GPOADmin service accounts can be configured with the Active Directory setting "Account is sensitive and cannot be delegated". While this is not a documented GPOADmin requirement or recommendation, enabling this setting is generally supported and should not impact normal GPOADmin operations in environments where Kerberos delegation is not required.
During a Microsoft Active Directory Security Risk Assessment Program (RAP), the GPOADmin service account is flagged with the recommendation:
Configure administrative accounts to prevent delegation
Administrators may be advised to enable the following account option:
Account is sensitive and cannot be delegated
This can raise concerns about whether enabling the setting will affect GPOADmin functionality.
The recommendation is a Microsoft security best practice intended to prevent privileged account credentials from being delegated to other systems. This helps reduce the risk of credential theft and lateral movement attacks.
Organizations performing security assessments may identify GPOADmin service accounts as administrative accounts and recommend enabling this setting.
GPOADmin can typically operate with the "Account is sensitive and cannot be delegated" option enabled.
Although this configuration is not specifically documented or required by GPOADmin, based on support experience and product knowledge, enabling the setting should not affect normal GPOADmin functionality provided that:
In most GPOADmin deployments, delegation is not required, making this a reasonable security hardening measure.
Enable "Account is sensitive and cannot be delegated" on the existing GPOADmin service account.
This approach aligns with Microsoft security recommendations while maintaining the current account configuration.
Implement a dedicated Group Managed Service Account (gMSA) with only the permissions required for GPOADmin operations.
Benefits include: