Showing posts with label login. Show all posts
Showing posts with label login. Show all posts

Wednesday, March 28, 2012

Is it possible to limit resources by login?

Is it possible in SQL 2005 to set a limit on resources to certain logins. In other words throttle down some users and therefore increase the priority of others?

SQL 2005 does not have the ability to limit resources based on logins.

Monday, March 26, 2012

Is it possible to grant a login the permission to create and schedule jobs?

I have a user who does not need to have any other server permissions other
than to create and schedule jobs, but I'm going round in circles trying to
figure out if I can actually do this using BOL as a resource. Is it possible
and if so, how?
TIA
Michael MacGregor
Database ArchitectMichael,
Yes it is possible, as long as the user is the job owner. The BOL says that
sp_add_job is public, which means that anyone who is a user of msdb (which
you may not have granted to everyone) should be able to create a job. So
first, the user needs rights to msdb.
*** SQL 2000 - I remember that we needed to do more, as show below, but no
longer remember all the reasons.
You can create a role, such as AgentJobManager and grant specific rights.
Users will (as non-sysadmins) be limited to managing the jobs that they
personally create.
GRANT EXECUTE ON sp_add_category TO AgentJobManager
GRANT EXECUTE ON sp_add_job TO AgentJobManager
GRANT EXECUTE ON sp_add_jobschedule TO AgentJobManager
GRANT EXECUTE ON sp_add_jobstep TO AgentJobManager
GRANT EXECUTE ON sp_delete_category TO AgentJobManager
GRANT EXECUTE ON sp_delete_job TO AgentJobManager
GRANT EXECUTE ON sp_delete_jobschedule TO AgentJobManager
GRANT EXECUTE ON sp_delete_jobstep TO AgentJobManager
GRANT EXECUTE ON sp_post_msx_operation TO AgentJobManager
GRANT EXECUTE ON sp_update_category TO AgentJobManager
GRANT EXECUTE ON sp_update_job TO AgentJobManager
GRANT EXECUTE ON sp_update_jobschedule TO AgentJobManager
GRANT EXECUTE ON sp_update_jobstep TO AgentJobManager
GRANT SELECT ON syscategories TO AgentJobManager
GRANT SELECT ON sysjobsTO AgentJobManager
GRANT SELECT ON sysjobserversTO AgentJobManager
Then make the necessary users member of the AgentJobManager role.
*** SQL 2005
Make the users members of one of the following roles, according to what
rights you want them to have:
SQLAgentOperatorRole
SQLAgentReaderRole
SQLAgentUserRole
RLF
"Michael MacGregor" <nospam@.nospam.com> wrote in message
news:uxaKhSVyHHA.4004@.TK2MSFTNGP05.phx.gbl...

>I have a user who does not need to have any other server permissions other
>than to create and schedule jobs, but I'm going round in circles trying to
>figure out if I can actually do this using BOL as a resource. Is it
>possible and if so, how?
> TIA
> Michael MacGregor
> Database Architect
>|||Thanks Russell. It would have probably taken me a long time to figure that
out.
MTM

Wednesday, March 21, 2012

is it possible to connect to SQL Express without network?

I have notebook, client server application and sql express sp2 on this notebook.

Also, I know domain user login/password,

but I don't know any local user name/password

and I don't know any sql server user name/password.

Domain user is not a local administrator on this notebook.

When notebook connected to the office LAN I am working good with my app-> my sql express as a domain/user.

I'd like to work at home too. I can logon to the system (XP SP2) using domain account when notebook has no network connection. (probably OS caches something)

Is it possible to work with sql express using domain login when no network connection?

PS. old version of this software used MSDE 2000 and it was possible(!).

Thank you.

Yes. SQL Server will still work the same as when you are connected to the office LAN.

Since you log on with your domain credentials (they are cachd on the laptop), the same credentials are used to gain entry to SQL Server.

|||

Arnie Rowland wrote:

Yes. SQL Server will still work the same as when you are connected to the office LAN.

Since you log on with your domain credentials (they are cachd on the laptop), the same credentials are used to gain entry to SQL Server.

Ok, thank you.

I did experiment on 2 workstations.

On one machine ist working good, but on the second machine (no netowrk connection) when I tried to connect to the sql server I have a problem:

SSMS is ocnnecting ok

Application gives me message: cannot generate SSPI context.

What can it be? ...

