.NET Tutorials, Forums, Interview Questions And Answers
Welcome :Guest
Sign In
Register
 
Win Surprise Gifts!!!
Congratulations!!!


Post New Web Links

Unauthorized SQL Server Account can shut down sql server

Posted By:      Posted Date: October 28, 2010    Points: 0   Category :Sql Server
 
SQL Server 2008 R2 RTM build (Standard Edition)

SQL Server account has following rights as per select * from fn_my_permissions(null, 'server')
server CONNECT SQL
server VIEW ANY DATABASE

However, when connecting via SSMS as the above mentioned user - I can shutdown SQL Server,

I have tried deny & revoke shutdown to no effect

this account is by default a member of public server role

Public server role has got connect on endpoints

Any advice?

Thank you



View Complete Post


More Related Resource Links

[SSRS 2008 R2]Report Builder Access error-The remote server returned an error: (401) Unauthorized.

  
Hello,        I am able to login Web Service URL and report manager using computer name and report builder is also working fine.  http://RPTSRV/reportserver   (RPTSRV is report server name. web service url working fine. all accessible) http://RPTSRV/reports  (report manager working fine and all accessible ,report builder too) It means I am able to access everything locally right? http://rs.test.abc.com/reportserver  (web service url working fine. all accessible)  http://rs.test.abc.com/reports    (Report manager working fine and all accessible accept report builder)(I carefully checked the link and its taking rs.test.abc.com/reportserver.....)     when I click on reportbuilder button in report manager it shows me error dialog box with following error log!! I tried from local and remote computer too but gives the same error both side. I am not sure but I am just thinking is this double hop kerberos security issue? Please help me to solve this problem. I am finding solution from last 4 days. Reporting Service configuratin tool settings Web Serivice URL -  all set to default Report Manager URL - all set to default Environment - Distributed deployment Server1(report_srv) --Windows server 2003, Installed sql server 2008R2 reporting service,

Enabling SA account on SQL Server 2008 R2

  
Hi I'm setting up a SharePoint 2010 development machine and hit a snag. I installed SQL Server 2008 R2 with the default instance (devserv1\mssqlserver). That's configured for mixed mode authent and I can login using either Windows Auth or SA no worries. Note that it's just a local machine account and NOT a domain account (this is an isolated VM with no domain) I installed SharePoint 2010 on the machine. I don't recall changing any settings and during the install, it has created a new instance called devserv1\sharepoint. I can login to it using Windows Authentication, but I don't appear to have any permissions. Also, the SA user is disabled, but I can't enable it, because I get a permissions error when using my windows account to do it... One thing I noticed that is a bit weird is the version numbers of the 2 instances - the first/default instance is 10.5.0.* whereas the one created by SharePoint install is 10.0.0.2513 or thereabouts - i.e., it's SQL 2008 but not R2 which I don't reallty understand. Anyway, how can I enable the sa account on the sharepoint instance? Thanks.weirdbeardmt, PhD, BSc. Silly name, but lots of letters.

SQL Agent - service account permissions - SQL Server 2008

  
Hi @ all   I installed two SQL Server 2008 on Server 2008 R2 Std (principal and mirror) and an AD Server 2008, with sperate service accounts, connect as SA, localy all works fine. I created some agent tasks (PowerShell, T-SQL), but I get some Error massages in the history, that service account of SQL Agent didn't have the permission to query a remote machine(access denied for wmi (HRESULT: 0x80070005 (E_ACCESSDENIED)) and linked database(SQLSTATE 42000 Error(7314)). The simple query with SA permissions on the remote machine works and the powershell scripts with the local domain user works too. But not with the SQL Agent. WHY?? Where ist the different between the user account permisions and service account permissions? Which settings are needed? Example: get-wmiobject -class win32_service -computername 192.168.xxx.xxx| where {$_.name -like '*SQL*'} Powershell Console: works                                     SQL Agent Job: access denied I tried some solutions with user rights, group policies and security permissions but nothing works. like: Configuration -Service Accounts, SQL Server or SQL Server Agent service account http://support.microsoft.com/kb/283811/en-us http://msdn2.microsoft.com/

How to impersonate a connection to SQL server under IIS app pool account if Windows Authentication i

  
I have a requirement I should connect to MS SQL server under IIS Application pool account from ASP.NET application where Windows Authentication is enabled. I cannot use user name and password in connection string. ASP.NET application should use Entity Framework 4.0 to work with data. Any ideas how to do it?    

Failed to change Farm Account in Sharepoint 2010 server, now Central Administration is not accessibl

  
Hello, I have a problem, that I no longer can access Central Administration Website, only the Sharepoint itself. I was running installation of Sharepoint 2010 Server with administrative account ImTheAdmin, who is a Domain Admin in the domain on one of the Windows 2008 R2 member servers. Besides that, I made ImTheAdmin the primary administrator of the Sharepoint. ImTheAdmin became the only user of this Sharepoint 2010 server after installation.  I installed everything on one box with default installation settings. I used builtin SQL server, not Standard or Enterprise. What then happened is: Using ImTheAdmin account, I opened Central Administration Website, and it said, that I need to change the Farm Account, for the account for Farm was the default one (I think it was network service). So I created a regular domain user MYDOMAIN\SharepointFarmAccount. The account name was too long to be as a Windows 2000 name, so it showed there without last 't', e.g. MYDOMAIN\SharepointFarmAccoun. I thought, Windows 2000 is long gone, so I didn't pay much attention, I think everywhere the account SID is important. I don't know if that is the real problem with my failure later, but it might be one of the reasons. I put MYDOMAIN\SharepointFarmAccount down in to the form of Central Administration Website, added the check mark, that it would react to password changes, and pre

Same server farm administrator domain account for both Intranet and Internet Sharepoint site?

  
Hello,   We are planning to setup 2 streams of architecture for both Intranet and Internet web sites. Just wondering whether there is any best practices/security concerns if we are using the same domain account as the Server Farm Administrator for both Intranet and Internet platform?   Thanks,

Service Account for SQL Server 2000 Cluster

  
Dear All, One of my customer is running a active/active SQL 2000 cluster in Windows 2003 and the service account for one of the instance is LocalSystem account. I am not sure how they changed the service account to localsystem because SQL Server doesn't allow LocalSystem account as your service account when you install it on a cluster and it doesn't allow to change the service account to LocalSystem account in Enterprise Manager when running in a cluster. I searched for documentation to findout whether Microsoft supports running SQL Server using LocalSystem account in a cluster but I am unable to find a documentation. Please help me to identify the documentation regarding the support or share your experience Regards BalajiRegards,Balaji, Please mark as answer if you think this answers your questions

SQL SERVER 2005/2008 Proxy Account Set up

  
Hi All,I need to clear the logic behind Proxy account in SQL server 2005/2008.1.If i want to create a proxy account to run the xp_cmd shell system stored procidures ?2.And if i want to run the job steps what i understand here is:For:1 .above we can create a SQL/Windos Login and we can map this login to master database. it will create a user in master database, and we can aisign this user in master database xp_cmd shell extended strored procidure access from the securibles node or by running the scripts, however if this login/user dont have sysadmin access he can not run the xp_cmdshell extended stored prcidure in sql server query analyzer to achieve this task we need to create a credential using the EXEC sp_xp_cmdshell_proxy_account 'Windows LOGIN NAME','Password'.Here 'Windows LOGIN NAME' can be any windows account having least privilage(can not have syadmin privilage).For 2:To Run job steps using proxy account is where we have to use gui(off course ready scripts also)  but for that we need to create a cridential first if you are using gui:a) give name of cridentaial b) choose any windows account(haveing no sys admin access) and give the password for this windows account, make sure you are giving the correct password here.so now credentail part is done now go to proxy under sql server agentright click on proxy> new proxy> give a name to proxy, in credenti

SQL Server broken - cannot reset 'logon as ' built-in account - urgent

  

 

SQL Server Express 2008, on a standalone XP Pro fully updated, with a named instance of COMPUTERNAME\SQLEXPRESS.

As installed, the 'log on as' was set to NT\NETWORK SERVICE. Basically things worked, though I had some issues, now irrelevant. Foolishly I went into SQL Server Configuration Manager, clicked on SQL Server Services, in the right pane right-clicked on Sql Server (SQLEXPRESS) - Properties, on the logon tab - Built-in account, which showed Network Service.

 

From the dropdown, I selected Local Service and probably Apply, then Start, though maybe vice versa.

 

This stopped pretty much everything working, e.g. no access via Managment Studio etc (cannot login). Now if I attempt to select Network Service from the dropdown to put it back to what it was:

- If I click Apply I get a message box : Cannot find object or property [0x80092004]

- If I click Start there is a long wait while the progress bar ticks over, then a message box with 'The request failed or the service did not respond in a timely fashion. Consult the event log or other applicable error logs for details'

 

In the logs folder the log starts with informational stuff that looks to me to be pretty

Login failed for user 'XXX'. Reason: Attempting to use an NT account name with SQL Server Authenti

  

Under a network service account. I want to perform some operations on the SQL server DB.

I am passing the user id and password of the admin on that box. Still I am getting Login failed for user 'XXX'. Reason: Attempting to use an NT account name with SQL Server Authentication.

Is there any way i can connect to Sql server with user id and password?

