Microsoft Defender for Identity
Identity protection

Manage action accounts in Microsoft Defender for Identity

In brief

The article title, wording, and screenshot descriptions were updated. It now explicitly introduces configuring a dedicated gMSA action account and clarifies the security rationale for separating action and Directory Service accounts.

What Defender admins need to know

Administrators configuring Defender for Identity action accounts have clearer setup guidance and more descriptive screenshots.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Configure Microsoft Defender for Identity action accounts

Defender for Identity allows you to take remediation actions targeting on-premises Active Directory accounts in the event that an identity is compromised. To take these actions, Microsoft Defender for Identity needs to have the required permissions to do so. This action account configuration is separate from the Directory Service Account, which is for reading AD data.

Best practices for action accounts

We recommend that you avoid using the same gMSA account you configured for Defender for Identity managed actions on servers other than domain controllers. If you use the same account on another server and that server is compromised, an attacker could retrieve the password for the account and gain the ability to change passwords and disable accounts.

We also recommend that you avoid using the same account as both the Directory Service account and the Manage Action account. Separating these roles is important because the Directory Service account requires only read-only permissions to Active Directory, and the Manage Action account needs write permissions on user accounts.

If you have multiple forests, your gMSA managed action account must be trusted in all of your forests, or create a separate one for each forest. For more information, see Microsoft Defender for Identity multi-forest support.

Create and configure a specific action account

To create and configure a dedicated gMSA action account, perform the following steps:

  1. Create a new gMSA account. For more information, see Getting started with Group Managed Service Accounts.

  2. Assign the Log on as a service right to the gMSA account on each domain controller running the Defender for Identity sensor.

    1. Right-click the relevant domain or OU and select Properties. For example:

      Screenshot of the domain Properties dialog open to the Security tab before adding gMSA permissions.

    2. Go the Security tab and select Advanced. For example:

      Screenshot of Advanced Security Settings where a new permission entry can be added for the gMSA account.

    3. Select Add > Select a principal. For example:

      Screenshot of the Permission Entry dialog with the gMSA account selected as the security principal.

    4. Make sure Service accounts is marked in Object types. For example:

      Screenshot of Object Types with Service Accounts enabled so the gMSA account can be found.

    5. In the Enter the object name to select box, enter the name of the gMSA account and select OK.

    6. In the Applies to field, select Descendant User objects, leave the existing settings, and add the permissions and properties shown in the following example:

      Screenshot of the Permission Entry dialog showing Descendant User objects scope with reset password and account control permissions.

      Required permissions include: