=\"async\" alt=\"twitter\" title=\"Share on Twitter\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none;box-shadow: none\" src=\"https:\/\/blog.capdata.fr\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/twitter.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-linkedin nolightbox\" data-provider=\"linkedin\" target=\"_blank\" rel=\"nofollow\" title=\"Share on Linkedin\" href=\"https:\/\/www.linkedin.com\/shareArticle?mini=true&#038;url=https%3A%2F%2Fblog.capdata.fr%2Findex.php%2Fwp-json%2Fwp%2Fv2%2Fposts%2F10382&#038;title=Les%20Managed%20Service%20Account%20%28MSA%20et%20gMSA%29%20%3A%20se%20simplifier%20la%20vie%20pour%20g%C3%A9rer%20ses%20comptes%20de%20service%20SQL%20Server\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img loading=\"lazy\" decoding=\"async\" alt=\"linkedin\" title=\"Share on Linkedin\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none;box-shadow: none\" src=\"https:\/\/blog.capdata.fr\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/linkedin.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-mail nolightbox\" data-provider=\"mail\" rel=\"nofollow\" title=\"Share by email\" href=\"mailto:?subject=Les%20Managed%20Service%20Account%20%28MSA%20et%20gMSA%29%20%3A%20se%20simplifier%20la%20vie%20pour%20g%C3%A9rer%20ses%20comptes%20de%20service%20SQL%20Server&#038;body=Article%20sur%20le%20blog%20de%20la%20Capdata%20Tech%20Team%20%3A%20:%20https%3A%2F%2Fblog.capdata.fr%2Findex.php%2Fwp-json%2Fwp%2Fv2%2Fposts%2F10382\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px\"><img loading=\"lazy\" decoding=\"async\" alt=\"mail\" title=\"Share by email\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none;box-shadow: none\" src=\"https:\/\/blog.capdata.fr\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/mail.png\" \/><\/a><p>Pour faire tourner son service SQL Server sous Windows, il y a diff\u00e9rentes \u00e9coles. Certains veulent un compte de service cr\u00e9\u00e9 dans l&#8217;Active Directory, afin d&#8217;y appliquer des GPO et bien les identifier avec un nom explicite. D&#8217;autres pr\u00e9f\u00e8rent garder les choses simples et laissent les Virtual Service Account (<em>NT Service\\MSSQLSERVER<\/em>).<\/p>\n<p>Le probl\u00e8me avec le passage sur un compte de service d\u00e9di\u00e9 est le risque de mauvaise administration et de s&#8217;en servir pour ouvrir une session interactive, combin\u00e9 avec l&#8217;\u00e9ventualit\u00e9 que le mot de passe soit r\u00e9cup\u00e9r\u00e9 par un utilisateur malicieux. On peut donc mettre en place une strat\u00e9gie d&#8217;expiration de mot de passe, mais alors la rotation des mots de passe dans le parc peut vite devenir infernale !<\/p>\n<p>C&#8217;est l\u00e0 qu&#8217;intervient une solution assez m\u00e9connue : les Managed Service Account. L&#8217;une des principales raisons pour laquelle cette solution est m\u00e9connue est qu&#8217;elle n\u00e9cessite que le niveau fonctionnel de la for\u00eat Active Directory soit au minimum au niveau fonctionnel de <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows-server\/security\/group-managed-service-accounts\/getting-started-with-group-managed-service-accounts#BKMK_gMSA_Req\">Windows 2012.<\/a><\/p>\n<p>Maintenant que nous sommes en 2023, on peut supposer que la plupart des infrastructures Active Directory sont dans des niveaux sup\u00e9rieurs.<\/p>\n<p>Les MSA \u00e9taient le premier nom donn\u00e9 \u00e0 ce type de compte, et ne fonctionnait que pour les service qui tournaient sur une seule machine. Peu de temps apr\u00e8s a \u00e9t\u00e9 ajout\u00e9 la possibilit\u00e9 de fonctionner sur un cluster avec la notion de Group Managed Service Account. Mais les commandes restent les m\u00eames.