Domain Level Service Account
If you use a domain user account or group managed service account for the sql server service account grant permissions to that domain user account.
Domain level service account. Services that run as the network service account access network resources by using the credentials of the computer account in the format domain name computer name. A domain user account enables the service to take full advantage of the service security features of windows and microsoft active directory domain services. The service can support kerberos mutual authentication. All managed service accounts are created by default in the new cn managed service accounts dc domain dc com container.
Active directory managed service accounts are similar to domain user accounts but the password is reset regularly and automatically. There are no domain or forest functional level requirements. A managed service account is designed to isolate domain accounts in crucial applications such as internet information services iis and eliminate the need for an administrator to manually administer the service principal name spn and credentials for the accounts. When the domain is running at the windows server 2008 r2 functional level the service principal name spn doesn t need to be managed as with local accounts.
If a malicious user were to compromise a service account then that malicious user accesses your domain up to and including all level of privilege of the associated service account. The network service account is a built in account that has more access to resources and objects than members of the users group. Unfortunately this best practice sometimes causes deployment headaches in that either we need to provision a new domain level service account quickly or once we have the account we now need to manage the account credentials. With active directory managed service accounts you can only assign one user account per computer and each account can be used with multiple services on the computer.
A user account can be used on only one computer you must create at least one account per computer. When using a managed service account. Forest functional level but there is a scenario where part of msa functionality requires a windows server 2008 domain functional level.