Microsoft SQL and Activity Monitor

Because of securtity I have excluded people from the sysadmin role of the server, but they should still be able to use the Activity Monitor, but it fails(see attached doc).
I have created a new group with the permissions "Alter any database", "Connect SQL", "Create any database", "View any definition" and "View server state" but they still get the error.

Am I missing any permissions?
Who is Participating?
systemgruppenConnect With a Mentor Author Commented:
First I tried to change the group from Universal to Domain Local, but that did not help.

Then I deleted the AD group, and then created a new one, but now as a Domain Local and not Universal Group,  applied it to the SQL server, gave it the above mentioned rights and this did the trick.
Vitor MontalvãoMSSQL Senior EngineerCommented:
Why they need to use the Activity Monitor? If you provide them some scripts with DMV's queries it would do the job.
Anyway, the users are AD users ,right? They need to be added to the group Performance Monitoring Users in Windows.
systemgruppenAuthor Commented:
I have made an AD group, which already are a member of the Performance Monitor Users group on the server.
Besides the group also has the following permissions on the SQL server:

1. Alter any databases
2. Connect SQL
3. Create any database
4. View any definition
5. View server state

And they need access to the Activity Monitor, so giving them scripts is not an option.
Build your data science skills into a career

Are you ready to take your data science career to the next step, or break into data science? With Springboard’s Data Science Career Track, you’ll master data science topics, have personalized career guidance, weekly calls with a data science expert, and a job guarantee.

Anthony PerkinsCommented:
SQL Server's BOL states:
To view the Activity Monitor, a user must have VIEW SERVER STATE permission. To view the Data File I/O section of Activity Monitor, you must have CREATE DATABASE, ALTER ANY DATABASE, or VIEW ANY DEFINITION permission in addition to VIEW SERVER STATE.
So, if you are sure you have given the users all these permissions and still get the error I would contact Microsoft Product Support or post a new entry in Microsoft Connect.
systemgruppenAuthor Commented:
Just for testing, I created a SQL user, and made the user member of the above mentioned SQL groups, and it works, so it seems to be a problem with the AD groups.
I then changed the AD Security groups from Universal to Domain Local, but no changes  still get the error.
I have to use AD groups, so does any a suggestion to what I can do?????
Anthony PerkinsCommented:
I can only assume that the AD Group does not have all the required permissions.    If that is not the case then you should contact Microsoft Product Support.
systemgruppenAuthor Commented:
That solved the problem
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.