Rights for a DBA
Windows Server Forum Index Windows Server
Server discussion on Windows platform.
 
 FAQFAQ   MemberlistMemberlist     RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 
 
Google
 
Web winserverhelp.com
Rights for a DBA

 
Post new topic   Reply to topic    Windows Server Forum Index -> Security
Author Message
Dave Morrow
Guest





Posted: Fri Nov 11, 2005 8:35 am    Post subject: Rights for a DBA Reply with quote

Hi all. I've run into a rather perplexing problem with respect to giving
access rights to a DBA. I have given the DBA System Administrator rights
within SQLServer 2000 which is running on the server but would prefer to not
give him Administrator rights to the Windows 2000 server itself.
Unfortunately, he needs to be able to stop and start the SQL Server services
(SQLServer and SQLServerAgent). Does anyone know how I can achieve this
without granting full administrator rights to the server?
Back to top
Steven L Umbach
Guest





Posted: Fri Nov 11, 2005 5:50 pm    Post subject: Re: Rights for a DBA Reply with quote

I am not an SQL guy :( but you can use utilities such as subinacl or setacl
[free third party] to change permissions on a service. Just be careful
because you want to probably edit the permissions and not replace then with
just that user account. The links below explains more and Group Policy is
another alternative. The mmc snapin for Security Configuration and Analysis
is a good way to see actual service permissions by doing an "analysis"
against some template if you want to verify results. You can do that with
subinacl but the output is rather user unfriendly unless you are used to
it.--- Steve

http://support.microsoft.com/default.aspx?scid=kb;en-us;288129
http://www.microsoft.com/technet/prodtechnol/windows2000serv/howto/seconfig.mspx
Back to top
Roger Abell [MVP]
Guest





Posted: Sat Nov 12, 2005 9:50 pm    Post subject: Re: Rights for a DBA Reply with quote

You can do as Steve has said to give them start/stop etc permissions
on the services of SQL, and also make sure that you have given them
permissions on the storage areas the SQL Server uses as they will
need this for creating new databases.
If you really, really want to make sure they are restricted from having
admin capability on the machine, then you must make sure that SQL
Server is not configured to run as Local System.
Back to top
S. Pidgorny
Guest





Posted: Sun Nov 13, 2005 9:50 am    Post subject: Re: Rights for a DBA Reply with quote

Nor is SQL Agent!

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-
Back to top
 
Post new topic   Reply to topic    Windows Server Forum Index -> Security All times are GMT
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum




New Topics Powered by phpBB