- A group Managed Service Account (gMSA) provides automatic password management, SPN management and delegated administration for service accounts across multiple servers.
- Use of gMSA is recommended to protect from Kerberoast type attacks!
- A 256 bytes random password is generated and is rotated every 30 days.
- When an authorized user reads the attribute 'msds-ManagedPassword’the gMSA password is computed.
- Only explicitly specified principals can read the password blob. Even the Domain Admins can't read it by default.
- A gMSA has object class 'msDS-GroupManagedServiceAccount'. This can be used to find the accounts.

Get-DomainObject -LDAPFilter '(objectClass=msDS-GroupManagedServiceAccount)'

Get-ADServiceAccount -Filter *

Get-ADServiceAccount -Identity jumpone -Properties * | select PrincipalsAllowedToRetrieveManagedPassword

- The attribute 'msDS-ManagedPassword' stores the password blob in binary form of
MSDS-MANAGEDPASSWORD_BLOB.
- Once we have compromised a principal that can read the blob. Use ADModule to read and DSInternals to compute NTLM hash: