Showing posts with label domain. Show all posts
Showing posts with label domain. Show all posts

Thursday, March 29, 2012

Changing the SQL SErver DOmain

Hello,
Anybody knows what's the effects caused by a Server Domains Change?
I'm planning to change a Domain of my SQL Server that actually has a trust
with the current Domain of this server.
I think that I don't need to do nothing after this change. I'm correct?
Thanks
Juliano Horta
Message posted via droptable.com
http://www.droptable.com/Uwe/Forums.aspx/sql-server/200703/1
Hello,
Take a look into the google archive for the similar topic.
[url]http://groups.google.com/group/microsoft.public.sqlserver.connect/browse_frm/thread/3533c9535e06f49e/b6ea4289a0ead18c?lnk=st&q=changing+sql+server+doma in&rnum=19&hl=en#b6ea4289a0ead18c[/url]
Thanks
Hari
"julianohorta via droptable.com" <u13014@.uwe> wrote in message
news:6e89b9509fcf6@.uwe...
> Hello,
> Anybody knows what's the effects caused by a Server Domains Change?
> I'm planning to change a Domain of my SQL Server that actually has a trust
> with the current Domain of this server.
> I think that I don't need to do nothing after this change. I'm correct?
> Thanks
> Juliano Horta
> --
> Message posted via droptable.com
> http://www.droptable.com/Uwe/Forums.aspx/sql-server/200703/1
>
sql

Changing the SQL SErver DOmain

Hello,
Anybody knows what's the effects caused by a Server Domains Change?
I'm planning to change a Domain of my SQL Server that actually has a trust
with the current Domain of this server.
I think that I don't need to do nothing after this change. I'm correct?
Thanks
Juliano Horta
--
Message posted via SQLMonster.com
http://www.sqlmonster.com/Uwe/Forums.aspx/sql-server/200703/1Hello,
Take a look into the google archive for the similar topic.
http://groups.google.com/group/microsoft.public.sqlserver.connect/browse_frm/thread/3533c9535e06f49e/b6ea4289a0ead18c?lnk=st&q=changing+sql+server+domain&rnum=19&hl=en#b6ea4289a0ead18c
Thanks
Hari
"julianohorta via SQLMonster.com" <u13014@.uwe> wrote in message
news:6e89b9509fcf6@.uwe...
> Hello,
> Anybody knows what's the effects caused by a Server Domains Change?
> I'm planning to change a Domain of my SQL Server that actually has a trust
> with the current Domain of this server.
> I think that I don't need to do nothing after this change. I'm correct?
> Thanks
> Juliano Horta
> --
> Message posted via SQLMonster.com
> http://www.sqlmonster.com/Uwe/Forums.aspx/sql-server/200703/1
>

Changing the SQL SErver DOmain

Hello,
Anybody knows what's the effects caused by a Server Domains Change?
I'm planning to change a Domain of my SQL Server that actually has a trust
with the current Domain of this server.
I think that I don't need to do nothing after this change. I'm correct?
Thanks
Juliano Horta
Message posted via droptable.com
http://www.droptable.com/Uwe/Forum...server/200703/1Hello,
Take a look into the google archive for the similar topic.
http://groups.google.com/group/micr...6ea4289a0ead18c
Thanks
Hari
"julianohorta via droptable.com" <u13014@.uwe> wrote in message
news:6e89b9509fcf6@.uwe...
> Hello,
> Anybody knows what's the effects caused by a Server Domains Change?
> I'm planning to change a Domain of my SQL Server that actually has a trust
> with the current Domain of this server.
> I think that I don't need to do nothing after this change. I'm correct?
> Thanks
> Juliano Horta
> --
> Message posted via droptable.com
> http://www.droptable.com/Uwe/Forum...server/200703/1
>

Changing the SQL Server Agent ID

Hello,
We have are using SQL 2000 on a 2003 server. We have one
instance of 2000 up to service pack 3a.
We need to change the domain user id of the SQL Server
Agent. We changed it through the Services section of
Windows 2003. Then starting up it reports 'Access is
deniged'
The domain userid we are change it to is already an
administrator on the server, and is used on a different
server, and I am logged on as a local administrator.
Can anyone point the way ?
Thanks
Peter
it's recommended to change it using enterprise manager instead of in the
services window. you may need to search for a kb article about how to
manually change the account associated with the sqlagent. there's
registry settings, file permissions, etc that need to change.
Peter wrote:

> Hello,
> We have are using SQL 2000 on a 2003 server. We have one
> instance of 2000 up to service pack 3a.
> We need to change the domain user id of the SQL Server
> Agent. We changed it through the Services section of
> Windows 2003. Then starting up it reports 'Access is
> deniged'
> The domain userid we are change it to is already an
> administrator on the server, and is used on a different
> server, and I am logged on as a local administrator.
> Can anyone point the way ?
> Thanks
> Peter
|||A good start is to search Books Online for "level token".
Tibor Karaszi, SQL Server MVP
http://www.karaszi.com/sqlserver/default.asp
"ch" <ch@.dontemailme.com> wrote in message news:4098DED6.AE35BF7D@.dontemailme.com...
> it's recommended to change it using enterprise manager instead of in the
> services window. you may need to search for a kb article about how to
> manually change the account associated with the sqlagent. there's
> registry settings, file permissions, etc that need to change.
>
> Peter wrote:
>

