Unable to create gMSA with DNSHostName error PermissionDenied, UnauthorizedAccessException

Jack Turner 16 Reputation points
2021-12-20T15:50:19.517+00:00

I have a new install of Windows Server 2019 on a VMware VM. There are two domain controllers, DC-01 and DC-02. I'm trying to create gMSA to start SQL Server services. I run the command:

Add-KDSRootKey -EffectiveTime ((get-date).addhours(-10))

This works correctly. I use AD Administration Tool to create a group SQLServers and add the SQL-01 server to this group, then I rebooted SQL-01.

I try to create the gMSA by running, inside an Administrator Power Shell:

New-ADServiceAccount SQLsvc -ServicePrincipalNames "MSSQLServer/SQL-01.xxx.com" -PrincipalsAllowedToRetrieveManagedPassword "SQLServers"
(NOTE: I tried both SQLsvc and SQLsvc$ and both give the same error) (and replacing xxx.com with the actual domain name from AD)

I get prompted with the following:

cmdlet New-ADServiceAccount at command pipeline position 1
Supply values for the following parameters:
DNSHostName: SQLsvc.xxx.com

I get the following error:

New-ADServiceAccount : Access is denied
At line:1 char:1

  • New-ADServiceAccount SQLsvc$ -ServicePrincipalNames "MSSQLServer/SQL ...
  • ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  • CategoryInfo : PermissionDenied: (CN=SQLsvc$,CN=M...C=xxx,DC=com:String) [New-AD
    ServiceAccount], UnauthorizedAccessException
  • FullyQualifiedErrorId : ActiveDirectoryCmdlet:System.UnauthorizedAccessException,Microsoft.A
    ctiveDirectory.Management.Commands.NewADServiceAccount

The Windows System error log shows the following, which I think is related, but perhaps not:

The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
and APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
to the user STES\TurnerJ.DA SID (S-1-5-21-846075100-2544379057-207111340-1110) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

It doesn't matter if I run using the Administrator account, or my Domain Admin account. Whenever I try to include the DNS parameter, I get this error. I'm running it from the DC-01 domain controller using an elevated PowerShell window.

Does anyone have any idea how to overcome this problem? Is there any other information I should provide? I just created the AD servers, so I don't know what can be wrong.

Thanks,
Jack

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Server | User experience | Other

Locked Question. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

1 answer

Sort by: Most helpful
  1. Leonardo Bazterrica 0 Reputation points
    2026-09-25T18:47:27.2366667+00:00

    It might be a little late to respond, but in case this happens to anyone else:

    1. make sure you have AD permissions.

    2. Launch PowerShell as an administrator, EVEN IF YOU'RE LOGGED IN WITH AN ADMIN ACCOUNT.

    Was this answer helpful?

    0 comments No comments