Re: Confused about Windows Authentication



JT
Is there a better way to approach this? If not, is there an
explanation on how to set up the user accounts that is better than
what I found in the help files? If I'm using Windows Authentication,
is it possible to have the application use a specific, unrestricted
account when the normal accounts for Windows logins are restricted to
just reading?

I think you on the right way. As I understood you cannot (at least I'm not
aware of) have two logins connected by one connection string , I mean to
activate the unrestricted account you will have to open a new connection
for him/her.
Have a look at application role to be activate by the application.
http://sqlcat.com/whitepapers/archive/2007/12/16/sql-server-2005-security-best-practices-operational-and-administrative-tasks.aspx



"JT" <jt@xxxxxxxxxxx> wrote in message
news:a937c621-3f48-47c9-996f-858635c2f937@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hi,

I read in the help file for MSSQL 2005 that Windows Authentication is
better than SQL Server authentication. Okay. So here's my scenario
and what I think I should do. Hopefully, you can offer me some
advice.

I have an application that interfaces with 2 MSSQL 2005 databases and
a DB2 database. For this example, I'll call them Master, Aux1 and
Aux2. Master contains most of the data and is MSSQL 2005. Aux1 is
MSSQL 2005 and contains a view that I need to read. Aux2 is DB2 and
contains 2 views. One is accessed directly. The other will be DTS'd
into a table in Master. I don't want the connection strings available
to the end-user, but I want to be able to change connection strings so
that the application is configurable to other databases. What I want
to do is

1) Create a user account in Master that gives it the rights to do
whatever is necessary. The application will restrict each user based
on Windows Authentication. I can secure this one connection string.

2) Create a table for storing the Aux1 and Aux2 connection strings
that can only be accessed by the account in step 1. Running the
application will give the appropriate users the rights to run the
forms for changing this table via the database user account.

This way the application can be ported to use different Aux1 and Aux2
databases but changing the connection strings cannot be done through
SQL Server Management Studio by just anyone with a valid Windows
login.

Is there a better way to approach this? If not, is there an
explanation on how to set up the user accounts that is better than
what I found in the help files? If I'm using Windows Authentication,
is it possible to have the application use a specific, unrestricted
account when the normal accounts for Windows logins are restricted to
just reading?

Thanks,

JT


.



Relevant Pages

  • Re: Confused about Windows Authentication
    ... appears that Windows Authentication or Mixed Mode is set at the server ... explanation on how to set up the user accounts that is  better than ... account when the normal accounts for Windows logins are restricted to ... but I want to be able to change connection strings so ...
    (microsoft.public.sqlserver.security)
  • Re: Thinking of reinstalling Windows...
    ... i've made several user accounts in that time. ... created a new limited user account. ... - the prototype per-user registry gets corrupted ... Classes from HKLM with the account-specific Classes from HKCU. ...
    (microsoft.public.windowsxp.general)
  • Re: Share or Sync the same data / same identity between Multiple Users, multiple computers.
    ... I want two User Accounts to share the same Entourage 2004 database. ... account and just use the Admin User account for myself on a daily ...
    (microsoft.public.mac.office.entourage)
  • VB.NET Standard 2003 installation ruined my XP Home system!
    ... new profile of "Uknown Account." ... In Control Panel, User Accounts, ... with total CPU usage at 100%. ... Microsoft Office 97, Professional Edition ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: SP2 and rebooting
    ... That should bring up the old style Windows login ... If you know the administrator account password, ... If you can gain access, go to Control Panel, User Accounts, and see if your ...
    (microsoft.public.windowsxp.help_and_support)