Showing posts with label domain. Show all posts
Showing posts with label domain. Show all posts

Tuesday, March 27, 2012

Adds the group to the database But Security EM

I am trying to add domain group with sql server security privileges to a SQL
Server database.
I view the database with SQL Server Enterprise Manager in the database and
users
and notice that domain group is add (sp_addgroup) but this not applied to
the SQL Server security domain group.
Not using the SQL Server Enterprise Manager. How do get the domain group
with
privileges applied to both places (database user , security).> I view the database with SQL Server Enterprise Manager in the database and
> users
> and notice that domain group is add (sp_addgroup) but this not applied to
> the SQL Server security domain group.
sp_addgroup adds a new database role. It is not used to grant an existing
Windows group database access. Also, sp_addgroup is provided only for
backwards compatibility. Use sp_addrole instead.

> Not using the SQL Server Enterprise Manager. How do get the domain group
> with
> privileges applied to both places (database user , security).
From Query Analyzer:
USE MyDatabase
--grant group permissions to connect to SQL Server
EXEC sp_grantlogin 'MyDomain\MyGroup'
--grant group permissions to use this database
EXEC sp_grantdbaccess 'MyDomain\MyGroup'
To setup object security, you can either grant permissions directly to the
Windows account or grant permissions to a SQL Server role and control
security via role membership
--grant object permissions directly
GRANT SELECT ON MyTable TO [MyDomain\MyGroup]
--grant object permissions to role
GRANT SELECT ON MyTable TO [MyDatabaseRole]
--add group to role
EXEC sp_addrolemember 'MyDatabaseRole', 'MyDomain\MyGroup'
Hope this helps.
Dan Guzman
SQL Server MVP
"Joe K." <Joe K.@.discussions.microsoft.com> wrote in message
news:229E0AAA-AEED-400D-B082-3425919A0F85@.microsoft.com...
>I am trying to add domain group with sql server security privileges to a
>SQL
> Server database.
> I view the database with SQL Server Enterprise Manager in the database and
> users
> and notice that domain group is add (sp_addgroup) but this not applied to
> the SQL Server security domain group.
> Not using the SQL Server Enterprise Manager. How do get the domain group
> with
> privileges applied to both places (database user , security).
>
>

Sunday, March 25, 2012

adding windows user via sp_cmdshell

assuming SQL server nt service is started under domain user with right to cr
eate windows user in domain, is there a way to execute sp_ in QA that allow
mw to create domain user, set password and add user to group in domain? if s
o can anyone provide this s
tatment.
Tom,Hi,
Yes. See the OS commands NET USER and NET GROUP in OS Help. You can use this
command from Query Anayzer using XP_CMDSHELL.
Sample
Master..XP_cmdshell 'net user Fin_user password /DOMAIN /ADD'
go
Master..XP_cmdshell 'net group Finance /DOMAIN /ADD'
go
For more details of command execute the below from command prompt
net user ?
net group ?
Thanks
Hari
MCDBA
"TOM P." <TOMP@.discussions.microsoft.com> wrote in message
news:E8D38151-CF4C-4EF9-A713-617E25BA2AEE@.microsoft.com...
> assuming SQL server nt service is started under domain user with right to
create windows user in domain, is there a way to execute sp_ in QA that
allow mw to create domain user, set password and add user to group in
domain? if so can anyone provide this statment.
> Tom,|||Hello Hari,
I have tried it, but it did not work for me, I got:
The request will be processedat DC ...
System error 5 has occurred
Access denied.
I got this regardless if I'm using SA account to open Query Analizer or wind
ows auth... where am member of domain admin. any idea...
"Hari Prasad" wrote:

> Hi,
> Yes. See the OS commands NET USER and NET GROUP in OS Help. You can use th
is
> command from Query Anayzer using XP_CMDSHELL.
> Sample
>
> Master..XP_cmdshell 'net user Fin_user password /DOMAIN /ADD'
> go
> Master..XP_cmdshell 'net group Finance /DOMAIN /ADD'
> go
>
> For more details of command execute the below from command prompt
> net user ?
> net group ?
> Thanks
> Hari
> MCDBA
>
> "TOM P." <TOMP@.discussions.microsoft.com> wrote in message
> news:E8D38151-CF4C-4EF9-A713-617E25BA2AEE@.microsoft.com...
> create windows user in domain, is there a way to execute sp_ in QA that
> allow mw to create domain user, set password and add user to group in
> domain? if so can anyone provide this statment.
>
>|||Hi Tom
As Hari said it is possible, but difficult. The problem
here is its taking the userid of SQL Server instance that
the runs the xp_cmdshell and attempting to create users.
If that userid doesn't have the Server (not SQL)
permission to do its going to crash and burn.

