Solved

Where do I create SQL Server Service Accounts?

Posted on 2009-05-17
5
420 Views
Last Modified: 2012-05-07
Hi

When setting up an account for each SQL Server Service are these created in the - SBS Users  - or - Users - part of Active Directory?

Does it matter?

Regards
William

AD.bmp
0
Comment
Question by:Whisky-Will
  • 2
  • 2
5 Comments
 
LVL 3

Assisted Solution

by:ddanonimity
ddanonimity earned 50 total points
ID: 24406464
I would say it doesn't matter  as long as you make sure they have the correct permissions for the account to run the required service
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 24406527
I've see a lot of organizations create an OU called "service accounts"
That way if you are ever making modifications it is really easy to exclude those accounts in that OU.
You could also add something to the description maybe like "serviceAccount"
Thanks
Mike
0
 

Author Comment

by:Whisky-Will
ID: 24406600
Hi
I have found some more information.
SBS USers: Default organisational unit for user accounts created with the Add New User Account wizard
Users: Default container for upgraded user accounts
As I created these accounts without using the Add New User wizard it looks like I should have created them in Users. Now when I try and move them I get a warning that If I move them things might not work because of the way group policies are applied.
Since being advised on this site to create separate accounts for each SQL service I just seem to be digging a bigger and bigger hole that I cant get out of.
At what level in my diagram should I create the new OU "Service Accounts" and can I ignore the error message and move the accounts there?
Regards
0
 
LVL 57

Accepted Solution

by:
Mike Kline earned 450 total points
ID: 24406612
We have our service accounts at the root so right click on the domain and select new OU
yes you can ignore the group policy warning, you shouldn't have issues there.
Thanks
Mike
0
 

Author Closing Comment

by:Whisky-Will
ID: 31582378
Thanks for your help guy's
0

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This article runs through the process of deploying a single EXE application selectively to a group of user.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question