Jerry Seinfield
asked on
AD permissions required to allow computer objects and service accounts to register SPNs
Hi Experts,
Need to verify with your team, AD/SQL minimum permissions required to successfully register SPNs in AD. By setting the SQL startup accounts to properly register SPN , I should be able to allow a SQL service account to register SPNs in AD .
Need to validate this for a Windows 2008 R2 SQL clusters, and for recent versions 2012, 2016. Please, make sure your answer carefully consider all of the environments. My understanding is that we already have a 2008 R2 SQL clusters, and permissions were not given before the installation of the cluster, you can later on assign permissions to register SPNs. Please, specify if rights should be granted at the cluster virtual object of SQL, cluster nodes, cluster instances and/ or computer nodes of the cluster.
On the other hand, advise if Domain admin rights is the only option to register SPN in AD. Otherwise, provide step by step instructions to allow SQL service accounts and clusters/nodes/instances to successfully register SPNs in AD
Need to verify with your team, AD/SQL minimum permissions required to successfully register SPNs in AD. By setting the SQL startup accounts to properly register SPN , I should be able to allow a SQL service account to register SPNs in AD .
Need to validate this for a Windows 2008 R2 SQL clusters, and for recent versions 2012, 2016. Please, make sure your answer carefully consider all of the environments. My understanding is that we already have a 2008 R2 SQL clusters, and permissions were not given before the installation of the cluster, you can later on assign permissions to register SPNs. Please, specify if rights should be granted at the cluster virtual object of SQL, cluster nodes, cluster instances and/ or computer nodes of the cluster.
On the other hand, advise if Domain admin rights is the only option to register SPN in AD. Otherwise, provide step by step instructions to allow SQL service accounts and clusters/nodes/instances to successfully register SPNs in AD
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.