>--Original Message--
>Hello Hari,
>I have tried it, but it did not work for me, I got:
>The request will be processedat DC ...
>System error 5 has occurred
>Access denied.
>I got this regardless if I'm using SA account to open
Query Analizer or windows auth... where am member of
domain admin. any idea...
>"Hari Prasad" wrote:
>
Help. You can use this[vbcol=seagreen]
password /DOMAIN /ADD'[vbcol=seagreen]
command prompt[vbcol=seagreen]
message[vbcol=seagreen]
617E25BA2AEE@.microsoft.com...[vbcol=seagreen]
domain user with right to[vbcol=seagreen]
execute sp_ in QA that[vbcol=seagreen]
user to group in[vbcol=seagreen]
>.
>|||Hi,
I agree with you peter. To do this you might need to start the MSSQL server
service using
a Domain Administrator account. I will not suggest you this.
I will not recommend you to create users / Groups from Query Analyzer.
Thanks
Hari
MCDBA
"Peter" <anonymous@.discussions.microsoft.com> wrote in message
news:2dc001c470c1$74fea120$a301280a@.phx.gbl...[vbcol=seagreen]
> Hi Tom
> As Hari said it is possible, but difficult. The problem
> here is its taking the userid of SQL Server instance that
> the runs the xp_cmdshell and attempting to create users.
> If that userid doesn't have the Server (not SQL)
> permission to do its going to crash and burn.
>
> Query Analizer or windows auth... where am member of
> domain admin. any idea...
> Help. You can use this
> password /DOMAIN /ADD'
> command prompt
> message
> 617E25BA2AEE@.microsoft.com...
> domain user with right to
> execute sp_ in QA that
> user to group in|||Agreed.

>--Original Message--
>Hi,
>I agree with you peter. To do this you might need to
start the MSSQL server
>service using
>a Domain Administrator account. I will not suggest you
this.
>I will not recommend you to create users / Groups from
Query Analyzer.
>Thanks
>Hari
>MCDBA
>
>"Peter" <anonymous@.discussions.microsoft.com> wrote in
message
>news:2dc001c470c1$74fea120$a301280a@.phx.gbl...
that[vbcol=seagreen]
>
>.
>sql

Friday, February 24, 2012

Adding Group Subscriptions

Hi,
Can anyone let me know how to add a group in the domain to reporting
services.I tried adding email address and could easily subscribe to reports.
but when i tried to add a group by spacifying domainname\group name, it did
not work. Can anyone please help!!!
SachinI got a solution for this. All i did was to add a group email in our email
server. Reporting services lets us enter only email address .
"Sachin" wrote:
> Hi,
> Can anyone let me know how to add a group in the domain to reporting
> services.I tried adding email address and could easily subscribe to reports.
> but when i tried to add a group by spacifying domainname\group name, it did
> not work. Can anyone please help!!!
> Sachin

Sunday, February 19, 2012

Adding Domain Local Group as SQL Logins

Hi,
I can not found Domain Local Group when I was adding SQL Logins. But, I foun
d them when using NTFS permission on the same computer. My Domain is 2000 Na
tive mode, SP3 was installed on the SQL Server and everyone group was added
in Pre-windows 2000 Acces
s Group. What's the problem? Help plz.
Rgds,
Harry"HarryNg" <anonymous@.discussions.microsoft.com> wrote in message
news:A6900F4B-1424-4444-9403-4E64FE94669D@.microsoft.com...
> I can not found Domain Local Group when I was adding SQL Logins. But, I
found them when using NTFS permission on the same computer. My Domain is
2000 Native mode, SP3 was installed on the SQL Server and everyone group was
added in Pre-windows 2000 Access Group. What's the problem? Help plz.
Hi, Please see my other post to your question in this newsgroup.
Steve

Adding Domain Local Group as Logins

Hi,
I can not found Domain Local Group when I was adding SQL Logins. But, I foun
d them when using NTFS permission on the same computer. My Domain is 2000 Na
tive mode, SP3 was installed on the SQL Server and everyone group was added
in Pre-windows 2000 Acces
s Group. What's the problem? Help plz.
Rgds,
Harry"HarryNg" <anonymous@.discussions.microsoft.com> wrote in message
news:180922DE-A85E-4D3D-8AB4-ECF10EED154B@.microsoft.com...

> I can not found Domain Local Group when I was adding SQL Logins. But, I
found them when using NTFS permission on the same computer. My Domain is
2000 Native mode, SP3 was installed on the SQL Server and everyone group was
added in Pre-windows 2000 Access Group. What's the problem? Help plz. <
This may be by design. A very simple workaround, create a local group on
your server running SQL Server, then add your domain global group into the
local group on your server. Then, add the (server) local group to the SQL
Server login and give it the proper db permissions...
Steve|||This was a bug that was fixed.
825042 FIX: SQL Server Jobs That Are Owned by Non-sysadmin Users May Not
Start
http://support.microsoft.com/?id=825042
Thanks,
Kevin McDonnell
Microsoft Corporation
This posting is provided AS IS with no warranties, and confers no rights.

