Is the Service Principal Name attribute assigned to the GPOADMIN Service account required for newer versions of the GPO admin tool.
The SPN is required. It is used by Kerberos authentication to associate a service instance with a service login account.
If you were to remove the SPN It wouldn't work at all, as the service authentication wouldn't be able to work. the process is described in the MS document below if you remove the SPN all the processes will be broken.
https://learn.microsoft.com/en-us/windows/win32/ad/service-principal-names
https://support.quest.com/gpoadmin/kb/4377320/using-quest-gpoadmin-with-a-gmsa-service-account-can-this-tool-run-without-spn
https://support.quest.com/gpoadmin/kb/4225507/cannot-login-to-the-gpoadmin-client
© ALL RIGHTS RESERVED. 使用条款 隐私 Cookie Preference Center