<\/p>\n<h2>Pr\u00e9-requis \u00e0 l&#8217;utilisation d&#8217;un Managed Service Account pour SQL Server (MSA\/gMSA) :<\/h2>\n<p>Comme indiqu\u00e9, le premier pr\u00e9-requis est au niveau de l&#8217;Active Directory qui doit \u00eatre au niveau fonctionnel 2012 ou sup\u00e9rieur.<\/p>\n<p>Pour SQL Server, si c&#8217;est pour travailler avec une instance &#8220;standalone&#8221; , il faudra un SQL Server 2014. Pour de l&#8217;AlwaysOn et du Failover Cluster Instance (FCI), cela n\u00e9cessitant la couche cluster, et donc un gMSA, il faudra un SQL Server 2016.<\/p>\n<p>Pour cr\u00e9er un (g)MSA, il faudra soit \u00eatre administrateur du domaine ou bien disposer du privil\u00e8ge de cr\u00e9ation des objets de type &#8220;msDS-GroupManagedServiceAccount&#8221;.<\/p>\n<p>Un acc\u00e8s PowerShell avec l&#8217;extension Active Directory (disponible par exemple en installant le feature Windows &#8220;Remote Management&#8221;) doit \u00eatre pr\u00e9sent sur les machines SQL Server.<\/p>\n<p>Afin de faire fonctionnaire les MSA, ils est \u00e9galement n\u00e9cessaire qu&#8217;une infrastructure KDS soit pr\u00e9sente sur le domaine. Si vous ne savez pas si vous en avez une, vous pouvez interrogez votre domaine avec la commande PowerShell Get-KDSRootKey :<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-10383\" src=\"https:\/\/blog.capdata.fr\/wp-content\/uploads\/2023\/11\/GetRootKey-300x152.png\" alt=\"\" width=\"614\" height=\"311\" srcset=\"https:\/\/blog.capdata.fr\/wp-content\/uploads\/2023\/11\/GetRootKey-300x152.png 300w, https:\/\/blog.capdata.fr\/wp-content\/uploads\/2023\/11\/GetRootKey.png 739w\" sizes=\"auto, (max-width: 614px) 100vw, 614px\" \/><\/p>\n<p>On voit ici qu&#8217;une cl\u00e9 a \u00e9t\u00e9 cr\u00e9\u00e9e le 29\/11\/2023.<\/p>\n<p>Si jamais vous n&#8217;en avez pas, il faut la cr\u00e9er avec la commande :<\/p>\n<pre class=\"brush: plain; title: ; notranslate\" title=\"\">\r\nAdd-KdsRootKey -EffectiveImmediately\r\n<\/pre>\n<p>Bien que le param\u00e8tre <em>EffectiveImmediately<\/em> permette son usage imm\u00e9diatement, j&#8217;ai rencontr\u00e9 des d\u00e9lais avant que mes machines SQL Server puissent utiliser les MSA, il se peut donc qu&#8217;il faille attendre \u00e9galement chez vous. Par ailleurs, si vous avez plusieurs contr\u00f4leurs de domaine, le temps de r\u00e9plication peut atteindre 10 heures.<\/p>\n<h2>Cr\u00e9ation d&#8217;un gMSA pour SQL Server :<\/h2>\n<p>Notre but ici est de cr\u00e9er un compte de service manag\u00e9 pour un SQL Server 2022 avec un groupe de disponibilit\u00e9. Nous sommes dans le sc\u00e9nario le plus compliqu\u00e9, o\u00f9 SQL Server a d\u00e9j\u00e0 \u00e9t\u00e9 install\u00e9 et le groupe de disponibilit\u00e9 est d\u00e9j\u00e0 pr\u00e9sent.<\/p>\n<p>Notre configuration est telle que nous avons deux serveurs LAB1SQL1 et LAB1SQL2 avec un listener pour le groupe de disponibilit\u00e9 LAB1_LSTN. Nous voulons un compte de service commun pour nos deux serveurs SQL que l&#8217;on appellera LAB1_gMSA. Nous voulons \u00e9galement que les SPN soient enregistr\u00e9s correctement sans intervention suppl\u00e9mentaire.<\/p>\n<h2>Cr\u00e9ation d&#8217;un groupe AD pour les machines autoris\u00e9es \u00e0 utiliser le gMSA :<\/h2>\n<p>Dans la console Active Directory Users and Computers, on va cr\u00e9er un groupe de s\u00e9curit\u00e9 et y ajouter les deux comptes ordinateurs de notre groupe de disponibilit\u00e9 :<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-10384\" src=\"https:\/\/blog.capdata.fr\/wp-content\/uploads\/2023\/11\/group1-300x259.png\" alt=\"\" width=\"577\" height=\"498\" srcset=\"https:\/\/blog.capdata.fr\/wp-content\/uploads\/2023\/11\/group1-300x259.png 300w, https:\/\/blog.capdata.fr\/wp-content\/uploads\/2023\/11\/group1.png 437w\" sizes=\"auto, (max-width: 577px) 100vw, 577px\" \/><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-10385\" src=\"https:\/\/blog.capdata.fr\/wp-content\/uploads\/2023\/11\/group2-264x300.png\" alt=\"\" width=\"515\" height=\"585\" srcset=\"https:\/\/blog.capdata.fr\/wp-content\/uploads\/2023\/11\/group2-264x300.png 264w, https:\/\/blog.capdata.fr\/wp-content\/uploads\/2023\/11\/group2.png 400w\" sizes=\"auto, (max-width: 515px) 100vw, 515px\" \/><\/p>\n<h2>Cr\u00e9ation du gMSA :<\/h2>\n<p>La cr\u00e9ation du gMSA se fait avec la commande PowerShell &#8220;New-ADServiceAccount&#8221;. Elle n&#8217;est pas possible par l&#8217;interface graphique &#8220;Active Directory Users and Computers&#8221;.<\/p>\n<pre class=\"brush: plain; title: ; notranslate\" title=\"\"> \r\nNew-ADServiceAccount -Name LAB1_gMSA -DNSHostName LAB1SQL1.LAB1.local -ManagedPasswordIntervalInDays 90 -PrincipalsAllowedToRetrieveManagedPassword LAB1_SQL_Group -ServicePrincipalNames MSSQLSvc\/LAB1SQL1.lab1.local, MSSQLSvc\/LAB1SQL1.lab1.local:1433, MSSQLSvc\/LAB1_LSTN.lab1.local, MSSQLSvc\/LAB1_LSTN.lab1.local:1434 -Enabled $true\r\n<\/pre>\n<p>On aura donc un groupe de disponibilit\u00e9 avec les param\u00e8tres suivants:<\/p>\n<ul>\n<li>Son nom sera LAB1_gMSA<\/li>\n<li>La rotation automatique des mots de passe du compte aura lieu tous les 90 jours (par d\u00e9faut 30)<\/li>\n<li>La liste des machines autoris\u00e9es \u00e0 utiliser le gMSA se trouve dans le groupe LAB1_SQL_Group<\/li>\n<li>Les SPN cr\u00e9\u00e9s seront : MSSQLSvc\/LAB1SQL1.lab1.local, MSSQLSvc\/LAB1SQL1.lab1.local:1433, MSSQLSvc\/LAB1_LSTN.lab1.local et MSSQLSvc\/LAB1_LSTN.lab1.local:1434<\/li>\n<li>Il sera actif d\u00e8s sa cr\u00e9ation<\/li>\n<\/ul>\n<p>On peut d\u00e9sormais le voir dans la console &#8220;Active Directory Users and Computers&#8221; :<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-10387\" src=\"https:\/\/blog.capdata.fr\/wp-content\/uploads\/2023\/11\/gMSA-300x100.png\" alt=\"\" width=\"711\" height=\"237\" srcset=\"https:\/\/blog.capdata.fr\/wp-content\/uploads\/2023\/11\/gMSA-300x100.png 300w, https:\/\/blog.capdata.fr\/wp-content\/uploads\/2023\/11\/gMSA-768x257.png 768w, https:\/\/blog.capdata.fr\/wp-content\/uploads\/2023\/11\/gMSA.png 832w\" sizes=\"auto, (max-width: 711px) 100vw, 711px\" \/><\/p>\n<h2>D\u00e9ploiement du gMSA sur les machines SQL :<\/h2>\n<p>Une fois compte cr\u00e9\u00e9, il faut donc le d\u00e9ployer sur les machines SQL. On va se connecter en PowerShell sur les machines SQL et utiliser la commande &#8220;Install-ADServiceAccount&#8221;. Pour rappel, il faut avoir le composant Remote Management pour pouvoir ex\u00e9cuter cette commande. Si jamais vous ne l&#8217;avez pas, vous pouvez le d\u00e9ployer rapidement avec la commande PowerShell<\/p>\n<pre class=\"brush: plain; title: ; notranslate\" title=\"\">\r\nAdd-WindowsFeature RSAT-AD-PowerShell\r\n<\/pre>\n<p>Apr\u00e8s on peut donc activer notre compte LAB1_gMSA :<\/p>\n<pre class=\"brush: plain; title: ; notranslate\" title=\"\">\r\nInstall-ADServiceAccount -Identity LAB1_gMSA\r\n<\/pre>\n<p>Apr\u00e8s avoir r\u00e9alis\u00e9 \u00e7a sur nos deux machines, on peut les sp\u00e9cifier dans notre configuration SQL Server.