Adding Domain Accounts to Databases

Hi guys
I have a user that is in the process of being migrated from one domain to
another. Therefore I have been asked to add his new domain account to the SQL
Server 2000.
However when I try to Add the user Domain2\user1 it fails saying 'user1'
already exist. Which is true as Domain1\User1.
Question is: Is there a way to add user1 from Domain2 without removing the
Domain1 user?
Thanks.
Regards
Jonas
Jonas
Lookup sp_change_users_login in the BOL.
"Jonas Larsen" <JonasLarsen@.discussions.microsoft.com> wrote in message
news:A913CF93-A288-45E0-8653-D085F2FB68B9@.microsoft.com...
> Hi guys
> I have a user that is in the process of being migrated from one domain to
> another. Therefore I have been asked to add his new domain account to the
> SQL
> Server 2000.
> However when I try to Add the user Domain2\user1 it fails saying 'user1'
> already exist. Which is true as Domain1\User1.
> Question is: Is there a way to add user1 from Domain2 without removing the
> Domain1 user?
> Thanks.
> Regards
> Jonas
|||Jonas Larsen wrote:
> Hi guys
> I have a user that is in the process of being migrated from one domain to
> another. Therefore I have been asked to add his new domain account to the SQL
> Server 2000.
> However when I try to Add the user Domain2\user1 it fails saying 'user1'
> already exist. Which is true as Domain1\User1.
> Question is: Is there a way to add user1 from Domain2 without removing the
> Domain1 user?
> Thanks.
> Regards
> Jonas
Hi Jonas
You could also create a group in the new domain and then give this group
the required access to the database. You can then put the new user
account into this group. That should give you what you want.
Regards
Steen

Adding Domain Accounts to Databases

Hi guys
I have a user that is in the process of being migrated from one domain to
another. Therefore I have been asked to add his new domain account to the SQL
Server 2000.
However when I try to Add the user Domain2\user1 it fails saying 'user1'
already exist. Which is true as Domain1\User1.
Question is: Is there a way to add user1 from Domain2 without removing the
Domain1 user?
Thanks.
Regards
JonasJonas
Lookup sp_change_users_login in the BOL.
"Jonas Larsen" <JonasLarsen@.discussions.microsoft.com> wrote in message
news:A913CF93-A288-45E0-8653-D085F2FB68B9@.microsoft.com...
> Hi guys
> I have a user that is in the process of being migrated from one domain to
> another. Therefore I have been asked to add his new domain account to the
> SQL
> Server 2000.
> However when I try to Add the user Domain2\user1 it fails saying 'user1'
> already exist. Which is true as Domain1\User1.
> Question is: Is there a way to add user1 from Domain2 without removing the
> Domain1 user?
> Thanks.
> Regards
> Jonas|||Jonas Larsen wrote:
> Hi guys
> I have a user that is in the process of being migrated from one domain to
> another. Therefore I have been asked to add his new domain account to the SQL
> Server 2000.
> However when I try to Add the user Domain2\user1 it fails saying 'user1'
> already exist. Which is true as Domain1\User1.
> Question is: Is there a way to add user1 from Domain2 without removing the
> Domain1 user?
> Thanks.
> Regards
> Jonas
Hi Jonas
You could also create a group in the new domain and then give this group
the required access to the database. You can then put the new user
account into this group. That should give you what you want.
Regards
Steen

Adding Domain Accounts to Databases

Hi guys
I have a user that is in the process of being migrated from one domain to
another. Therefore I have been asked to add his new domain account to the SQ
L
Server 2000.
However when I try to Add the user Domain2\user1 it fails saying 'user1'
already exist. Which is true as Domain1\User1.
Question is: Is there a way to add user1 from Domain2 without removing the
Domain1 user?
Thanks.
Regards
JonasJonas
Lookup sp_change_users_login in the BOL.
"Jonas Larsen" <JonasLarsen@.discussions.microsoft.com> wrote in message
news:A913CF93-A288-45E0-8653-D085F2FB68B9@.microsoft.com...
> Hi guys
> I have a user that is in the process of being migrated from one domain to
> another. Therefore I have been asked to add his new domain account to the
> SQL
> Server 2000.
> However when I try to Add the user Domain2\user1 it fails saying 'user1'
> already exist. Which is true as Domain1\User1.
> Question is: Is there a way to add user1 from Domain2 without removing the
> Domain1 user?
> Thanks.
> Regards
> Jonas|||Jonas Larsen wrote:
> Hi guys
> I have a user that is in the process of being migrated from one domain to
> another. Therefore I have been asked to add his new domain account to the
SQL
> Server 2000.
> However when I try to Add the user Domain2\user1 it fails saying 'user1'
> already exist. Which is true as Domain1\User1.
> Question is: Is there a way to add user1 from Domain2 without removing the
> Domain1 user?
> Thanks.
> Regards
> Jonas
Hi Jonas
You could also create a group in the new domain and then give this group
the required access to the database. You can then put the new user
account into this group. That should give you what you want.
Regards
Steen