Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >
article

KB-6051:Support for MSA (Manage Service Account) Accounts on DirectControl Console

30 December,16 at 11:52 PM

Applies to:
Centrify Zone Provisioning Agent (ZPA) version 5.2.3 and lower on all platforms 

Problem:
When configuring the service account for ZPA, an issue is encountered when attempting to select a managed service account (MSA) that allows you to create an account in AD that is tied to a specific computer. 

When going into a zone to delegate control for this service account, it does not give the option to lookup service account, it only displays 'User/Group/Computer'.  After added the service account in local security settings, console does not display or can find the MS Windows service account.

Cause:
 
ZPA and Access Manager relies on a Microsoft API that does not support selecting an MSA. As a result, when you try to select the MSA object type there is no option for it. 

Resolution:
MSA is now supported for use with ZPA in Suite 2016

 

 

Still have questions? Click here to log a technical support case, or collaborate with your peers in Centrify's Online Community.