<\/p>\n<h2>Configuration du gMSA dans SQL Server :<\/h2>\n<p>Dans la console &#8220;SQL Server Configuration Manager&#8221;, dans la section &#8220;SQL Server Services&#8221;, on doit aller dans l&#8217;onglet &#8220;Log On&#8221; des propri\u00e9t\u00e9s du service SQL Server (et de son agent \u00e9ventuellement).<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-10388\" src=\"https:\/\/blog.capdata.fr\/wp-content\/uploads\/2023\/11\/service_account-300x231.png\" alt=\"\" width=\"668\" height=\"514\" srcset=\"https:\/\/blog.capdata.fr\/wp-content\/uploads\/2023\/11\/service_account-300x231.png 300w, https:\/\/blog.capdata.fr\/wp-content\/uploads\/2023\/11\/service_account-768x592.png 768w, https:\/\/blog.capdata.fr\/wp-content\/uploads\/2023\/11\/service_account.png 956w\" sizes=\"auto, (max-width: 668px) 100vw, 668px\" \/><\/p>\n<p>Comme un objet ordinateur, un gMSA s&#8217;\u00e9crit avec un $ \u00e0 la fin.<\/p>\n<p>Dans SQL Server, on n&#8217;a plus qu&#8217;\u00e0 lui donner les privil\u00e8ges suffisants :<\/p>\n<pre class=\"brush: plain; title: ; notranslate\" title=\"\">\r\nCREATE LOGIN [LAB1\\LAB1_gMSA$] FROM WINDOWS ; \r\nGRANT CONNECT ON ENDPOINT::Hadr_endpoint TO [LAB1\\LAB1_gMSA$] ;\r\nALTER SERVER ROLE [sysadmin] ADD MEMBER [LAB1\\LAB1_gMSA$]\r\nGO\r\n<\/pre>\n<p>Si on regarde dans les logs, on verra d\u00e9sormais les lignes suivantes :<\/p>\n<pre class=\"brush: plain; title: ; notranslate\" title=\"\">\r\nThe service account is 'LAB1\\LAB1_gMSA$'. This is an informational message; no user action is required.\r\n[...]\r\nThe SQL Server Network Interface library successfully registered the Service Principal Name (SPN) [ MSSQLSvc\/LAB1SQL1.lab1.local ] for the SQL Server service.\r\nThe SQL Server Network Interface library successfully registered the Service Principal Name (SPN) [ MSSQLSvc\/LAB1SQL1.lab1.local:1433 ] for the SQL Server service.\r\n<\/pre>\n<p>Ca y est ! vous avez configur\u00e9 le gMSA de votre SQL Server. Mais vous pouvez (devriez ?) utiliser \u00e9galement \u00e7a pour vos applications qui utilisent un compte de service sp\u00e9cifique.<\/p>\n<a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-twitter nolightbox\" data-provider=\"twitter\" target=\"_blank\" rel=\"nofollow\" title=\"Share on Twitter\" href=\"https:\/\/twitter.com\/intent\/tweet?url=https%3A%2F%2Fblog.capdata.fr%2Findex.php%2Fwp-json%2Fwp%2Fv2%2Fposts%2F10382&#038;text=Article%20sur%20le%20blog%20de%20la%20Capdata%20Tech%20Team%20%3A%20\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img loading=\"lazy\" decoding=\"async\" alt=\"twitter\" title=\"Share on Twitter\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none;box-shadow: none\" src=\"https:\/\/blog.capdata.fr\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/twitter.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-linkedin nolightbox\" data-provider=\"linkedin\" target=\"_blank\" rel=\"nofollow\" title=\"Share on Linkedin\" href=\"https:\/\/www.linkedin.com\/shareArticle?mini=true&#038;url=https%3A%2F%2Fblog.capdata.fr%2Findex.php%2Fwp-json%2Fwp%2Fv2%2Fposts%2F10382&#038;title=Les%20Managed%20Service%20Account%20%28MSA%20et%20gMSA%29%20%3A%20se%20simplifier%20la%20vie%20pour%20g%C3%A9rer%20ses%20comptes%20de%20service%20SQL%20Server\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img loading=\"lazy\" decoding=\"async\" alt=\"linkedin\" title=\"Share on Linkedin\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none;box-shadow: none\" src=\"https:\/\/blog.capdata.fr\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/linkedin.