Showing posts with label power. Show all posts
Showing posts with label power. Show all posts

Wednesday, March 28, 2012

Running/Starting MSDE Server as Power User automatically

I am able to install MSDE as an Administrator. The server will also
start (with the little icon in system tray showing the white circle
with a green play graphic).
I am able to use the server perfectly fine as a user under the
Administration group.
However, when I created a local account under POWER USER group, the
server does not start or connect to any servers.
I have to manually type in my computer's name at which point it will
start.
I have also had trouble installing the server and having it
successfully run under a POWER USER group.
Anyone have any soultions?
Gautam Lad
hi,
"Gautam Lad" <gautam@.hbfenn.com> ha scritto nel messaggio
news:3a492d07.0501031241.1e0cf675@.posting.google.c om
> I am able to install MSDE as an Administrator. The server will also
> start (with the little icon in system tray showing the white circle
> with a green play graphic).
> I am able to use the server perfectly fine as a user under the
> Administration group.
> However, when I created a local account under POWER USER group, the
> server does not start or connect to any servers.
> I have to manually type in my computer's name at which point it will
> start.
> I have also had trouble installing the server and having it
> successfully run under a POWER USER group.
> Anyone have any soultions?
as SQL Server requires a lot of admin privileges at startup, in order to
register services, install MDAC (if needed) and loo of COM server, the best
way to go is installing it as mmber of admins WinNT role...
as regard running SQL Server, it's services (MSSQLSERVER and SQLSERVERAGENT
for a default instance) usually run under LocalSystem WinNT special account,
but you can run them under any admin member WinNT account, as special
privileges for file system and registry access...
in usual solutions, MSDE is installed from admins and run under their
account (LocalSystem and/or standard WinNT local admin accounts), but WinNT
logged users are (as best practice) traditional non admin users, that's to
say power users or limited users, and you should not see problems this
way... you have to check the account the services are running under...
Andrea Montanari (Microsoft MVP - SQL Server)
http://www.asql.biz/DbaMgr.shtmhttp://italy.mvps.org
DbaMgr2k ver 0.9.1 - DbaMgr ver 0.55.1
(my vb6+sql-dmo little try to provide MS MSDE 1.0 and MSDE 2000 a visual
interface)
-- remove DMO to reply
sql

Wednesday, March 21, 2012

Running SQLServer and SQLServer Agent as Power User

We're trying to limit the number of user accounts with Admin level permissio
n
on our Win2K servers, especially SQL servers. We have created a domain level
account to run SQLServer and SQLAgent. We'd like to limit it to Power User
status instead of Admin status on the servers, but we cannot seem to start
and stop the services from SEM with only Power User status. We've checked
registry key permissions and everything seems to be configured properly. Is
this configuration even possible? Or does this account NEED to be local admi
n
on the server? Help would be appreciated. Thanks.The account that starts the services needs to have the "log on as a service"
right. Without this MSSQLServer and MS SQL Server Agent will not start.
It would also be more secure to use a domain account for this rather than a
local account as SQL then benefits from the integrated security of Windows
2000.
Also why would you want end users to have admin rights on the server at all?
This defeats the object of system security and resource accessibility. It
is best that they are Doman Users only then assign access rights to shares
on the servers.
HTH
Regards
Dazza
"gbledsoe" <gbledsoe@.discussions.microsoft.com> wrote in message
news:72CDD311-3C73-480E-9734-3E6F0E76DB09@.microsoft.com...
> We're trying to limit the number of user accounts with Admin level
> permission
> on our Win2K servers, especially SQL servers. We have created a domain
> level
> account to run SQLServer and SQLAgent. We'd like to limit it to Power User
> status instead of Admin status on the servers, but we cannot seem to start
> and stop the services from SEM with only Power User status. We've checked
> registry key permissions and everything seems to be configured properly.
> Is
> this configuration even possible? Or does this account NEED to be local
> admin
> on the server? Help would be appreciated. Thanks.|||We've following the instructions in MS article 283811 and ensured that the
account has all necessary extended user rights, such as act as part of
operating system, logon as batch job, logon as service. The fundamental
question is whether the account can run as Power User or does it need to be
Administrator? If it does not NEED to be Administrator, what other
configuration is necessary to let us use that account to stop and start the
SQLServer service, since Power User does not seem to have the rights. Thanks
.
"Dazza" wrote:

> The account that starts the services needs to have the "log on as a servic
e"
> right. Without this MSSQLServer and MS SQL Server Agent will not start.
> It would also be more secure to use a domain account for this rather than
a
> local account as SQL then benefits from the integrated security of Windows
> 2000.
> Also why would you want end users to have admin rights on the server at al
l?
> This defeats the object of system security and resource accessibility. It
> is best that they are Doman Users only then assign access rights to shares
> on the servers.
> HTH
> Regards
> Dazza
>
> "gbledsoe" <gbledsoe@.discussions.microsoft.com> wrote in message
> news:72CDD311-3C73-480E-9734-3E6F0E76DB09@.microsoft.com...
>
>|||gbledsoe wrote:
> We're trying to limit the number of user accounts with Admin level permiss
ion
> on our Win2K servers, especially SQL servers. We have created a domain lev
el
> account to run SQLServer and SQLAgent. We'd like to limit it to Power User
> status instead of Admin status on the servers, but we cannot seem to start
> and stop the services from SEM with only Power User status. We've checked
> registry key permissions and everything seems to be configured properly. I
s
> this configuration even possible? Or does this account NEED to be local ad
min
> on the server? Help would be appreciated. Thanks.
It should be, although not all sql feature are available. I am running
multiple instances with different plain domain user accounts. When you are
not sure about registry, user and ntfs permission change the account using
the enterprise manager.
When you need the proxy account to run scheduled dts packages create a
separate account for the sql agent service and make it local admin, unless
someone here can explain how to accomplice this without local admin rights.
have a look at this one:
http://support.microsoft.com/defaul...;283811&sd=tech
Hans