Ad Widget

Collapse

Invalid value for service.info when running Zabbix agent with GMSA account

Collapse
This topic has been answered.
X
X
 
  • Time
  • Show
Clear All
new posts
  • kdotzoltan
    Junior Member
    • Feb 2025
    • 2

    #1

    Invalid value for service.info when running Zabbix agent with GMSA account

    I'm running Zabbix Agent 6.0.28 on a Windows DC server, and I'm using a group managed service account (GMSA) as the "Log On As" account for the service.
    In this setup I'm getting 255 (service not running) for Active Directory Domain Services (NTDS) , but I do get correct values for other services, like KDC for example.
    Changing the Zabbix Agent Service to run as Local System solves this issue.
    Running the query manually as Administrator also gives the correct value:

    .\zabbix_agent2.exe -c .\zabbix_agent2.conf -t service.info[NTDS]
    service.info[NTDS] [s|0]

    I suspect this could be some permission related issue, however I can find no indication of a denied permission.
    The GMSA account is associated with the server (otherwise the Zabbix Agent service couldn't even start with it)
  • Answer selected by kdotzoltan at 01-03-2025, 08:37.
    kdotzoltan
    Junior Member
    • Feb 2025
    • 2

    answering myself, if anyone stumbles into a similar issue in the future. It's not particularly related whether the account is a GMSA or a regular account (other than Local System/Service)

    Check your service permissions with
    Code:
    sc sdshow
    (built in), or
    Code:
    subinacl.exe
    from Windows Resource Kit, eventually google (and use at your own risk) Service Security Editor - a free tool from a third-party.
    the account running Zabbix Agent service needs (at least) read access to the service.

    Comment

    • kdotzoltan
      Junior Member
      • Feb 2025
      • 2

      #2
      answering myself, if anyone stumbles into a similar issue in the future. It's not particularly related whether the account is a GMSA or a regular account (other than Local System/Service)

      Check your service permissions with
      Code:
      sc sdshow
      (built in), or
      Code:
      subinacl.exe
      from Windows Resource Kit, eventually google (and use at your own risk) Service Security Editor - a free tool from a third-party.
      the account running Zabbix Agent service needs (at least) read access to the service.

      Comment

      Working...