Best For You Organics must move a service that runs as an ordinary domain user account to a delegated Managed Service Account. All the hosts and domain controllers involved run Windows Server 2025. Which sequence should you use?
- A.
Create a group managed service account first and convert it to a dMSA with Set-ADServiceAccount.
- B.
Install the dMSA on the host with Install-ADServiceAccount and change the service logon, because no migration is required.
- C.
Create the dMSA, run Start-ADServiceAccountMigration naming the user account as the superseded account, let the service refresh its tickets, then run Complete-ADServiceAccountMigration.
- D.
Create the dMSA, run Complete-ADServiceAccountMigration immediately, and then delete the original user account.
Show answer
Answer: C
A dMSA migration is a two-stage operation: Start-ADServiceAccountMigration links the superseded user account to the dMSA, and Complete-ADServiceAccountMigration finishes the change once tickets have refreshed.
- A. Migration from a gMSA or a standalone managed service account to a dMSA is explicitly not supported.
- B. Without migration the dMSA does not inherit the original account's access and the original password stays enabled.
- C. It follows the documented start, learn, complete sequence that transfers access and then disables the original account.
- D. Completing at once skips the stage in which the dMSA learns the machine identities, and hosts can then fail to authenticate.