Solved

SQL - Grant group access to database fails

Posted on 2013-06-11
5
318 Views
Last Modified: 2013-08-06
Hoping someone can help me out here.

I've create a database in SQL 2005 and need to have users access it via Excel.
If I gran login access to a user account, excel quite happily connects, all is good.

I however want to grant access with an AD global group instead of per user.  When I do so, using the same server & database permissions, Excel gives me a login failed.

To be clear, I'm assigning my database as the default database in the General tab.
Server Roles - Public (default)
User Mapping - public, db_datareader

In the server event log I get a Failure Audit on the user (when I've assigned group access to the database), event ID 18456.

Can't figure this out. Still searching...
Thank you for your time.
0
Comment
Question by:Jay
5 Comments
 
LVL 4

Expert Comment

by:TalShyar
ID: 39238352
Take a look at this article if you have not already done so:

http://blogs.msdn.com/b/sql_protocols/archive/2006/02/21/536201.aspx
0
 

Author Comment

by:Jay
ID: 39238678
Thank you.   I went through it but didn't find anything that matched my issue.

So specifically, I'm getting "severity 14, state 16".
Everything Ive read so far point to the login not being set to an active database, yet like I said, the same setup on a user account works fine.
0
 
LVL 24

Expert Comment

by:DBAduck - Ben Miller
ID: 39239994
So to be clear, you have created a global group in AD and added this user, that worked when used alone, to this group.

Then you went into SQL and added this Global Group to Login and set a default database to your database, then mapped this group to a database and assigned db_datareader.

Is that where you are now?
0
 
LVL 75

Accepted Solution

by:
Anthony Perkins earned 500 total points
ID: 39240004
So you created a Windows Login in SQL Server as opposed to a SQL Server Login?  Did you map the user in the database to this Login?  What does your connection string in Excel look like?
0
 

Author Comment

by:Jay
ID: 39242468
dbaduck - That sounds about right.

Under Security/Logins, I added the user account, assigned the database, and assigned permissions db_datareader.

Works fine.

Same procedure except using the global group doesn't work.  
I'm assuming i should be assinging the database under User Mapping?  Right ? Thats where i would normally select the database and then assign db_datareader.
Server Roles is set to Public
nothing else is changed.
0

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Why is this different from all of the other step by step guides?  Because I make a living as a DBA and not as a writer and I lived through this experience. Defining the name: When I talk to people they say different names on this subject stuff l…
Last week, our Skyport webinar on “How to secure your Active Directory” (https://www.experts-exchange.com/videos/5810/Webinar-Is-Your-Active-Directory-as-Secure-as-You-Think.html?cid=Gene_Skyport) provided 218 attendees with a step-by-step guide for…
Using examples as well as descriptions, and references to Books Online, show the different Recovery Models available in SQL Server and explain, as well as show how full, differential and transaction log backups are performed
Viewers will learn how to use the INSERT statement to insert data into their tables. It will also introduce the NULL statement, to show them what happens when no value is giving for any given column.

765 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question