Changing the SQL Server Agent ID

Hello,
We have are using SQL 2000 on a 2003 server. We have one
instance of 2000 up to service pack 3a.
We need to change the domain user id of the SQL Server
Agent. We changed it through the Services section of
Windows 2003. Then starting up it reports 'Access is
deniged'
The domain userid we are change it to is already an
administrator on the server, and is used on a different
server, and I am logged on as a local administrator.
Can anyone point the way ?
Thanks
Peterit's recommended to change it using enterprise manager instead of in the
services window. you may need to search for a kb article about how to
manually change the account associated with the sqlagent. there's
registry settings, file permissions, etc that need to change.
Peter wrote:

> Hello,
> We have are using SQL 2000 on a 2003 server. We have one
> instance of 2000 up to service pack 3a.
> We need to change the domain user id of the SQL Server
> Agent. We changed it through the Services section of
> Windows 2003. Then starting up it reports 'Access is
> deniged'
> The domain userid we are change it to is already an
> administrator on the server, and is used on a different
> server, and I am logged on as a local administrator.
> Can anyone point the way ?
> Thanks
> Peter|||A good start is to search Books Online for "level token".
Tibor Karaszi, SQL Server MVP
http://www.karaszi.com/sqlserver/default.asp
"ch" <ch@.dontemailme.com> wrote in message news:4098DED6.AE35BF7D@.dontemailme.com...eagreen">
> it's recommended to change it using enterprise manager instead of in the
> services window. you may need to search for a kb article about how to
> manually change the account associated with the sqlagent. there's
> registry settings, file permissions, etc that need to change.
>
> Peter wrote:
>
>

Changing the SQL Server Agent ID

Hello,
We have are using SQL 2000 on a 2003 server. We have one
instance of 2000 up to service pack 3a.
We need to change the domain user id of the SQL Server
Agent. We changed it through the Services section of
Windows 2003. Then starting up it reports 'Access is
deniged'
The domain userid we are change it to is already an
administrator on the server, and is used on a different
server, and I am logged on as a local administrator.
Can anyone point the way ?
Thanks
Peterit's recommended to change it using enterprise manager instead of in the
services window. you may need to search for a kb article about how to
manually change the account associated with the sqlagent. there's
registry settings, file permissions, etc that need to change.
Peter wrote:
> Hello,
> We have are using SQL 2000 on a 2003 server. We have one
> instance of 2000 up to service pack 3a.
> We need to change the domain user id of the SQL Server
> Agent. We changed it through the Services section of
> Windows 2003. Then starting up it reports 'Access is
> deniged'
> The domain userid we are change it to is already an
> administrator on the server, and is used on a different
> server, and I am logged on as a local administrator.
> Can anyone point the way ?
> Thanks
> Peter|||A good start is to search Books Online for "level token".
--
Tibor Karaszi, SQL Server MVP
http://www.karaszi.com/sqlserver/default.asp
"ch" <ch@.dontemailme.com> wrote in message news:4098DED6.AE35BF7D@.dontemailme.com...
> it's recommended to change it using enterprise manager instead of in the
> services window. you may need to search for a kb article about how to
> manually change the account associated with the sqlagent. there's
> registry settings, file permissions, etc that need to change.
>
> Peter wrote:
> > Hello,
> >
> > We have are using SQL 2000 on a 2003 server. We have one
> > instance of 2000 up to service pack 3a.
> >
> > We need to change the domain user id of the SQL Server
> > Agent. We changed it through the Services section of
> > Windows 2003. Then starting up it reports 'Access is
> > deniged'
> >
> > The domain userid we are change it to is already an
> > administrator on the server, and is used on a different
> > server, and I am logged on as a local administrator.
> >
> > Can anyone point the way ?
> >
> > Thanks
> > Peter
>sql

Tuesday, March 27, 2012

Changing the MSSQLServer service account causes SQL Agent could not start

Hi...a SQL2005 enterprise under W2K3 server. All the SQL services are
running either a domain account or local system account, i.e.
MSSQLServer service is under a domain account, SQL Agent is under
local system.
For a reason, we need to switch the domain account to the other domain
account, the MSSQLServer service is started up with no problem but the
SQL Agent is not able to start up neither in local system or new
domain account, the error message is: "The SQL Server Agent
(MSSQLSERVER) service on Local Computer started and then stop
automatically if they have no work to do, for example, the Performance
Logs and Alerts service. "
Switch back to original domain account is fine, let the MSSQLServer
running on local system account is fine too for both MSSQLServer and
SQL Agent.
P.S. Both old/new domain accounts are in the server's local admin and
domain administrator groups and as well as SQL sa.
What is needed to use a domain account as the SQL service account?
Thanks,
Yvette.
Hi Yvette
"yvette.ye@.gmail.com" wrote:

> Hi...a SQL2005 enterprise under W2K3 server. All the SQL services are
> running either a domain account or local system account, i.e.
> MSSQLServer service is under a domain account, SQL Agent is under
> local system.
> For a reason, we need to switch the domain account to the other domain
> account, the MSSQLServer service is started up with no problem but the
> SQL Agent is not able to start up neither in local system or new
> domain account, the error message is: "The SQL Server Agent
> (MSSQLSERVER) service on Local Computer started and then stop
> automatically if they have no work to do, for example, the Performance
> Logs and Alerts service. "
> Switch back to original domain account is fine, let the MSSQLServer
> running on local system account is fine too for both MSSQLServer and
> SQL Agent.
> P.S. Both old/new domain accounts are in the server's local admin and
> domain administrator groups and as well as SQL sa.
> What is needed to use a domain account as the SQL service account?
> Thanks,
> Yvette.
>
For the account types that can be used see
http://support.microsoft.com/kb/907557
and http://support.microsoft.com/kb/283811 describes the requirements for
the accounts if you don't use EM or SCM to change the account.
John
|||"John Bell" wrote:

