Can Group Managed Service Accounts be used to access Orchestrator & Robots?

How to use Group Managed Service Accounts (gMSA) to access Orchestrator & Robots?

Group Managed Service Accounts can not be used o access Orchestrator & Robots, due to below reasons:

  • Interactive Logon is not allowed for gMSA
  • Their randomly generated passwords are not available either outside the AD.


Therefore Group Managed Service Accounts can not connect to RDP session or log into some website such as Orchestrator.

They are made for Services, however Robot services can not use it either.

  • Robot service must use Local System because impersonation role is needed while the service writes and secures packages access rights in Robot user profiles.