Skip to content

docs(auditor/10.9): add gMSA support page for Inactive User Tracker#1153

Open
AlexGRNetwrix wants to merge 1 commit into
release/auditor_10.9from
pt3/ag/iut_gmsa_support_10.9
Open

docs(auditor/10.9): add gMSA support page for Inactive User Tracker#1153
AlexGRNetwrix wants to merge 1 commit into
release/auditor_10.9from
pt3/ag/iut_gmsa_support_10.9

Conversation

@AlexGRNetwrix

Copy link
Copy Markdown
Collaborator

Summary

  • Add a new page documenting gMSA support in Inactive User Tracker 10.9 (minimum AD permissions, Delegation of Control Wizard in ADUC, monitoring plan configuration, UI limitations, troubleshooting).
  • Convert the single inactiveusertracker.md into a folder following the passwordexpirationnotifier/ and eventlogmanager/ pattern. The original file is moved via git mv to preserve history.
  • Update tools/overview.md link to the new path.

Generated with AI

Co-Authored-By: Claude Code ai@netwrix.com

Convert the single inactiveusertracker.md into a folder following the
passwordexpirationnotifier/eventlogmanager pattern, and add a dedicated
page documenting the new gMSA support in IUT 10.9:

- Minimum AD permissions per monitoring plan action (alternative to
  Domain Admins)
- Permissions delegation via the Delegation of Control Wizard in ADUC
- How to specify the gMSA in the monitoring plan (trailing $, locked
  Password field, scheduled task under NT AUTHORITY\SYSTEM)
- UI limitations (Generate report / Filter by OU / Browse OU)
- Troubleshooting table

The existing inactiveusertracker.md is moved via git mv to preserve
history. tools/overview.md is updated to the new path.

Generated with AI

Co-Authored-By: Claude Code <ai@netwrix.com>
@AlexGRNetwrix AlexGRNetwrix requested a review from a team as a code owner June 19, 2026 17:03

After you complete those prerequisites, delegate the Active Directory permissions described below and specify the gMSA in the Inactive User Tracker monitoring plan.

:::note

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It seems it is not valid markdown

Image

| Delete accounts after | Read + `Delete` on user and computer objects + `DeleteChild` (user, computer) on the parent container |
| Delete account with all its subnodes | All of the permissions for Delete accounts after, plus the `DeleteTree` standard right on user and computer objects |

:::note

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The same


## Limitations

:::warning

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The same for warning

Image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants