What is needed to use a gMSA with the Foreign Forest Agent?
The workflow when using a gMSA with a Foreign Agent is as follows:
This configuration does not give any other foreign agent (or any other account for that matter) the ability to do anything with the gMSA account. The only objects permitted to retrieve the password for the gMSA are those that have been added to the PrincipalsAllowedToRetrieveManagedPasswords attribute.
In this scenario, the gMSA is used by the agent to query for the SCP and then for the Coordinator to validate that the account being used is permitted to connect.