Solved

Windows login that is trusted on SQL Server 2005

Posted on 2014-11-19
2
92 Views
Last Modified: 2014-11-26
I guess this is a two part issue but would like to know how to do this in one step. When I create a user on the windows server it creates the user and mailbox on the exchange server but would like for it to also create a user on the SQL server that has trusted rights to run crystal reports we have created. Currently I have to create a new user on the SQL server which has public role assigned to the user but want them to also be trusted so they can run the reports. Right now they have to use the SA login to run the reports and I don't like that. I have read I need to give the sysadmin role to that user but that is like letting them use the SA login. How can I do this in one step and what role on the sql server can I give them that allows them to be trusted but not make modifications on the database?
0
Comment
Question by:tparus
2 Comments
 
LVL 47

Expert Comment

by:Vitor Montalvão
ID: 40452718
Create an AD group and give that group permissions on SQL Server instead of a single user. Then, new users will be added directly to the AD group and will have automatically access to SQL Server.
0
 
LVL 69

Accepted Solution

by:
Qlemo earned 500 total points
ID: 40452728
This is indeed two-fold:
a) How to best manage trusted new users in MSSQL
b) How to set up the privs correctly

a) assign those folks to a user group in AD, and make an assignment for that AD group in MSSQL
b) usually you need nothing else than the datareader and datawriter roles (or datareader for read-only access)
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
This script can help you clean up your user profile database by comparing profiles to Active Directory users in a particular OU, and removing the profiles that don't match.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

821 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question