Connection string i am using is Data Source=imdbstrs22;Initial Catalog=DataStore;Integrated Security=false;user Id=XXX;password =Imdbaug#10;

 

 

 

 


Error during installation of SQL Server 2005 when typing the domain account

  

I am installing SQL Server 2005 on a server (Windows Server Enterprise Edition 2003 SP2) that is not domain controller and on the screen "Service Account" I checked the box "Customize for each service account" and typed a domain account (it has permission to "logon as a service"), its password and domain, and when I click the "Next" button, I am getting the error below:

"SQL Server Setup could not validate the service accounts. Either the service accounts have not been provided for all of the services being installed, or the specified username or password is incorrect. For each service, specify a valid username, password, and domain, or specify a built-in system account. "

What's happening? Why is this error occurring? What I have to do for this error does not occur?

Thanks for any help me to solve this problem

(Note : Excuse me because my English isn't very good !)

 


Error during installation of SQL Server 2005 when typing the domain account

  

I am installing SQL Server 2005 on a server (Windows Server Enterprise Edition 2003 SP2) that is not domain controller and on the screen "Service Account" I checked the box "Customize for each service account" and typed a domain account (it has permission to "logon as a service"), its password and domain, and when I click the "Next" button, I am getting the error below:

"SQL Server Setup could not validate the service accounts. Either the service accounts have not been provided for all of the services being installed, or the specified username or password is incorrect. For each service, specify a valid username, password, and domain, or specify a built-in system account. "

What's happening? Why is this error occurring? What I have to do for this error does not occur?

Thanks for any help me to solve this problem

 


SQL Server Reporting Service 2008 R2 - The request failed with HTTP status 401: Unauthorized.

  
I got the error "The request failed with HTTP status 401: Unauthorized." when I call the Reporting Service Web Service.

The code is very simple:

// Initialise the reporting service Web Service

this.RSWebService = new ReportingService2010();

// Pass windos authentication credentials to Web Service

this.RSWebService.Credentials = System.Net.CredentialCache.DefaultCredentials;

// List children

List<CatalogItem> reports = this.RSWebService.ListChildren(folder, false).ToList();

The SQL Server is installed on a different machine (say server A) from the Web server (say server B). We are using Windows Server 2003.

The code work fine for all the scenario below:

i) Run locally (XP) to call the web service on the sql server

ii) Provide the Network Credentials with the username, password, and domain when calling the web service

iii) If the web server and sql server is using same server (i.e. not distributed)

I'm using windows authentication and impersonation. Any idea?


The remote server returned an error: (401) Unauthorized. Failed to execute web request for the speci

  

Hi,

I am creating reports using SQL business intelligence 2008.

Connection string 'http://<SharepointServer>/_vti_bin/lists.asmx '.

And i have created a data set using the below xml query.

<Query>
   <SoapAction>http://schemas.microsoft.com/sharepoint/soap/GetListItems </SoapAction>
   <Method Namespace="http://schemas.microsoft.com/sharepoint/soap/ " Name="GetListItems">
      <Parameters>
         <Parameter Name="listName">
            <DefaultValue>{GUID of the list}</DefaultValue>      
         </Parameter>      
      </Parameters>
   </Method>
   <ElementPath IgnoreNamespaces="True">*</ElementPath>
</Query>

 

When I try to execute th

NT Authority \System Account Having SysAdmin Server Role

  

Looking to tighten security access to a SQL Server 2008 instance based on Windows 2003 Server clusters.

Is their any downside risk to revoking the sysadmin role from this account?  We've established all our services to run under domain service accounts we had set up.

Are there features or functions in SQL 2008 that depend on this account being present and having elevated priviledges?

 

thks

 


SQL Job not able to sen email after SQL Server Service Account change

  

Hi,

I changed on the SQL Server service account to a least priviledge domain user.  However after the change, one of my sqljob which use sp_send_dbmail is not functioning. after checking on the log, it mentioned no permission. i tried to set the MSSQLUser Group as db_owner of msdb database, but it was not helping. When i set the MSSQLUser group as sysadmin ,then only the job able to send email. what could be the least priviledge of the service account so that i able to send email via sql job?


Sharepoint Search Server Express 2008 can not index external domain fileshare with valid account

  

Since i have understood that sharepoint 2008 search express doesn't do any security trimming i am trying to index an external fileshare (on a non trusted domain) with it. After authenticating with the external domain account I can manually access all the files in that share i need to. Sharepoint 2008 search express somehow is unable to use the crawl rule in which i specified a different content access account (which is the external domain account).It continuously gives the error "Access is denied. Check that the Default Content Access Account has access to this content, or add a crawl rule to crawl this content."

Exactly the same configuration works fine with sharepoint search server 2010, but that does do security trimming and because of the share being completely external my users could't see any search results.

Any suggestions?



Categories: 
ASP.NetWindows Application  .NET Framework  C#  VB.Net  ADO.Net  
Sql Server  SharePoint  Silverlight  Others  All   

Hall of Fame    Twitter   Terms of Service    Privacy Policy    Contact Us    Archives   Tell A Friend