> Hi Yvette
> For the account types that can be used see
> http://support.microsoft.com/kb/907557
> and http://support.microsoft.com/kb/283811 describes the requirements for
> the accounts if you don't use EM or SCM to change the account.
> John
Also try http://msdn2.microsoft.com/en-us/library/ms143504.aspx
John

Changing the MSSQLServer service account causes SQL Agent could not start

Hi...a SQL2005 enterprise under W2K3 server. All the SQL services are
running either a domain account or local system account, i.e.
MSSQLServer service is under a domain account, SQL Agent is under
local system.
For a reason, we need to switch the domain account to the other domain
account, the MSSQLServer service is started up with no problem but the
SQL Agent is not able to start up neither in local system or new
domain account, the error message is: "The SQL Server Agent
(MSSQLSERVER) service on Local Computer started and then stop
automatically if they have no work to do, for example, the Performance
Logs and Alerts service. "
Switch back to original domain account is fine, let the MSSQLServer
running on local system account is fine too for both MSSQLServer and
SQL Agent.
P.S. Both old/new domain accounts are in the server's local admin and
domain administrator groups and as well as SQL sa.
What is needed to use a domain account as the SQL service account?
Thanks,
Yvette.Hi Yvette
"yvette.ye@.gmail.com" wrote:
> Hi...a SQL2005 enterprise under W2K3 server. All the SQL services are
> running either a domain account or local system account, i.e.
> MSSQLServer service is under a domain account, SQL Agent is under
> local system.
> For a reason, we need to switch the domain account to the other domain
> account, the MSSQLServer service is started up with no problem but the
> SQL Agent is not able to start up neither in local system or new
> domain account, the error message is: "The SQL Server Agent
> (MSSQLSERVER) service on Local Computer started and then stop
> automatically if they have no work to do, for example, the Performance
> Logs and Alerts service. "
> Switch back to original domain account is fine, let the MSSQLServer
> running on local system account is fine too for both MSSQLServer and
> SQL Agent.
> P.S. Both old/new domain accounts are in the server's local admin and
> domain administrator groups and as well as SQL sa.
> What is needed to use a domain account as the SQL service account?
> Thanks,
> Yvette.
>
For the account types that can be used see
http://support.microsoft.com/kb/907557
and http://support.microsoft.com/kb/283811 describes the requirements for
the accounts if you don't use EM or SCM to change the account.
John|||"John Bell" wrote:
> Hi Yvette
> For the account types that can be used see
> http://support.microsoft.com/kb/907557
> and http://support.microsoft.com/kb/283811 describes the requirements for
> the accounts if you don't use EM or SCM to change the account.
> John
Also try http://msdn2.microsoft.com/en-us/library/ms143504.aspx
John

Sunday, March 25, 2012

Changing the Domain User Password

Is there an automatic way of changing the Domain user password getting used for running the SQL Server as a Domain user account? I'm taking about EM--Security--Domain User name and the password getting used for running the SQL Server?Check out this thread

http://www.dbforums.com/t992825.html

Changing the Domain of a SQL 2005 Cluster

I know it's not possible, I've read the KBs. But I don't understand why not - from my testing, it looks like the only things that break are the domain groups to which the service logins are added. The service logins can be changed, as can the IPs, and SQL starts up just fine. The only problem is the domain groups.

I saw this KB:

http://support.microsoft.com/?kbid=910708

which says this:

After you install a SQL Server 2005 failover cluster, you can change the service accounts, but you cannot change the domain groups. If you want to use different domain groups, you must uninstall and then reinstall SQL Server 2005.

But it doesn't elaborate, it just says that the groups cannot be changed. Why not? That seems silly to me - it's not just a line in a config file somewhere? Can someone please give me a good reason why the groups cannot be changed?

Never mind. Found it, hacked it, blogged it.

Hope this helps someone else who's trying to do the same thing.

http://dbaiq.blogspot.com/2006/07/changing-domain-for-sql-2005-cluster.html

|||

Hi,

I really need your knowledge but none of the links you have posted above works. Can you please advise me how to change the domain of a SQL 2005 cluster?

Thank you very much for your help.

sql

Changing the Domain of a SQL 2005 Cluster

I know it's not possible, I've read the KBs. But I don't understand why not - from my testing, it looks like the only things that break are the domain groups to which the service logins are added. The service logins can be changed, as can the IPs, and SQL starts up just fine. The only problem is the domain groups.

I saw this KB:

http://support.microsoft.com/?kbid=910708

which says this:

After you install a SQL Server 2005 failover cluster, you can change the service accounts, but you cannot change the domain groups. If you want to use different domain groups, you must uninstall and then reinstall SQL Server 2005.

But it doesn't elaborate, it just says that the groups cannot be changed. Why not? That seems silly to me - it's not just a line in a config file somewhere? Can someone please give me a good reason why the groups cannot be changed?

Never mind. Found it, hacked it, blogged it.

Hope this helps someone else who's trying to do the same thing.

http://dbaiq.blogspot.com/2006/07/changing-domain-for-sql-2005-cluster.html

|||

Hi,

I really need your knowledge but none of the links you have posted above works. Can you please advise me how to change the domain of a SQL 2005 cluster?

Thank you very much for your help.

