Re: SQL DBA Permissions

From: Andrew Mitchell (amitchel_at_removecasey.vic.gov.au)
Date: 03/26/04


Date: Fri, 26 Mar 2004 06:05:03 -0800


"Oli Restorick [MVP]" <oli@mvps.org> said

> You are talking about the account your DBA uses to log on and not the
> SQL Server service account (which requires surprisingly low privileges
> at the machine it's running on), aren't you?
>

While we're on the subject, what permissions does the service account for SQL
require?
I recently attended the MS security presentation in Melbourne, and we were
advised that the service acct only needs restricted privileges, but I have
been unable to find out exactly what it needs.

It would be nice if MS provided a web page stating what the various services
(SQL, Exchange, SMS etc.) need in order to operate correctly. Having it all
listed on one page would make it very convenient.

Andy.



Relevant Pages

  • Re: SPN for SSL over common name
    ... you can't register those SPNs under the SQL Server's ... service account is the MSSQL SPN. ... That SPN should be registered under ... Lastly, since the SQL Server is not being used for delegation anywhere, ...
    (microsoft.public.inetserver.iis.security)
  • Cannot Use Non-Administrator Account to Start SQL Server and Force Encryption
    ... I changed the service account of a named instance (product ... a certificate from a Microsft Certificate Server ... the SQL Service. ... SQL Server could not spawn FRunCM thread. ...
    (microsoft.public.sqlserver.security)
  • Re: Builtin Administrators Group and SQL Agent Jobs
    ... > I checked and 'Change a process level token' and 'Act as> part of the OS' were not granted to the service account. ... >>> All jobs are owned by SA and the problem remains. ... >>>>> for DBA's and gave that login full access to all SQL ...
    (microsoft.public.sqlserver.security)
  • Re: Delegation problems
    ... I did a search for the SPN and it came back with two ... When the SQL server was initially setup (by a FORMER ... administrator) he used his account as the service account for SQL ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Alerts not coming thru
    ... So I Do NOT use the Network Service account. ... change to a different account as something is odd in my AD and can't get SQL ... have set for the IIS App Pool I am using for Sharepoint (Not the Network ... >>> confirmation email never arrives hence the alerts never arrive. ...
    (microsoft.public.sharepoint.windowsservices)