Re: Security Policy for MSSQL service account.

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance




"Geoff N. Hiten" <SQLCraftsman@xxxxxxxxx> wrote in message
news:O23zI8VdHHA.4188@xxxxxxxxxxxxxxxxxxxxxxx
How to change service accounts for a clustered computer that is running
SQL Server
http://support.microsoft.com/kb/239885/en-us

The permissions/privileges are enumerated in the context of changing the
service account on a clustered instance.

--
Geoff N. Hiten
Senior Database Administrator
Microsoft SQL Server MVP


"Gerry Sinkiewicz" <sinkiege@xxxxxxxx> wrote in message
news:N4fPh.142$w41.48@xxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Does anyone have a link for the essential local security policy settings
that are needed by the domain account
that is used to start a clustered MS SQL Server 2000 instance?

I have been to MS Technet and not found a really explicit list of privs
as they relate to my problem.

Of course this has to do with the security guys wanting to deny local
logon, network logon, and terminal services access to the account.
Perhaps that is ok, but will the clustered instance still work?



Thanks, I did find that reference and a few others with similar information.
What will happen, because of the local administrator requirement, is an
exception will be issued
with a mitigation of strong passwords changed at frequent intervals (like
whenever MS OS patches are applied
would be a good time). That makes it once a month or less.


.



Relevant Pages

  • Re: Error 15401 using sp_grantlogin (not addressed by current KB articles)
    ... Restarting Windows 2000 resolved the problem for this particular account, ... confused when it sees a duplicate SID. ... > One way to get SQL Server to agree with the renamed NT ... > Preview (to ensure the script was created), ...
    (microsoft.public.sqlserver.security)
  • Re: SharePoint V3 Install Error
    ... But it our case it had to do with Group Policies that forbid the account of ... WSS FAQ:www.wssv3faq.com/wss.collutions.com ... Event Source: WindowsSharePointServices3Search ... whatever you are installing WSS as sufficient rights to the SQL Server ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: sbs 2003 network slow why?
    ... Issue: Local Account Password Test ... SQL Server and/or MSDE authentication mode is set to Windows Only. ... The Everyone group does not have more than Read access to the SQL Server and/or MSDE registry keys. ... BUILTIN\Administrators group should not be part of sysadmin role. ...
    (microsoft.public.windows.server.sbs)
  • Re: Error 0x80070534 when changing service account
    ... The only solution that I have been able to find for this error is to RDP into the SQL Server using the new Service account you want the SQL server to run under. ... prefix, an error 0x80070056 "The specified network password is not correct." ...
    (microsoft.public.sqlserver.security)
  • RE: Problems with WebParts
    ... to a database called aspnetdb. ... > The connection string specifies a local SQL Server Express instance using a ... > server account must have read and write access to the applications directory. ... > This is necessary because the web server account will automatically create ...
    (microsoft.public.dotnet.framework.aspnet)