Thursday, March 22, 2012

Changing the database Owner

Hi,
I have the problem changing the database onwer using sp_changedbowner. I
have a database TEST and owner it is shwing as userid/domain and in sysusers
in this database it showing sa as dbo. When I ran the sp_changedbowner sa ,
it is telling sa is already user in the database. I wnat to change this
database onwer to 'sa', can some tell how to do this.
Thnaks,
RbHow many rows does below return:
USE dbname
SELECT *
FROM sysusers su INNER JOIN master..syslogins AS sl ON su.sid = sl.sid
and sl.name = 'sa'
--
Tibor Karaszi, SQL Server MVP
Archive at:
http://groups.google.com/groups?oi=djq&as_ugroup=microsoft.public.sqlserver
"rb" <srbssr@.yahoo.com> wrote in message
news:uQ0A440uDHA.1224@.TK2MSFTNGP09.phx.gbl...
> Hi,
> I have the problem changing the database onwer using sp_changedbowner. I
> have a database TEST and owner it is shwing as userid/domain and in
sysusers
> in this database it showing sa as dbo. When I ran the sp_changedbowner sa
,
> it is telling sa is already user in the database. I wnat to change this
> database onwer to 'sa', can some tell how to do this.
> Thnaks,
> Rb
>|||Tibor,
I am getting One row when I ran the query.
(1 row(s) affected)
Thanks,
RB
"Tibor Karaszi" <tibor.please_reply_to_public_forum.karaszi@.cornerstone.se>
wrote in message news:%23mYyRd1uDHA.3536@.tk2msftngp13.phx.gbl...
> How many rows does below return:
> USE dbname
> SELECT *
> FROM sysusers su INNER JOIN master..syslogins AS sl ON su.sid = sl.sid
> and sl.name = 'sa'
> --
> Tibor Karaszi, SQL Server MVP
> Archive at:
>
http://groups.google.com/groups?oi=djq&as_ugroup=microsoft.public.sqlserver
>
> "rb" <srbssr@.yahoo.com> wrote in message
> news:uQ0A440uDHA.1224@.TK2MSFTNGP09.phx.gbl...
> > Hi,
> > I have the problem changing the database onwer using sp_changedbowner. I
> > have a database TEST and owner it is shwing as userid/domain and in
> sysusers
> > in this database it showing sa as dbo. When I ran the sp_changedbowner
sa
> ,
> > it is telling sa is already user in the database. I wnat to change this
> > database onwer to 'sa', can some tell how to do this.
> >
> > Thnaks,
> > Rb
> >
> >
>|||Then sa is already a user in the database. What username does it say?
--
Tibor Karaszi, SQL Server MVP
Archive at:
http://groups.google.com/groups?oi=djq&as_ugroup=microsoft.public.sqlserver
"rb" <srbssr@.yahoo.com> wrote in message
news:O0M9Gs2uDHA.2208@.TK2MSFTNGP10.phx.gbl...
> Tibor,
> I am getting One row when I ran the query.
> (1 row(s) affected)
> Thanks,
> RB
>
> "Tibor Karaszi"
<tibor.please_reply_to_public_forum.karaszi@.cornerstone.se>
> wrote in message news:%23mYyRd1uDHA.3536@.tk2msftngp13.phx.gbl...
> > How many rows does below return:
> > USE dbname
> > SELECT *
> > FROM sysusers su INNER JOIN master..syslogins AS sl ON su.sid = sl.sid
> > and sl.name = 'sa'
> >
> > --
> > Tibor Karaszi, SQL Server MVP
> > Archive at:
> >
>
http://groups.google.com/groups?oi=djq&as_ugroup=microsoft.public.sqlserver
> >
> >
> > "rb" <srbssr@.yahoo.com> wrote in message
> > news:uQ0A440uDHA.1224@.TK2MSFTNGP09.phx.gbl...
> > > Hi,
> > > I have the problem changing the database onwer using sp_changedbowner.
I
> > > have a database TEST and owner it is shwing as userid/domain and in
> > sysusers
> > > in this database it showing sa as dbo. When I ran the sp_changedbowner
> sa
> > ,
> > > it is telling sa is already user in the database. I wnat to change
this
> > > database onwer to 'sa', can some tell how to do this.
> > >
> > > Thnaks,
> > > Rb
> > >
> > >
> >
> >
>

Tuesday, March 20, 2012

Changing SQL startup account

I just can't seem to get this working right. I want to make it just a
regular domain user in a W2k domain on a 2003 server running sql 2000 sp3.
Everything is in place from what I see. It actually works too...until you
reboot. I don't konw what is wrong. Perhaps someone knows about this
error.
SQL Server could not find the default instance (MSSQLSERVER) - please
specify the name of an existing instance on the invocation of sqlservr.exe.
I think I reinstalled this about 10 times now, I'll do it again if it makes
it work too.
Yes, I get the same error loging in as the accound and trying to run the
sqlservr manually.
I'm guessing it is something from one of the policies when it reboots?
Or maybe the service start after the initial install/change in the
Enterprise Manager and the service starts out of context?
Any help from someone who did this before would be great. Because at this
point I don't even think it will work.Check the NT Application Event logs for errors while SQL is starting.
May be problems with the account you're using to start the service with or
if you've changed /moved database files
to another drive location etc.
Also, check the sqlstp.log for errors as well during initial setup.
Thanks,
Kevin McDonnell
Microsoft Corporation
This posting is provided AS IS with no warranties, and confers no rights.|||Ok,
I think I'm on the right track here, It looks like the registry
permissions are the ones at fault. Regmon proves useful again. I can go
and set the permissions manually on the following keys:
HKLM\SOFTWARE\Microsoft\MSSQLSERVER\MSSQ
LServer\CurrentVersion
HKLM\SOFTWARE\Microsoft\MSSQLSERVER\\Set
up
This I have done previously and SEM does this too.
Of course I can set the permissions, but... they disappear after I restart
the sql service. That is the only access denied message in regmon. The
ntfs permissions are still correct, just the registry. Has anyone run into
this before? I never came across permissions in the registry being modified
by any application that was not being setup.
And now I have, setting the permissions on the registry keys while the
cluster service was controlling the service did not properly replicate over
to the corresponding cluster server. Thus the permissions being reverted
after setting them while the service was in a "offline" state...created a
difference which was overridden by the cluster service's replication.
Why did this happen? I'm sure anyone in the group can tell me why this
occurred. And I'm gonna leave this out.
"Kevin McDonnell [MSFT]" <kevmc@.online.microsoft.com> wrote in message
news:0DSXEPtGFHA.2412@.TK2MSFTNGXA02.phx.gbl...
> Check the NT Application Event logs for errors while SQL is starting.
> May be problems with the account you're using to start the service with or
> if you've changed /moved database files
> to another drive location etc.
> Also, check the sqlstp.log for errors as well during initial setup.
> Thanks,
> Kevin McDonnell
> Microsoft Corporation
> This posting is provided AS IS with no warranties, and confers no rights.
>
>|||You failed to mention this was a SQL Cluster in your original post.
You can't make manual changes to the SQL registry keys as the Windows
Cluster checkpoint will just roll back the changes
you made manually.
It sounds like you have both a non-Clustered default instance and a
Clustered instance.
My advice would be to open a case with PSS SQL Support to resolve this.
Thanks,
Kevin McDonnell
Microsoft Corporation
This posting is provided AS IS with no warranties, and confers no rights.|||Luke,
We had a very similar situation, and we followed the solution in:
http://groups.google.com/groups?q=l...ftngxa07&rnum=3
However, we weren't using clusters so this might not be appropriate.
Simon.
"Luke" wrote:

> I just can't seem to get this working right. I want to make it just a
> regular domain user in a W2k domain on a 2003 server running sql 2000 sp3.
> Everything is in place from what I see. It actually works too...until you
> reboot. I don't konw what is wrong. Perhaps someone knows about this
> error.
> SQL Server could not find the default instance (MSSQLSERVER) - please
> specify the name of an existing instance on the invocation of sqlservr.exe
.
> I think I reinstalled this about 10 times now, I'll do it again if it make
s
> it work too.
> Yes, I get the same error loging in as the accound and trying to run the
> sqlservr manually.
> I'm guessing it is something from one of the policies when it reboots?
> Or maybe the service start after the initial install/change in the
> Enterprise Manager and the service starts out of context?
> Any help from someone who did this before would be great. Because at this
> point I don't even think it will work.
>
>sql

Changing SQL Service Account

Has anyone ever converted from running SQL Server under the Local System account to running under a Domain User account?

I have often installed SQL using a Domain User account, but I am inheriting a couple of SQL Servers that were set up to run under Local System. I have never had to convert "on the fly" before.

If you have any input or insights, I would be grateful.

Regards,

hmscottI have done this several times, and have had no issues (knock on wood). Make sure that the Domain account has sufficient permissions on the local machine, and you shold be ok.|||Is "Power User" sufficient, or do I have to grant local admin to the account?

Regards,

hmscott|||If any of the jobs on the local involves deleting/creating files then better to give admin and its no harm is allocating this privilege for SQL service accounts.|||Originally posted by Satya
If any of the jobs on the local involves deleting/creating files then better to give admin and its no harm is allocating this privilege for SQL service accounts.

8-O

That's wrong! Basic tenet of security is least privileges of course. Required permissions are outlined in this article:

http://support.microsoft.com/?id=283811

Quote from the article: "...running SQL Server under such high user rights is not recommended."|||No such threat at our end, so far so good.
It purely depend how you secure the network and connections.|||Due to the nature of what our SQL Servers do, we make most of the machines run as LocalSystem. We basically make each machine run with the lowest level of privledge that it needs to do its job.

We do have one machine that is our interface/automation server that does all kinds of things like copying data from one server to another, runs DTS packages that affect multiple machines, etc that has privleges similar to a Domain Admin (because it must touch nearly every machine in the Data Center). Only the Domain Admins and a few select IT staff can even see this box, much less touch it!

-PatP

changing sql server service account password

SQL Server 2000 running on W2K3 Advanced Server Cluster with 2 nodes.
We have a domain level account which the MSSQLSERVER and SQLSERVERAGENT
services use.
When I change the password for this account in active directory, I also
changed the password for the services in the Services properties on both
cluster nodes
The services Startup Type has to be Manual, or else the following error
occurs:
"17050: initerrlog: could not open error log file ... (the correct path
to the error log follows)"
The error log is on the shared drive of the cluster.
Also, when the servers boot up, the following error is in Event Viewer:
"The Data portion of event 19002 from MSSQLServer is invalid"
Microsoft (Q230393) says this is a bug and ignore it, but it didn't occur
until I changed the password.
Are these normal consequences of changing the account password?
Are there other steps I should take?
Thanks
Bill
Go back into Enterprise Manager and change the service accounts there. That
will fix any permissions and setup issues. Service startup type as Manual
is correct. That allows the cluster service to control the actual service
start/stop.
Geoff N. Hiten
Microsoft SQL Server MVP
Senior Database Administrator
"bill" <belgie@.datamti.com> wrote in message
news:uOYfAolLFHA.904@.tk2msftngp13.phx.gbl...
> SQL Server 2000 running on W2K3 Advanced Server Cluster with 2 nodes.
> We have a domain level account which the MSSQLSERVER and SQLSERVERAGENT
> services use.
> When I change the password for this account in active directory, I also
> changed the password for the services in the Services properties on both
> cluster nodes
> The services Startup Type has to be Manual, or else the following error
> occurs:
> "17050: initerrlog: could not open error log file ... (the correct path
> to the error log follows)"
> The error log is on the shared drive of the cluster.
> Also, when the servers boot up, the following error is in Event Viewer:
> "The Data portion of event 19002 from MSSQLServer is invalid"
> Microsoft (Q230393) says this is a bug and ignore it, but it didn't occur
> until I changed the password.
> Are these normal consequences of changing the account password?
> Are there other steps I should take?
> Thanks
> Bill
>
>