Thank you

|||

Check these souces:

Error -Cannot generate SSPI context
http://support.microsoft.com/Default.aspx?id=811889
http://support.microsoft.com/kb/827422/en-us
http://support.microsoft.com/kb/843248/en-us
http://support.microsoft.com/kb/269541/en-us
http://support.microsoft.com/kb/267588/en-us
http://support.microsoft.com/kb/814401/en-us
http://support.microsoft.com/kb/818173/en-us

sql

Monday, March 19, 2012

is it possible to change the name of a login is sql server 2000

Hi, is it possible to change the name of a login on sql server 2000 from :
domain1\myuser to domain2\myuser
The authentication is windows mode.
Thank you
Is domain1\myuser owns any objects? If not, probably you can just drop
domain1\myuser and add domain2\myuser.
Lucas
"toutous" wrote:

> Hi, is it possible to change the name of a login on sql server 2000 from :
> domain1\myuser to domain2\myuser
> The authentication is windows mode.
> Thank you
>
|||I need to do a script that automates that for all logins. So yes the logins
might also own objects
Thank you
"Lucas Kartawidjaja" wrote:
[vbcol=seagreen]
> Is domain1\myuser owns any objects? If not, probably you can just drop
> domain1\myuser and add domain2\myuser.
> Lucas
> "toutous" wrote:

is it possible to change the name of a login is sql server 2000

Hi, is it possible to change the name of a login on sql server 2000 from :
domain1\myuser to domain2\myuser
The authentication is windows mode.
Thank youIs domain1\myuser owns any objects? If not, probably you can just drop
domain1\myuser and add domain2\myuser.
Lucas
"toutous" wrote:
> Hi, is it possible to change the name of a login on sql server 2000 from :
> domain1\myuser to domain2\myuser
> The authentication is windows mode.
> Thank you
>|||I need to do a script that automates that for all logins. So yes the logins
might also own objects
Thank you
"Lucas Kartawidjaja" wrote:
> Is domain1\myuser owns any objects? If not, probably you can just drop
> domain1\myuser and add domain2\myuser.
> Lucas
> "toutous" wrote:
> > Hi, is it possible to change the name of a login on sql server 2000 from :
> > domain1\myuser to domain2\myuser
> > The authentication is windows mode.
> > Thank you
> >

is it possible to change the name of a login is sql server 2000

Hi, is it possible to change the name of a login on sql server 2000 from :
domain1\myuser to domain2\myuser
The authentication is windows mode.
Thank youIs domain1\myuser owns any objects? If not, probably you can just drop
domain1\myuser and add domain2\myuser.
Lucas
"toutous" wrote:

> Hi, is it possible to change the name of a login on sql server 2000 from :
> domain1\myuser to domain2\myuser
> The authentication is windows mode.
> Thank you
>

is it possible to change the name of a login is sq

Hi, is it possible to change the name of a login on sql server 2000 from :
domain1\myuser to domain2\myuser
The authentication is windows mode.
Thank you

You cannot change logins for windows accounts.

You will have to add the domain2 logins and then map them to the databases as necessary.

It is possible to change SQL Server logins using sp_changeuserslogin system stored procedure, but I do not believe this will work with windows accounts.

is it possible to change the name of a login is sq

Hi, is it possible to change the name of a login on sql server 2000 from :
domain1\myuser to domain2\myuser
The authentication is windows mode.
Thank you

You cannot change logins for windows accounts.

You will have to add the domain2 logins and then map them to the databases as necessary.

It is possible to change SQL Server logins using sp_changeuserslogin system stored procedure, but I do not believe this will work with windows accounts.

Friday, February 24, 2012

Is Forms Authentication available on Standard

I have been looking at the forms authentication sample that creates a custom login page. After looking at the licencing am I right in saying that this can only be implemented using SQL server enterprise edition as standard edition does not have the security extension API. If this is the case is there any way to custom authenticate a user when using URL calls that is not windows Authentication?I have found the answer which is simply no. Back to Crystal Reports then. Good luck getting this off the ground when you have to buy Enterprise Edition just to securely provide reports over the web that have some kind of functionality.
"Ryan Smith" wrote:
> I have been looking at the forms authentication sample that creates a custom login page. After looking at the licencing am I right in saying that this can only be implemented using SQL server enterprise edition as standard edition does not have the security extension API. If this is the case is there any way to custom authenticate a user when using URL calls that is not windows Authentication?|||Web services does not support everything as it only provides a snapshot of
the report and does not have drill down functionality. If you have a report
that has drill downs (95% of my reports) in it and you run a webservice for
it, when the user clicks on the drill down they get an error.
"Richard" wrote:
> You can still build your own web app (report manager) and use the web service
> to communitate with it. I have gone over the api for the ws and it supports
> everyting you need. Yes it's a bit of work up front but there are no
> licensing issues at all
> "Ryan Smith" wrote:
> > I have found the answer which is simply no. Back to Crystal Reports then. Good luck getting this off the ground when you have to buy Enterprise Edition just to securely provide reports over the web that have some kind of functionality.
> >
> > "Ryan Smith" wrote:
> >
> > > I have been looking at the forms authentication sample that creates a custom login page. After looking at the licencing am I right in saying that this can only be implemented using SQL server enterprise edition as standard edition does not have the security extension API. If this is the case is there any way to custom authenticate a user when using URL calls that is not windows Authentication?