Solved

guest User Access

Posted on 2014-03-18
3
365 Views
Last Modified: 2014-03-19
Hi,

Is there a query I can run to determine which permissions the guest account has? Would it be considered an exception if the guest has access to master, msdb, and tempdb?

Thanks!

--
Vic
0
Comment
Question by:VicBel
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 40

Accepted Solution

by:
lcohan earned 250 total points
ID: 39938021
"You should not disable the guest user in the msdb database in SQL Server'

http://support.microsoft.com/kb/2539091

"how to find guest account is enabled or disabled sql server"
https://sites.google.com/site/jayantdass/how-to-find-guest-account-is-enabled-or-disabled-sql-server
0
 
LVL 69

Assisted Solution

by:Scott Pletcher
Scott Pletcher earned 250 total points
ID: 39938225
>> is there a query ... <<

Takes more of a mini-script, like below, to make sure you include all permissions that might have been given to the guest account:

USE msdb

DECLARE @guest_principal_id int
SELECT @guest_principal_id = principal_id
FROM sys.database_principals
WHERE
    name = 'guest'

SELECT *
FROM sys.database_permissions dp
WHERE
    dp.grantee_principal_id = @guest_principal_id

SELECT dp.name
FROM sys.database_role_members drm
INNER JOIN sys.database_principals dp ON
    dp.principal_id = drm.role_principal_id
WHERE
    drm.member_principal_id = @guest_principal_id


>> Would it be considered an exception if the guest has access to master, msdb, and tempdb? <<

No, and you don't want to remove "CONNECT" permission from guest to any of those databases (unless, I guess, you're absolutely certain you know what you're doing and that it won't cause an issue, but only a very experienced DBA should even try it).
0
 
LVL 69

Expert Comment

by:Scott Pletcher
ID: 39940499
Hope this helped you out here.  Good luck on future qs.
0

Featured Post

Moving data to the cloud? Find out if you’re ready

Before moving to the cloud, it is important to carefully define your db needs, plan for the migration & understand prod. environment. This wp explains how to define what you need from a cloud provider, plan for the migration & what putting a cloud solution into practice entails.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

For both online and offline retail, the cross-channel business is the most recent pattern in the B2C trade space.
In part one, we reviewed the prerequisites required for installing SQL Server vNext. In this part we will explore how to install Microsoft's SQL Server on Ubuntu 16.04.
Via a live example combined with referencing Books Online, show some of the information that can be extracted from the Catalog Views in SQL Server.
Using examples as well as descriptions, and references to Books Online, show the different Recovery Models available in SQL Server and explain, as well as show how full, differential and transaction log backups are performed

617 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question