Monday, March 19, 2012

changing sql server account using sem ...

when trying to change the sql server and sql server agent accounts using the
sql enterprise manager what is the syntax for a domain account that should be
used ( i.e. domainname/username, just username, domainname\username, etc... )
? when attempting to add an existing domain account an error message keeps
poping-up that says 'the account (local computername)/accountname is not a
valid windows account' ( for some reason it thinks its a local system account
instead of a domain account ) even though sql server is installed on the pdc.
tia ...
Hello E-Double.
I find it easiest to change the account using the services console (type
services.msc in Start>Run), that way you can browse the network and or check
the name that you enter so it will be prefixed correctly with the domain. I
just find I don't have to think about it this way.
regards,
Mark Baekdal
http://www.dbghost.com
+44 (0)208 241 1762
Database change management for SQL Server
"E-Double" wrote:

> when trying to change the sql server and sql server agent accounts using the
> sql enterprise manager what is the syntax for a domain account that should be
> used ( i.e. domainname/username, just username, domainname\username, etc... )
> ? when attempting to add an existing domain account an error message keeps
> poping-up that says 'the account (local computername)/accountname is not a
> valid windows account' ( for some reason it thinks its a local system account
> instead of a domain account ) even though sql server is installed on the pdc.
> tia ...
|||Yes, but the recommended approach is to do it through EM. This way all of
the necessary permissions and user rights assingments will be given
appropriately. However, using the services msc is an alternative as long as
you follow the KB article that describes manually setting all of the other
requirements.
http://support.microsoft.com/default...b;en-us;283811
Sincerely,
Anthony Thomas

"mark baekdal" <markbaekdal@.discussions.microsoft.com> wrote in message
news:E4E1E754-CEE0-4703-9D8E-537C0994AD47@.microsoft.com...
Hello E-Double.
I find it easiest to change the account using the services console (type
services.msc in Start>Run), that way you can browse the network and or check
the name that you enter so it will be prefixed correctly with the domain. I
just find I don't have to think about it this way.
regards,
Mark Baekdal
http://www.dbghost.com
+44 (0)208 241 1762
Database change management for SQL Server
"E-Double" wrote:

> when trying to change the sql server and sql server agent accounts using
the
> sql enterprise manager what is the syntax for a domain account that should
be
> used ( i.e. domainname/username, just username, domainname\username,
etc... )
> ? when attempting to add an existing domain account an error message
keeps
> poping-up that says 'the account (local computername)/accountname is not a
> valid windows account' ( for some reason it thinks its a local system
account
> instead of a domain account ) even though sql server is installed on the
pdc.
> tia ...
|||Thanks Anthony.
regards,
Mark Baekdal
http://www.dbghost.com
+44 (0)208 241 1762
Database change management for SQL Server
"Anthony Thomas" wrote:

> Yes, but the recommended approach is to do it through EM. This way all of
> the necessary permissions and user rights assingments will be given
> appropriately. However, using the services msc is an alternative as long as
> you follow the KB article that describes manually setting all of the other
> requirements.
> http://support.microsoft.com/default...b;en-us;283811
> Sincerely,
>
> Anthony Thomas
>
> --
> "mark baekdal" <markbaekdal@.discussions.microsoft.com> wrote in message
> news:E4E1E754-CEE0-4703-9D8E-537C0994AD47@.microsoft.com...
> Hello E-Double.
> I find it easiest to change the account using the services console (type
> services.msc in Start>Run), that way you can browse the network and or check
> the name that you enter so it will be prefixed correctly with the domain. I
> just find I don't have to think about it this way.
>
> regards,
> Mark Baekdal
> http://www.dbghost.com
> +44 (0)208 241 1762
> Database change management for SQL Server
>
>
> "E-Double" wrote:
> the
> be
> etc... )
> keeps
> account
> pdc.
>
>

changing sql server account using sem ...

when trying to change the sql server and sql server agent accounts using the
sql enterprise manager what is the syntax for a domain account that should be
used ( i.e. domainname/username, just username, domainname\username, etc... )
? when attempting to add an existing domain account an error message keeps
poping-up that says 'the account (local computername)/accountname is not a
valid windows account' ( for some reason it thinks its a local system account
instead of a domain account ) even though sql server is installed on the pdc.
tia ...Hello E-Double.
I find it easiest to change the account using the services console (type
services.msc in Start>Run), that way you can browse the network and or check
the name that you enter so it will be prefixed correctly with the domain. I
just find I don't have to think about it this way.
regards,
Mark Baekdal
http://www.dbghost.com
+44 (0)208 241 1762
Database change management for SQL Server
"E-Double" wrote:
> when trying to change the sql server and sql server agent accounts using the
> sql enterprise manager what is the syntax for a domain account that should be
> used ( i.e. domainname/username, just username, domainname\username, etc... )
> ? when attempting to add an existing domain account an error message keeps
> poping-up that says 'the account (local computername)/accountname is not a
> valid windows account' ( for some reason it thinks its a local system account
> instead of a domain account ) even though sql server is installed on the pdc.
> tia ...|||Yes, but the recommended approach is to do it through EM. This way all of
the necessary permissions and user rights assingments will be given
appropriately. However, using the services msc is an alternative as long as
you follow the KB article that describes manually setting all of the other
requirements.
http://support.microsoft.com/default.aspx?scid=kb;en-us;283811
Sincerely,
Anthony Thomas
"mark baekdal" <markbaekdal@.discussions.microsoft.com> wrote in message
news:E4E1E754-CEE0-4703-9D8E-537C0994AD47@.microsoft.com...
Hello E-Double.
I find it easiest to change the account using the services console (type
services.msc in Start>Run), that way you can browse the network and or check
the name that you enter so it will be prefixed correctly with the domain. I
just find I don't have to think about it this way.
regards,
Mark Baekdal
http://www.dbghost.com
+44 (0)208 241 1762
Database change management for SQL Server
"E-Double" wrote:
> when trying to change the sql server and sql server agent accounts using
the
> sql enterprise manager what is the syntax for a domain account that should
be
> used ( i.e. domainname/username, just username, domainname\username,
etc... )
> ? when attempting to add an existing domain account an error message
keeps
> poping-up that says 'the account (local computername)/accountname is not a
> valid windows account' ( for some reason it thinks its a local system
account
> instead of a domain account ) even though sql server is installed on the
pdc.
> tia ...|||Thanks Anthony.
regards,
Mark Baekdal
http://www.dbghost.com
+44 (0)208 241 1762
Database change management for SQL Server
"Anthony Thomas" wrote:
> Yes, but the recommended approach is to do it through EM. This way all of
> the necessary permissions and user rights assingments will be given
> appropriately. However, using the services msc is an alternative as long as
> you follow the KB article that describes manually setting all of the other
> requirements.
> http://support.microsoft.com/default.aspx?scid=kb;en-us;283811
> Sincerely,
>
> Anthony Thomas
>
> --
> "mark baekdal" <markbaekdal@.discussions.microsoft.com> wrote in message
> news:E4E1E754-CEE0-4703-9D8E-537C0994AD47@.microsoft.com...
> Hello E-Double.
> I find it easiest to change the account using the services console (type
> services.msc in Start>Run), that way you can browse the network and or check
> the name that you enter so it will be prefixed correctly with the domain. I
> just find I don't have to think about it this way.
>
> regards,
> Mark Baekdal
> http://www.dbghost.com
> +44 (0)208 241 1762
> Database change management for SQL Server
>
>
> "E-Double" wrote:
> > when trying to change the sql server and sql server agent accounts using
> the
> > sql enterprise manager what is the syntax for a domain account that should
> be
> > used ( i.e. domainname/username, just username, domainname\username,
> etc... )
> > ? when attempting to add an existing domain account an error message
> keeps
> > poping-up that says 'the account (local computername)/accountname is not a
> > valid windows account' ( for some reason it thinks its a local system
> account
> > instead of a domain account ) even though sql server is installed on the
> pdc.
> > tia ...
>
>

changing sql server account using sem ...

when trying to change the sql server and sql server agent accounts using the
sql enterprise manager what is the syntax for a domain account that should b
e
used ( i.e. domainname/username, just username, domainname\username, etc...
)
? when attempting to add an existing domain account an error message keeps
poping-up that says 'the account (local computername)/accountname is not a
valid windows account' ( for some reason it thinks its a local system accoun
t
instead of a domain account ) even though sql server is installed on the pdc
.
tia ...Hello E-Double.
I find it easiest to change the account using the services console (type
services.msc in Start>Run), that way you can browse the network and or check
the name that you enter so it will be prefixed correctly with the domain. I
just find I don't have to think about it this way.
regards,
Mark Baekdal
http://www.dbghost.com
+44 (0)208 241 1762
Database change management for SQL Server
"E-Double" wrote:

> when trying to change the sql server and sql server agent accounts using t
he
> sql enterprise manager what is the syntax for a domain account that should
be
> used ( i.e. domainname/username, just username, domainname\username, etc..
. )
> ? when attempting to add an existing domain account an error message keep
s
> poping-up that says 'the account (local computername)/accountname is not a
> valid windows account' ( for some reason it thinks its a local system acco
unt
> instead of a domain account ) even though sql server is installed on the p
dc.
> tia ...|||Yes, but the recommended approach is to do it through EM. This way all of
the necessary permissions and user rights assingments will be given
appropriately. However, using the services msc is an alternative as long as
you follow the KB article that describes manually setting all of the other
requirements.
http://support.microsoft.com/defaul...kb;en-us;283811
Sincerely,
Anthony Thomas
"mark baekdal" <markbaekdal@.discussions.microsoft.com> wrote in message
news:E4E1E754-CEE0-4703-9D8E-537C0994AD47@.microsoft.com...
Hello E-Double.
I find it easiest to change the account using the services console (type
services.msc in Start>Run), that way you can browse the network and or check
the name that you enter so it will be prefixed correctly with the domain. I
just find I don't have to think about it this way.
regards,
Mark Baekdal
http://www.dbghost.com
+44 (0)208 241 1762
Database change management for SQL Server
"E-Double" wrote:

> when trying to change the sql server and sql server agent accounts using
the
> sql enterprise manager what is the syntax for a domain account that should
be
> used ( i.e. domainname/username, just username, domainname\username,
etc... )
> ? when attempting to add an existing domain account an error message
keeps
> poping-up that says 'the account (local computername)/accountname is not a
> valid windows account' ( for some reason it thinks its a local system
account
> instead of a domain account ) even though sql server is installed on the
pdc.
> tia ...|||Thanks Anthony.
regards,
Mark Baekdal
http://www.dbghost.com
+44 (0)208 241 1762
Database change management for SQL Server
"Anthony Thomas" wrote:

> Yes, but the recommended approach is to do it through EM. This way all of
> the necessary permissions and user rights assingments will be given
> appropriately. However, using the services msc is an alternative as long
as
> you follow the KB article that describes manually setting all of the other
> requirements.
> http://support.microsoft.com/defaul...kb;en-us;283811
> Sincerely,
>
> Anthony Thomas
>
> --
> "mark baekdal" <markbaekdal@.discussions.microsoft.com> wrote in message
> news:E4E1E754-CEE0-4703-9D8E-537C0994AD47@.microsoft.com...
> Hello E-Double.
> I find it easiest to change the account using the services console (type
> services.msc in Start>Run), that way you can browse the network and or che
ck
> the name that you enter so it will be prefixed correctly with the domain.
I
> just find I don't have to think about it this way.
>
> regards,
> Mark Baekdal
> http://www.dbghost.com
> +44 (0)208 241 1762
> Database change management for SQL Server
>
>
> "E-Double" wrote:
>
> the
> be
> etc... )
> keeps
> account
> pdc.
>
>

Changing SQL Domain Account

I need to change the domain account our SQL cluster is running under. The
cluster is Win2k with a single instance of SQL 2000.
I looked in the cluster Administrator and I don't see where it is specified.
Do I use the services applet in control panel to specify the user for
cluster service? I found for SQL in Enterprise manager I can specify the
user there. Is that where I change the SQL user?
I'm thinking...
- Change the user for SQL in Enterprise Manager
- Stop SQL and the Cluster Service
- Change the user for Cluster Service in Control Panel
- Restart Cluster Service
- Restart SQL
Would this be right? Thanks in advance.
You are in luck. Microsoft has a document detailing exactly how to do this.
How to change service accounts for a clustered SQL Server computer
http://support.microsoft.com/kb/239885/en-us
Geoff N. Hiten
Senior Database Administrator
Microsoft SQL Server MVP
"Sam" <sam@.nospam.com> wrote in message
news:AqaZf.3719$i41.904@.newsread1.news.atl.earthli nk.net...
>I need to change the domain account our SQL cluster is running under. The
> cluster is Win2k with a single instance of SQL 2000.
> I looked in the cluster Administrator and I don't see where it is
> specified.
> Do I use the services applet in control panel to specify the user for
> cluster service? I found for SQL in Enterprise manager I can specify the
> user there. Is that where I change the SQL user?
> I'm thinking...
> - Change the user for SQL in Enterprise Manager
> - Stop SQL and the Cluster Service
> - Change the user for Cluster Service in Control Panel
> - Restart Cluster Service
> - Restart SQL
> Would this be right? Thanks in advance.
>
>
|||Thanks for the link. I'm trying to verify if the policies specified in the
article are indeed set for the new account we plan to use. We have already
setup a new Win_2003/SQL_2005 cluster with the new account so my guess it
the account is ok and ready to go.
The article doesn't really give a process however, other than making sure
the change to the SQL service is made with Enterprise Manager. I'm still
not sure where to change the cluster service account, except to guess about
using the Services applet in Control Panel. Is this right?
"Geoff N. Hiten" <SQLCraftsman@.gmail.com> wrote in message
news:%23$u90$YWGHA.4768@.TK2MSFTNGP05.phx.gbl...
> You are in luck. Microsoft has a document detailing exactly how to do
this.[vbcol=seagreen]
> How to change service accounts for a clustered SQL Server computer
> http://support.microsoft.com/kb/239885/en-us
> --
> Geoff N. Hiten
> Senior Database Administrator
> Microsoft SQL Server MVP
>
> "Sam" <sam@.nospam.com> wrote in message
> news:AqaZf.3719$i41.904@.newsread1.news.atl.earthli nk.net...
The[vbcol=seagreen]
the
>
|||Enterprise Manager lets you change the SQL service account directly. Do not
use the services applet to change account information in a clustered
environment. EM sets the account properties correctly on each node when you
make the change. EM is also cluster-aware and changes all the nodes at
once.
Geoff N. Hiten
Senior Database Administrator
Microsoft SQL Server MVP
"Sam" <sam@.nospam.com> wrote in message
news:JzbZf.1275$Es3.1066@.newsread3.news.atl.earthl ink.net...
> Thanks for the link. I'm trying to verify if the policies specified in
> the
> article are indeed set for the new account we plan to use. We have
> already
> setup a new Win_2003/SQL_2005 cluster with the new account so my guess it
> the account is ok and ready to go.
> The article doesn't really give a process however, other than making sure
> the change to the SQL service is made with Enterprise Manager. I'm still
> not sure where to change the cluster service account, except to guess
> about
> using the Services applet in Control Panel. Is this right?
>
> "Geoff N. Hiten" <SQLCraftsman@.gmail.com> wrote in message
> news:%23$u90$YWGHA.4768@.TK2MSFTNGP05.phx.gbl...
> this.
> The
> the
>

Sunday, March 11, 2012

Changing sa SQL 2005

I have changed my sa password on the database SQL 2005. I have also changed the DOMAIN\Account account from our Active Directory.

Then I went into SQL Server Configuration Manager and changed the SQL Server Broswer to the new DOMAIN\Account and I also changed the SQL Server Agent (MSSQLSERVER) to the new DOMAIN\Account.

Now I think I got everything covered. But my jobs are failing. Even though the Owner of the Job is DOMAIN\Account i get a

".. Description: System.Runtime.InteropServices.COMException (0x80040E4D): Login failed for user 'sa'. ..."

thank you

Check the job to see if it is running as sa and if it is make sure that the password is the same as the password you selected for sa when you changed it.

HTH,

-Steven Gott

SDE/T

SQL Server