Solved

Ability to Apply Group Policy allowing access to SQL Enterprise management console

Posted on 2006-11-10
1
471 Views
Last Modified: 2013-12-03
I have a group of users who must be able to access the SQL Enterprise Management Console from their own machines to see DBs on the network. I only want them to be able to see just this console and not be able to open any other mmc. I do not see a specific extension console to enable in the GPO. Is there any way to do this without openning the whole flood gate of mmc consoles. i want to keep the environment restricted from this. Please HELP!!

0
Comment
Question by:pterranova13
1 Comment
 
LVL 83

Accepted Solution

by:
oBdA earned 500 total points
ID: 17917992
Save the following (from and including "CLASS USER") as MMC-SQLSnapIn.adm (or whatever.adm), and import it into the group policy editor. You can then allow the SQL manager (you'll find the entry under "Additional Settings").
You might have to remove line breaks in the "MMC_Restrict_Explain" string.
Restrict_Run
http://www.microsoft.com/technet/prodtechnol/windows2000serv/reskit/regentry/93792.mspx?mfr=true

CLASS USER

CATEGORY !!AdditionalSettings
 CATEGORY !!MMC
  CATEGORY !!MMC_RESTRICT
   POLICY "SQL Enterprise Manager"
    KEYNAME "Software\Policies\Microsoft\MMC\{00100100-1816-11d0-8EF5-00AA0062C58F}"
    EXPLAIN !!MMC_Restrict_Explain
    VALUENAME "Restrict_Run"
    VALUEON NUMERIC 0
    VALUEOFF NUMERIC 1
   END POLICY
  END CATEGORY
 END CATEGORY
END CATEGORY

[strings]
AdditionalSettings="Additional Settings"
MMC="Microsoft Management Console"
MMC_RESTRICT="Restricted/Permitted snap-ins"
MMC_Restrict_Explain="Permits or prohibits use of this snap-in.\n\nIf you enable this setting, the snap-in is permitted. If you disable the setting, the snap-in is prohibited.\n\nIf this setting is not configured, the setting of the "Restrict users to the explicitly permitted list of snap-ins" setting determines whether this snap-in is permitted or prohibited.\n\n--  If "Restrict users to the explicitly permitted list of snap-ins" is enabled, users cannot use any snap-in except those explicitly permitted.\n\n    To explicitly permit use of this snap-in, enable this setting. If this setting is not configured (or disabled), this snap-in is prohibited.\n\n--  If "Restrict users to the explicitly permitted list of snap-ins" is disabled or not configured, users can use any snap-in except those explicitly prohibited.\n\n    To explicitly prohibit use of this snap-in, disable this setting. If this setting is not configured (or enabled), the snap-in is permitted.\n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear."
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
GPO Access denied in AD 12 36
Dentrix G4 1 32
OPINIONS please : best Active Directory Monitoring tool 5 74
AD Replications issues 12 50
The HP utility "HP Lights-Out Online Configuration Utility for Windows Server 2003/2008" could be of great use when it comes to remotely configure a HP servers ILO WITHOUT rebooting the server. We would only need to create and run scripts using thi…
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now