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-mail nolightbox\" data-provider=\"mail\" rel=\"nofollow\" title=\"Share by email\" href=\"mailto:?subject=Les%20Managed%20Service%20Account%20%28MSA%20et%20gMSA%29%20%3A%20se%20simplifier%20la%20vie%20pour%20g%C3%A9rer%20ses%20comptes%20de%20service%20SQL%20Server&#038;body=Article%20sur%20le%20blog%20de%20la%20Capdata%20Tech%20Team%20%3A%20:%20https%3A%2F%2Fblog.capdata.fr%2Findex.php%2Fwp-json%2Fwp%2Fv2%2Fposts%2F10382\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px\"><img loading=\"lazy\" decoding=\"async\" alt=\"mail\" title=\"Share by email\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none;box-shadow: none\" src=\"https:\/\/blog.capdata.fr\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/mail.png\" \/><\/a>","protected":false},"excerpt":{"rendered":"<p>Pour faire tourner son service SQL Server sous Windows, il y a diff\u00e9rentes \u00e9coles. Certains veulent un compte de service cr\u00e9\u00e9 dans l&#8217;Active Directory, afin d&#8217;y appliquer des GPO et bien les identifier avec un nom explicite. D&#8217;autres pr\u00e9f\u00e8rent garder&hellip; <a href=\"https:\/\/blog.capdata.fr\/index.php\/les-managed-service-account-msa-et-gmsa-se-simplifier-la-vie-pour-gerer-ses-comptes-de-service-sql-server\/\" class=\"more-link\">Continuer la lecture <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":10391,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[173,5],"tags":[473,470,472,474,469,471],"class_list":["post-10382","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-operating-system","category-sqlserver","tag-gmsa","tag-managed-service-account","tag-msa","tag-powershell","tag-sql-server","tag-virtual-service-account"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v20.8 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Les Managed Service Account (MSA et gMSA) : se simplifier la vie pour g\u00e9rer ses comptes de service SQL Server - Capdata TECH BLOG<\/title>\n<meta name=\"description\" content=\"Comment utiliser les managed service account avec SQL Server\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.capdata.fr\/index.php\/les-managed-service-account-msa-et-gmsa-se-simplifier-la-vie-pour-gerer-ses-comptes-de-service-sql-server\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Les Managed Service Account (MSA et gMSA) : se simplifier la vie pour g\u00e9rer ses comptes de service SQL Server - Capdata TECH BLOG\" \/>\n<meta property=\"og:description\" content=\"Comment utiliser les managed service account avec SQL Server\" \/>\n<meta property=\"og:url\" content=\"https:\/\/blog.capdata.fr\/index.php\/les-managed-service-account-msa-et-gmsa-se-simplifier-la-vie-pour-gerer-ses-comptes-de-service-sql-server\/\" \/>\n<meta property=\"og:site_name\" content=\"Capdata TECH BLOG\" \/>\n<meta property=\"article:published_time\" content=\"2023-11-30T09:56:30+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-12-13T09:53:06+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/blog.capdata.fr\/wp-content\/uploads\/2023\/11\/gMSA1.png\" \/>\n\t<meta property=\"og:image:width\" content=\"486\" \/>\n\t<meta property=\"og:image:height\" content=\"413\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Capdata team\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u00c9crit par\" \/>\n\t<meta name=\"twitter:data1\" content=\"Capdata team\" \/>\n\t<meta name=\"twitter:label2\" content=\"Dur\u00e9e de lecture