Make sure you have a $ in the account for the group managed sevice account in Defender for Identity and you can run this on the server
Test-ADServiceAccount -Identity NewSmsa
