Cannot install managed service account

Install-ADServiceAccount Error Message

An unspecified error has occurred

The installation of a group managed services account fails!

If the following error messages appear,

Test failed for managed service account

then it is very likely that the server hardening policy on the domain controller was configured as follows. Only the use of Kerberos in the grades AES128 and AES256 is permitted.

gMSA AES128 AES256 Kerberos

So the “Supported Encryption Type” of the Managed Services Account has to be adjusted accordingly.

Supported Encryption Type Value 24

gMSA Cannot Install Service Account