estim\u00e9e\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/blog.capdata.fr\/index.php\/les-managed-service-account-msa-et-gmsa-se-simplifier-la-vie-pour-gerer-ses-comptes-de-service-sql-server\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/blog.capdata.fr\/index.php\/les-managed-service-account-msa-et-gmsa-se-simplifier-la-vie-pour-gerer-ses-comptes-de-service-sql-server\/\"},\"author\":{\"name\":\"Capdata team\",\"@id\":\"https:\/\/blog.capdata.fr\/#\/schema\/person\/bfd9395c8ba4fa125792a543377035e9\"},\"headline\":\"Les Managed Service Account (MSA et gMSA) : se simplifier la vie pour g\u00e9rer ses comptes de service SQL Server\",\"datePublished\":\"2023-11-30T09:56:30+00:00\",\"dateModified\":\"2023-12-13T09:53:06+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/blog.capdata.fr\/index.php\/les-managed-service-account-msa-et-gmsa-se-simplifier-la-vie-pour-gerer-ses-comptes-de-service-sql-server\/\"},\"wordCount\":1146,\"commentCount\":1,\"publisher\":{\"@id\":\"https:\/\/blog.capdata.fr\/#organization\"},\"keywords\":[\"gMSA\",\"Managed Service Account\",\"MSA\",\"PowerShell\",\"SQL Server\",\"Virtual Service Account\"],\"articleSection\":[\"Operating System\",\"SQL Server\"],\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/blog.capdata.fr\/index.php\/les-managed-service-account-msa-et-gmsa-se-simplifier-la-vie-pour-gerer-ses-comptes-de-service-sql-server\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.capdata.fr\/index.php\/les-managed-service-account-msa-et-gmsa-se-simplifier-la-vie-pour-gerer-ses-comptes-de-service-sql-server\/\",\"url\":\"https:\/\/blog.capdata.fr\/index.php\/les-managed-service-account-msa-et-gmsa-se-simplifier-la-vie-pour-gerer-ses-comptes-de-service-sql-server\/\",\"name\":\"Les Managed Service Account (MSA et gMSA) : se simplifier la vie pour g\u00e9rer ses comptes de service SQL Server - Capdata TECH BLOG\",\"isPartOf\":{\"@id\":\"https:\/\/blog.capdata.fr\/#website\"},\"datePublished\":\"2023-11-30T09:56:30+00:00\",\"dateModified\":\"2023-12-13T09:53:06+00:00\",\"description\":\"Comment utiliser les managed service account avec SQL Server\",\"breadcrumb\":{\"@id\":\"https:\/\/blog.capdata.fr\/index.php\/les-managed-service-account-msa-et-gmsa-se-simplifier-la-vie-pour-gerer-ses-comptes-de-service-sql-server\/#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.capdata.fr\/index.php\/les-managed-service-account-msa-et-gmsa-se-simplifier-la-vie-pour-gerer-ses-comptes-de-service-sql-server\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/blog.capdata.fr\/index.php\/les-managed-service-account-msa-et-gmsa-se-simplifier-la-vie-pour-gerer-ses-comptes-de-service-sql-server\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\/\/blog.capdata.fr\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Les Managed Service Account (MSA et gMSA) : se simplifier la vie pour g\u00e9rer ses comptes de service SQL Server\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/blog.capdata.fr\/#website\",\"url\":\"https:\/\/blog.capdata.fr\/\",\"name\":\"Capdata TECH BLOG\",\"description\":\"Le blog technique sur les bases de donn\u00e9es de CAP DATA Consulting\",\"publisher\":{\"@id\":\"https:\/\/blog.capdata.fr\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/blog.capdata.fr\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"fr-FR\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/blog.capdata.fr\/#organization\",\"name\":\"Capdata TECH BLOG\",\"url\":\"https:\/\/blog.capdata.fr\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\/\/blog.capdata.fr\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/blog.capdata.fr\/wp-content\/uploads\/2023\/01\/logo_capdata.webp\",\"contentUrl\":\"https:\/\/blog.capdata.fr\/wp-content\/uploads\/2023\/01\/logo_capdata.webp\",\"width\":800,\"height\":254,\"caption\":\"Capdata TECH BLOG\"},\"image\":{\"@id\":\"https:\/\/blog.capdata.fr\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.linkedin.com\/company\/cap-data-consulting\/mycompany\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/blog.capdata.fr\/#\/schema\/person\/bfd9395c8ba4fa125792a543377035e9\",\"name\":\"Capdata team\",\"sameAs\":[\"https:\/\/www.capdata.fr\"],\"url\":\"https:\/\/blog.capdata.fr\/index.php\/author\/admin\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Les Managed Service Account (MSA et gMSA) : se simplifier la vie pour g\u00e9rer ses comptes de service SQL Server - Capdata TECH BLOG","description":"Comment utiliser les managed service account avec SQL Server","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.capdata.fr\/index.php\/les-managed-service-account-msa-et-gmsa-se-simplifier-la-vie-pour-gerer-ses-comptes-de-service-sql-server\/","og_locale":"fr_FR","og_type":"article","og_title":"Les Managed Service Account (MSA et gMSA) : se simplifier la vie pour g\u00e9rer ses comptes de service SQL Server - Capdata TECH BLOG","og_description":"Comment utiliser les managed service account avec SQL Server","og_url":"https:\/\/blog.capdata.fr\/index.php\/les-managed-service-account-msa-et-gmsa-se-simplifier-la-vie-pour-gerer-ses-comptes-de-service-sql-server\/","og_site_name":"Capdata TECH BLOG","article_published_time":"2023-11-30T09:56:30+00:00","article_modified_time":"2023-12-13T09:53:06+00:00","og_image":[{"width":486,"height":413,"url":"https:\/\/blog.capdata.fr\/wp-content\/uploads\/2023\/11\/gMSA1.png","type":"image\/png"}],"author":"Capdata team","twitter_card":"summary_large_image","twitter_misc":{"\u00c9crit par":"Capdata team","Dur\u00e9e de lecture estim\u00e9e":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/blog.capdata.fr\/index.php\/les-managed-service-account-msa-et-gmsa-se-simplifier-la-vie-pour-gerer-ses-comptes-de-service-sql-server\/#article","isPartOf":{"@id":"https:\/\/blog.capdata.fr\/index.php\/les-managed-service-account-msa-et-gmsa-se-simplifier-la-vie-pour-gerer-ses-comptes-de-service-sql-server\/"},"author":{"name":"Capdata team","@id":"https:\/\/blog.capdata.fr\/#\/schema\/person\/bfd9395c8ba4fa125792a543377035e9"},"headline":"Les Managed Service Account (MSA et gMSA) : se simplifier la vie pour g\u00e9rer ses comptes de service SQL Server","datePublished":"2023-11-30T09:56:30+00:00","dateModified":"2023-12-13T09:53:06+00:00","mainEntityOfPage":{"@id":"https:\/\/blog.capdata.fr\/index.php\/les-managed-service-account-msa-et-gmsa-se-simplifier-la-vie-pour-gerer-ses-comptes-de-service-sql-server\/"},"wordCount":1146,"commentCount":1,"publisher":{"@id":"https:\/\/blog.capdata.fr\/#organization"},"keywords":["gMSA","Managed Service Account","MSA","PowerShell","SQL Server","Virtual Service Account"],"articleSection":["Operating System","SQL Server"],"inLanguage":"fr-FR","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/blog.capdata.fr\/index.php\/les-managed-service-account-msa-et-gmsa-se-simplifier-la-vie-pour-gerer-ses-comptes-de-service-sql-server\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/blog.capdata.fr\/index.php\/les-managed-service-account-msa-et-gmsa-se-simplifier-la-vie-pour-gerer-ses-comptes-de-service-sql-server\/","url":"https:\/\/blog.capdata.fr\/index.php\/les-managed-service-account-msa-et-gmsa-se-simplifier-la-vie-pour-gerer-ses-comptes-de-service-sql-server\/","name":"Les Managed Service Account (MSA et gMSA) : se simplifier la vie pour g\u00e9rer ses comptes de service SQL Server - Capdata TECH BLOG","isPartOf":{"@id":"https:\/\/blog.capdata.fr\/#website"},"datePublished":"2023-11-30T09:56:30+00:00","dateModified":"2023-12-13T09:53:06+00:00","description":"Comment utiliser les managed service account avec SQL Server","breadcrumb":{"@id":"https:\/\/blog.capdata.fr\/index.php\/les-managed-service-account-msa-et-gmsa-se-simplifier-la-vie-pour-gerer-ses-comptes-de-service-sql-server\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.capdata.fr\/index.php\/les-managed-service-account-msa-et-gmsa-se-simplifier-la-vie-pour-gerer-ses-comptes-de-service-sql-server\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/blog.capdata.fr\/index.php\/les-managed-service-account-msa-et-gmsa-se-simplifier-la-vie-pour-gerer-ses-comptes-de-service-sql-server\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/blog.capdata.fr\/"},{"@type":"ListItem","position":2,"name":"Les Managed Service Account (MSA et gMSA) : se simplifier la vie pour g\u00e9rer ses comptes de service SQL Server"}]},{"@type":"WebSite","@id":"https:\/\/blog.capdata.fr\/#website","url":"https:\/\/blog.capdata.fr\/","name":"Capdata TECH BLOG","description":"Le blog technique sur les bases de donn\u00e9es de CAP DATA Consulting","publisher":{"@id":"https:\/\/blog.capdata.fr\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.capdata.fr\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"fr-FR"},{"@type":"Organization","@id":"https:\/\/blog.capdata.fr\/#organization","name":"Capdata TECH BLOG","url":"https:\/\/blog.capdata.fr\/","logo":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/blog.capdata.fr\/#\/schema\/logo\/image\/","url":"https:\/\/blog.capdata.fr\/wp-content\/uploads\/2023\/01\/logo_capdata.webp","contentUrl":"https:\/\/blog.capdata.fr\/wp-content\/uploads\/2023\/01\/logo_capdata.webp","width":800,"height":254,"caption":"Capdata TECH BLOG"},"image":{"@id":"https:\/\/blog.capdata.fr\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/cap-data-consulting\/mycompany\/"]},{"@type":"Person","@id":"https:\/\/blog.capdata.fr\/#\/schema\/person\/bfd9395c8ba4fa125792a543377035e9","name":"Capdata team","sameAs":["https:\/\/www.capdata.fr"],"url":"https:\/\/blog.capdata.fr\/index.php\/author\/admin\/"}]}},"_links":{"self":[{"href":"https:\/\/blog.capdata.fr\/index.php\/wp-json\/wp\/v2\/posts\/10382","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.capdata.fr\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.capdata.fr\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.capdata.fr\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.capdata.fr\/index.php\/wp-json\/wp\/v2\/comments?post=10382"}],"version-history":[{"count":8,"href":"https:\/\/blog.capdata.fr\/index.php\/wp-json\/wp\/v2\/posts\/10382\/revisions"}],"predecessor-version":[{"id":10401,"href":"https:\/\/blog.capdata.fr\/index.php\/wp-json\/wp\/v2\/posts\/10382\/revisions\/10401"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.capdata.fr\/index.php\/wp-json\/wp\/v2\/media\/10391"}],"wp:attachment":[{"href":"https:\/\/blog.capdata.fr\/index.php\/wp-json\/wp\/v2\/media?parent=10382"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.capdata.fr\/index.php\/wp-json\/wp\/v2\/categories?post=10382"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.capdata.fr\/index.php\/wp-json\/wp\/v2\/tags?post=10382"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}