Link to home
Start Free TrialLog in
Avatar of Jerry Seinfield
Jerry SeinfieldFlag for United States of America

asked on

AD permissions required to allow computer objects and service accounts to register SPNs

Hi Experts,

Need to verify with your team, AD/SQL minimum permissions required to successfully register SPNs in AD. By setting the SQL startup accounts to properly register SPN , I should be able to allow a SQL service account to register SPNs in AD .

Need to validate this for a Windows 2008 R2 SQL clusters, and for recent versions  2012,  2016. Please, make sure your answer carefully consider all of the environments. My understanding is that we already have a 2008 R2 SQL clusters, and permissions were not given before the installation of the cluster, you can later on assign permissions to register SPNs. Please, specify if rights should be granted at the cluster virtual object of SQL, cluster nodes, cluster instances and/ or computer nodes of the cluster.

On the other hand, advise if Domain admin rights is the only option to register SPN in AD. Otherwise, provide step by step instructions to allow SQL service accounts and clusters/nodes/instances to successfully register SPNs in AD
ASKER CERTIFIED SOLUTION
Avatar of Vitor Montalvão
Vitor Montalvão
Flag of Switzerland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial