cancel
Showing results for 
Search instead for 
Did you mean: 

BE with Group Managed Service Accounts

bmartinsiten
Level 1

Hello everyone,

I was trying to setup Backup Exec 16 to work with Microsoft's Group Managed Service Accounts but I am not being successful.

Always getting error message "Unable to authenticate with the OpenStorage device.  Ensure that the logon account that is required to access the device has the correct credentials."

Does anyone here got it working, or knows if they are supported at all?

Thanks!

2 REPLIES 2

DevG
Level 4
Employee Accredited Certified

Hello,

Not aware of any article explicitly stating Group Managed Service Accounts cannot be used with BE 16. However, the recommendation is to use a dedicated account for BE. Since usage of gMSA is restricted to only those computers specified in the security descriptor (msDS-GroupMSAMembership), it may give issues backing up remote servers using BE and not part of the security descriptor.
Secondly, assuming if the gMSA account is used in BE, it would become the default System Logon account and Backup Exec Service Account in BE. So, whenever the password of gMSA is changed (as per password behaviour\management in gMSA), it needs to be ensured that the same is updated in BE for the Logon account as well as all BE services using this account to avoid all job failures due to authentication issue.
Coming to the error message "Unable to authenticate with the OpenStorage device...."  posted in the query, it sounds like the same is coming during configuring storage in BE. Can you confirm if this error comes when attempting to configure a storage in BE or during BE installation itself?

Stephen_Kent
Level 4
Employee

I just wanted to clarify that the error your getting is only saying that Backup Exec is unable to authenticate to the NAS/OST storage device that you're backing up to. Everything else might be fine as far as permissions/credentials go, but the account you're using doesn't have access to the storage...and I'm assuming that device uses it's own authintication outside of Active Directory.