Documentation forSolarWinds Observability SaaS

Configure gMSA accounts for Windows polling

When you poll nodes using WinRM with Kerberos authentication, you can use group managed service accounts (gMSAs).

Use the following links to configure your environment:

Requirements

  • You can use gMSA accounts for polling only when using WinRM with Kerberos authentication.

  • Specify gMSA credentials as <username>$@<domain> or <domain>\<username>$, using the fully qualified domain name (FQDN).

  • gMSA authentication in SolarWinds Observability SaaS requires Network Collector version 2025.1 or later.

  • Configure your gMSA account with required permissions on both the Network Collector machine and the polled server. Administrator privileges are supported, but not required.

    To follow the principle of least privilege, SolarWinds recommends setting up and using a non-admin configuration whenever possible. For more information, see Non-Admin User in SolarWinds Platform documentation.

Configure gMSA deployment

Before you can poll with a gMSA account, configure the account itself: create the service account, configure DNS (forward and reverse), and configure Kerberos delegation.

For details, see Get started with Group Managed Service Accounts in Microsoft documentation.

Configure polling servers using gMSA accounts

When you have completed the configuration, specify that you want to poll servers using gMSA when adding the server. Just select the Use a group Managed Service Account (gMSA) box and complete the Add Host wizard.