Defender ATP doesnt remove old service account when switched te new account

%3CLINGO-SUB%20id%3D%22lingo-sub-2343351%22%20slang%3D%22en-US%22%3EDefender%20ATP%20doesnt%20remove%20old%20service%20account%20when%20switched%20te%20new%20account%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2343351%22%20slang%3D%22en-US%22%3E%3CP%3EGood%20day%20all%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ELast%20week%20i%20wanted%20to%20setup%20a%20gmsa%20account%20instead%20of%20a%20user%20account%20for%20ATP%20Defender%20for%20identity%20service.%3CBR%20%2F%3EI%20had%20a%20test%20account%20which%20i%20later%20changed%20to%20the%20new%20one.%26nbsp%3B%3CBR%20%2F%3EThe%20new%20gMSA%20account%20works%20fine%20now.%26nbsp%3B%3CBR%20%2F%3EBut%20the%20thing%20is%3A%3C%2FP%3E%3CP%3EI%20have%20removed%20the%20old%20testgmsa%20account%20but%20the%20old%20account%20somehow%20are%20still%20being%20reported%20that%20the%20credentials%20are%20not%20correct.%20The%20issues%20keeps%20popping%20up%20in%20our%20portal.%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22defenderatp.jpg%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F279724i2BC3FE7855833A26%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22defenderatp.jpg%22%20alt%3D%22defenderatp.jpg%22%20%2F%3E%3C%2FSPAN%3E%3CBR%20%2F%3EDoes%20anyone%20have%20seen%20this%20behaviour%3F%20And%20is%20there%20a%20fix%20for%20this%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2343704%22%20slang%3D%22en-US%22%3ERe%3A%20Defender%20ATP%20doesnt%20remove%20old%20service%20account%20when%20switched%20te%20new%20account%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2343704%22%20slang%3D%22en-US%22%3EClose%20the%20alert%2C%20if%20it%20says%20closed%20it's%20OK%2C%20if%20it%20reopens%20let%20me%20know.%3CBR%20%2F%3EWe%20close%20the%20alert%20if%20we%20see%20the%20credentials%20fixed%2C%20but%20in%20this%20case%20you%20removed%20it%20while%20they%20were%20in%20error%2C%20so%20we%20are%20not%20reporting%20it%20fixed%20to%20auto%20close%20this.%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2343727%22%20slang%3D%22en-US%22%3ERe%3A%20Defender%20ATP%20doesnt%20remove%20old%20service%20account%20when%20switched%20te%20new%20account%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2343727%22%20slang%3D%22en-US%22%3EThanks%20for%20your%20quick%20reply!%20unfortunatly%20the%20alert%20immediatly%20re-opens%20when%20i%20close%20the%20alert.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2343758%22%20slang%3D%22en-US%22%3ERe%3A%20Defender%20ATP%20doesnt%20remove%20old%20service%20account%20when%20switched%20te%20new%20account%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2343758%22%20slang%3D%22en-US%22%3Ethis%20account%20is%20no%20longer%20in%20the%20credentials%20list%20in%20the%20MDI%20portal%20%3F%20can%20you%20make%20sure%3F%3CBR%20%2F%3Eare%20all%20sensors%20currently%20reporting%20healthy%20%3F%3CBR%20%2F%3Eis%20it%20possible%20not%20all%20sensors%20can%20pull%20the%20gmsa's%20password%20for%20the%20new%20credentials%20%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2343944%22%20slang%3D%22en-US%22%3ERe%3A%20Defender%20ATP%20doesnt%20remove%20old%20service%20account%20when%20switched%20te%20new%20account%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2343944%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F106935%22%20target%3D%22_blank%22%3E%40Eli%20Ofek%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECorrect.%20All%20sensors%20installed%20and%20confirmed%20as%20%22running%22%20ands%20report%20healthy.%20The%20current%20account%20is%20working.%26nbsp%3B%3C%2FP%3E%3CP%3EI%20did%20a%20test%20just%20to%20switched%20to%20a%20non-existing%20account%20and%20switch%20back%20to%20the%20current%20working%20account.%26nbsp%3B%3C%2FP%3E%3CP%3EAnd%20now%20two%20accounts%20reports%20credential%20failures%2C%20even%20though%20they%20are%20not%20existing%20and%20not%20selected%20as%20account.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20can%20also%20confirm%20that%20all%20dc's%20are%20in%20the%20gmsa%20group%20for%20receiving%20password.%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

Good day all,

 

Last week i wanted to setup a gmsa account instead of a user account for ATP Defender for identity service.
I had a test account which i later changed to the new one. 
The new gMSA account works fine now. 
But the thing is:

I have removed the old testgmsa account but the old account somehow are still being reported that the credentials are not correct. The issues keeps popping up in our portal.defenderatp.jpg
Does anyone have seen this behaviour? And is there a fix for this?

6 Replies
Close the alert, if it says closed it's OK, if it reopens let me know.
We close the alert if we see the credentials fixed, but in this case you removed it while they were in error, so we are not reporting it fixed to auto close this.
Thanks for your quick reply! unfortunatly the alert immediatly re-opens when i close the alert.
this account is no longer in the credentials list in the MDI portal ? can you make sure?
are all sensors currently reporting healthy ?
is it possible not all sensors can pull the gmsa's password for the new credentials ?

@Eli Ofek 

 

Correct. All sensors installed and confirmed as "running" ands report healthy. The current account is working. 

I did a test just to switched to a non-existing account and switch back to the current working account. 

And now two accounts reports credential failures, even though they are not existing and not selected as account. 

 

I can also confirm that all dc's are in the gmsa group for receiving password.

Weird, this seems too challenging for a forum troubleshooting, please open a support case for this one, so the engineer can collect sensor logs and check why the sensors keep using the old credentials.
Oke, i will do that!And thanks anyway for your efforts!
We support Ukraine and condemn war. Push Russian government to act against war. Be brave, vocal and show your support to Ukraine. Follow the latest news HERE