能否通过New-Service命令创建使用gMSA账户的服务?
是否可以用New-Service命令创建使用gMSA账户的服务?
问题描述
尝试用New-Service创建使用gMSA账户的服务时,遇到以下问题:
- 尝试用空密码创建凭据失败,因为
ConvertTo-SecureString不允许空字符串:
$password = ConvertTo-SecureString "" -AsPlainText -Force $credential = New-Object System.Management.Automation.PSCredential ("DOMAIN\dev-user$", $password) New-Service -Name Service -BinaryPathName C:\Service -StartupType Automatic -Credential $credential Start-Service -Name "Service"
- 尝试设置任意密码(如"a")时,收到错误:
New-Service : Service '(Service)' cannot be created due to the following error: The account name is invalid or does not exist, or the password is invalid for the account name specified
已知可以通过Wmi-Object或sc.exe实现,但希望确认是否能通过New-Service完成,排查是否存在操作失误。
解答
无法直接通过New-Service命令创建使用gMSA账户的服务,这不是操作失误,而是命令本身的局限性:
New-Service底层调用Windows的CreateServiceAPI,该API要求必须提供账户密码,但gMSA的密码由Active Directory自动管理,不存在可手动输入的密码;- 无论是传入空密码还是任意自定义密码,都不符合gMSA的认证逻辑,因此会触发错误。
如果必须用PowerShell实现,可改用Get-WmiObject或sc.exe,它们支持指定gMSA账户时无需提供密码。
内容的提问来源于stack exchange,提问作者Max Young
相关产品推荐
相关产品推荐

