adclient.krb5.cache.infinite.renewal.gmsa

Use this parameter to specify a list of Group Managed Service Accounts (gMSA) for which adclient will issue and renew a Kerberos credential cache indefinitely. You can specify the gMSA account by CN (Common name), Display Name, or UPN.

For example:

adclient.krb5.cache.infinite.renewal.gmsa: joe.user@acme.com