To The Lab: gMSA for ServiceNow Discovery - a comprehensive summary
Einar & Partners
·
Mar 02, 2022
·
video
group managed service accounts often referred to as gmsa is a windows domain feature that has been around since the introduction of windows server 2016. it can even be leveraged on windows server 2012. now with the san diego release right around the corner gmsa will be officially supported by servicenow's agentless discovery solution now if that didn't make you jump up enjoy then maybe stick around two more minutes and let me explain you why this is a game changer for any future security discussions and if you did jump up enjoy well then use the timestamps down below to get into the technical juicy bits [Music] let us make a long story short a managed service account is a domain account that delegates things such as password management to the windows operating system and the domain it belongs to in other words you can now run windows discovery without sharing or storing credentials in the servicenow instance no person will ever have to handle managed service account credentials this is huge because apart from solving one of the biggest security concerns with the servicenow agentless discovery solution we have now other features that makes this entire setup even more interesting like strong passwords gmsa uses 240 byte randomly generated complex passwords and cycling these passwords regularly shifting the password management to the operating system means that passwords can be automatically changed every so often if we now look at our security maturity model from one the least complex to four the most complex to build and maintain gmsa ranks right around level 2 with gea quick side note here we have not tested it yet but nothing is technically preventing gea to work together with gmsa we will find out so stay tuned in any of our social media channels now back to the topic at hand of course is a fair amount of additional work and prerequisites involved so without further delay let's get into the technical details let's start with the technical concept picture an on-premise windows domain in order for it to work we need to have at least one domain controller typically a windows server who hosts the domain with its many features for all the joined devices now for any of these domain joined windows servers to use gmsa we first need to create a domain security group with all servers we want to manage as its members including the mid server next we can go ahead and create a managed service account and allow the members of the security group to retrieve managed passwords hence group managed service accounts all that remains to do now is to install these managed service accounts on the windows servers we want to use them on meaning the servers that have been added to the security group in other words we are allowing the operating system of these servers to use encrypted kerberos service tickets to authenticate throughout the domain with this setup the mid server agent service can now be started with the managed service account as the account password is managed by the operating system and controlled by the domain we can now initiate a discovery request without ever knowing the encrypted password that was used now that we know about the technical concept let's have a look at our lab we have followed the instructions documented by mark rodonek on his community article as well as the servicenow docs it's rather straightforward never the less i have a few additional points that i would like to clarify for you so let's get started with the kds root key well domain controllers require a kds root key to begin generating passwords for managed service accounts the root key only needs to be created once so if there is already a root key in your domain you don't need to follow this step go to the next one which would be security groups so a domain security group contains as members all the windows servers that we want to manage including the mid server here it is important to consider the size and scope of your discovery implementation maybe you are in a lab it's not that important but if you're planning for production and you have 10 000 servers to manage maybe one security group and one managed service account is a bit risky so consider that okay we have now our security group we are done going ahead and we are creating the managed service account and upon creating a managed service account the security group that will be allowed to retrieve the managed passwords needs to be specified in the principles allowed to retrieve managed password attribute this is done during the creation with the powershell command good now we have created the managed service account we have the security group maybe you need to restart your servers or force a gpo update but once available in the domain while the managed service account needs to be installed on the servers and those are the servers that are in your security group additionally the servers also need to grant local administrator rights to this managed service account it is also very important to mention that on the servers you need to install the remote server administration tools these are usually only active by default on domain controllers maybe your administrators have already pushed them but you absolutely need them in order to run the installation command for the managed service account last but not least we also have the mid server configuration the mid-server agent service needs to run with the managed service account as already mentioned the windows service logon account needs to be the managed service account followed with the dollar suffix the dollar indicates that the password is managed by the operating system on the other hand in the servicenow instance there would be a windows credential entry with use mid server service account checked as true you can already see now that only one managed service account can be used per running mid server agent service as a list of credentials is not applicable it does not exist so let's have a quick look over the setup then let's deep dive into it first of all i would like you to note the credentials that i have here in my instance i basically just have one credential that is applicable i left the others just for show and you will see that in this credential we have no username no password we have just used mid server service account checked as true then switching over to the discovery schedule i can see that i'm using this mid server so the mid server with the hostname only mid hm and the ip address 1005. you need that in a sec when i switch to the servers and you can see that i'm going to scan 1006 so our target server where i want to run discovery against let's launch this right away good while discovery is running let's head over to the servers first of all i would like you to show you my mid server the only mid hn as you can see 1005 and you can see here in my active directory console i have the managed service accounts the managed service accounts here you cannot do much with them they are mostly controlled with powershell commands you can also see that i have a security group created and if i open it you can see that its members are well this mid server as well as the windows server that i would like to discover please also note that when i look at this mid server i have a few running agents mid-server agents this one that i'm showing here is the one responsible for our gmsa lab and you can see that it runs with the gms a03 dollar account so that is the account that we've created that you can see also in the console and that we are going to use during discovery heading back into our instance we should see that the discovery run has completed yes indeed we have one device updated successfully so now heading to the device that was discovered i can see within the event viewer logs i have created a filter to make this easier but basically i can see in the event viewer as some security logon events and here i can see that i had a successful gun of the account gmsa03 dollar meaning that our discovery with the gmsa setup has actually worked we have already arrived at the end of our video there is not much to add except that we've run this entire setup in the rome release even though the official support is only mentioned as of san diego that said i really hope you liked this video if you did hit like and subscribe consider supporting us we are putting a lot of effort into this in our free time right next to our customer projects you can also find us on other social medias such as linkedin and we do have our own research website where we are regularly publishing infographics benchmarks articles also this stuff so any support that we can get from you guys would be much appreciated that said thank you so much for your attention and see you next time [Music] you
https://www.youtube.com/watch?v=grmScCee1NE