Is there a Security Tool to verify or debug access?

From: Stephanie (stephanie.harrell_at_stateauto.com)
Date: 07/29/03

  • Next message: Kevin: "Re: Valid port ranges for SQL Server 2000"
    Date: 29 Jul 2003 07:41:32 -0700
    
    

    Is anyone aware of a tool or utility or proc that can help debug SQL
    Security? We use Active Directory "groups" of Windows logins to give
    users authority in SQL. I'm trying to find out why a user can delete
    records when I don't think he should. For example

    John Smith can delete a record from TableA. He is in a group called
    "Security B" which has db_readonly role assigned, yet he can still
    delete records. Obviously he is in another group with more authority,
    but which one? He could also be a member of a group with SysAdmin
    authority, so just looking at table permissions doesn't work either.

    Is there anything out there where you can "verify" and id and it's
    access or track how an id gains access. Sql has to do the work anyway
    to resolve the permissions, there ought to be a way to report it.

    Let me type in a userid, table and function and it report "yes -
    granted by membership in 'groupname'" or "no - denied by ......"


  • Next message: Kevin: "Re: Valid port ranges for SQL Server 2000"

    Relevant Pages

    • Re: Is there a Security Tool to verify or debug access?
      ... > Is anyone aware of a tool or utility or proc that can help debug SQL ... Obviously he is in another group with more authority, ... > access or track how an id gains access. ... there ought to be a way to report it. ...
      (microsoft.public.sqlserver.security)
    • Over-Protected
      ... any different permissions. ... looks like it has to do with standard SQL security. ... >restrictions of the Windows NT Authority on the network. ...
      (microsoft.public.sqlserver.security)
    • Re: HELP! Cant change crystal report database source dynamically!
      ... The connection you initially set the report up with must use windows ... security if you're to use that or sql if you're using a specific user. ... This uses windows security. ...
      (microsoft.public.vb.crystal)
    • Re: Populating a list -- table structure?
      ... I had made a report already and figured out about adding the ... your responce below, but thanks to your help with SQL, I was able to get the ... It takes a summary from a select query and gives the ... KitID, long integer ...
      (microsoft.public.access.forms)
    • RE: SQL Slammer doing the rounds again?
      ... SQL Slammer doing the rounds again? ... "I used to hate writing assignments, ... > Security Business Unit ... > at the largest, most highly-anticipated industry ...
      (Incidents)