New nt account to replace builtin admin

Posted on 2006-05-26
Last Modified: 2008-03-06
If i set up a new domain account to start SQL and remove builtin/admins

The new ntdomain/sqlstartup account in Windows NT
does this need to be part of domain admins.
and the nt authority\network sevice   (anyone know what this is ?)
Question by:TRACEYMARY
    1 Comment
    LVL 5

    Accepted Solution

    I know for sure that microsoft does not recommend that you run SQL Server with domain admin or even local admin permissions.

    If you do not want the SQL Server or the SQL Server Agent startup account to be a member of the Local Administrators Group , then the startup account for the MSSQLServer service and the SQLServerAgent service (either a local Windows NT account, or a domain Windows NT account) must have these user rights:
    • Act as Part of the Operating System = SeTcbPrivilege  
    • Bypass Traverse Checking = SeChangeNotify  
    • Lock Pages In Memory = SeLockMemory  
    • Log on as a Batch Job = SeBatchLogonRight  
    • Log on as a Service = SeServiceLogonRight  
    • Replace a Process Level Token = SeAssignPrimaryTokenPrivilege  

    All that we need to give are the above permissions (of course the full permissions on binaries and the datafiles).
    Just a point here -- if SQL is running on cluster and we plan to remove builtin/admin -- do not forget to add cluster service startup account as a login under SQL.. other wise sql would fail to come online.


    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    IT, Stop Being Called Into Every Meeting

    Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

    This article describes some very basic things about SQL Server filegroups.
    SQL Command Tool comes with APEX under SQL Workshop. It helps us to make changes on the database directly using a graphical user interface. This helps us writing any SQL/ PLSQL queries and execute it on the database and we can create any database ob…
    Video by: Steve
    Using examples as well as descriptions, step through each of the common simple join types, explaining differences in syntax, differences in expected outputs and showing how the queries run along with the actual outputs based upon a simple set of dem…
    Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

    737 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    16 Experts available now in Live!

    Get 1:1 Help Now