Add-KdsRootKey dssite.msc Get-KdsRootKey Microsoft Microsoft Windows PowerShell Windows Windows PowerShell Windows Server Windows Server 2012 Windows Server 2016
If you want to use the Group Managed Service Accounts feature, you must first create a root key for the group key distribution service within Active Directory. This is used by the KDS service in Domain Controllers to generate passwords. In this post, I show you how to create the KDS root key using the Add-KdsRootKey cmdlet. Use the Add-KdsRootKey cmdlet with the following syntax:
The date on which takes effect the newly generated root key. If this parameter is not specified, the default date set is 10 days after the current date. Use the mm/dd/yyyy format.
This command creates a new root key immediately but must wait up to 10 hours to be available. This is a safety measure to make sure all domain controllers have replicated and are ready to respond to gMSA requests.