(This message is cross posted to SQL and AD groups).
I'm in the process of migrating NT users to Active Directory. For file share
access this is fine because I migrate with SID history so everything just
works.
However I've done some test migrations for users with SQL permissions and
they can't access any databases. (As the permissions says their old name).
Short of me having to go through every single server for ever user is there
a way to update or a way for this to work?
Thanks
Rob.
Thanks.
Do you know what scripting i would be looking at or what third party tools?
I've spent a good while searching on this topic and am unable to find
anything so would appreciated any advice.
Thanks.
Rob.
"Jorge de Almeida Pinto [MVP - DS]"
<SubstituteThisWithMyFullNameSeparatedByDots@.gmail .com> wrote in message
news:%23ZQC3GxaIHA.1212@.TK2MSFTNGP05.phx.gbl...
> ADMT does not update SQL DBs. You might do it yourself (scripting) or buy
> third party software
> --
> Cheers,
> (HOPEFULLY THIS INFORMATION HELPS YOU!)
> # Jorge de Almeida Pinto # MVP Windows Server - Directory Services
> BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
> BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
> ----
> * How to ask a question --> http://support.microsoft.com/?id=555375
> ----
> * This posting is provided "AS IS" with no warranties and confers no
> rights!
> * Always test before implementing!
> ----
> #################################################
> #################################################
> ----
> "Robert Nafty" <rob_nafty_spam@.hotmail.co.uk> wrote in message
> news:ODqqU8waIHA.6024@.TK2MSFTNGP06.phx.gbl...
>
|||Hi
If you need to change the domain then look at
http://support.microsoft.com/kb/298897
This may also be used:
http://support.microsoft.com/kb/246133/
You may have orphaned users in which case see
http://support.microsoft.com/kb/274188/
Also check out http://support.microsoft.com/kb/240872/
John
"Robert Nafty" wrote:
> Thanks.
> Do you know what scripting i would be looking at or what third party tools?
> I've spent a good while searching on this topic and am unable to find
> anything so would appreciated any advice.
>
> Thanks.
> Rob.
>
> "Jorge de Almeida Pinto [MVP - DS]"
> <SubstituteThisWithMyFullNameSeparatedByDots@.gmail .com> wrote in message
> news:%23ZQC3GxaIHA.1212@.TK2MSFTNGP05.phx.gbl...
>
>
Showing posts with label directory. Show all posts
Showing posts with label directory. Show all posts
Monday, March 26, 2012
Migrated NT users to AD - Permissions (Cross Posted)
(This message is cross posted to SQL and AD groups).
I'm in the process of migrating NT users to Active Directory. For file share
access this is fine because I migrate with SID history so everything just
works.
However I've done some test migrations for users with SQL permissions and
they can't access any databases. (As the permissions says their old name).
Short of me having to go through every single server for ever user is there
a way to update or a way for this to work'
Thanks
Rob.ADMT does not update SQL DBs. You might do it yourself (scripting) or buy
third party software
--
Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)
# Jorge de Almeida Pinto # MVP Windows Server - Directory Services
BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
----
* How to ask a question --> http://support.microsoft.com/?id=555375
----
* This posting is provided "AS IS" with no warranties and confers no rights!
* Always test before implementing!
----
#################################################
#################################################
----
"Robert Nafty" <rob_nafty_spam@.hotmail.co.uk> wrote in message
news:ODqqU8waIHA.6024@.TK2MSFTNGP06.phx.gbl...
> (This message is cross posted to SQL and AD groups).
> I'm in the process of migrating NT users to Active Directory. For file
> share access this is fine because I migrate with SID history so everything
> just works.
> However I've done some test migrations for users with SQL permissions and
> they can't access any databases. (As the permissions says their old name).
> Short of me having to go through every single server for ever user is
> there a way to update or a way for this to work'
> Thanks
> Rob.
>|||Thanks.
Do you know what scripting i would be looking at or what third party tools?
I've spent a good while searching on this topic and am unable to find
anything so would appreciated any advice.
Thanks.
Rob.
"Jorge de Almeida Pinto [MVP - DS]"
<SubstituteThisWithMyFullNameSeparatedByDots@.gmail.com> wrote in message
news:%23ZQC3GxaIHA.1212@.TK2MSFTNGP05.phx.gbl...
> ADMT does not update SQL DBs. You might do it yourself (scripting) or buy
> third party software
> --
> Cheers,
> (HOPEFULLY THIS INFORMATION HELPS YOU!)
> # Jorge de Almeida Pinto # MVP Windows Server - Directory Services
> BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
> BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
> ----
> * How to ask a question --> http://support.microsoft.com/?id=555375
> ----
> * This posting is provided "AS IS" with no warranties and confers no
> rights!
> * Always test before implementing!
> ----
> #################################################
> #################################################
> ----
> "Robert Nafty" <rob_nafty_spam@.hotmail.co.uk> wrote in message
> news:ODqqU8waIHA.6024@.TK2MSFTNGP06.phx.gbl...
>> (This message is cross posted to SQL and AD groups).
>> I'm in the process of migrating NT users to Active Directory. For file
>> share access this is fine because I migrate with SID history so
>> everything just works.
>> However I've done some test migrations for users with SQL permissions and
>> they can't access any databases. (As the permissions says their old
>> name).
>> Short of me having to go through every single server for ever user is
>> there a way to update or a way for this to work'
>> Thanks
>> Rob.
>>
>|||maybe SQL scripts, vbs scripts
third party tooling, try Quest
--
Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)
# Jorge de Almeida Pinto # MVP Windows Server - Directory Services
BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
----
* How to ask a question --> http://support.microsoft.com/?id=555375
----
* This posting is provided "AS IS" with no warranties and confers no rights!
* Always test before implementing!
----
#################################################
#################################################
----
"Robert Nafty" <rob_nafty_spam@.hotmail.co.uk> wrote in message
news:u6y7cDyaIHA.356@.TK2MSFTNGP03.phx.gbl...
> Thanks.
> Do you know what scripting i would be looking at or what third party
> tools?
> I've spent a good while searching on this topic and am unable to find
> anything so would appreciated any advice.
>
> Thanks.
> Rob.
>
> "Jorge de Almeida Pinto [MVP - DS]"
> <SubstituteThisWithMyFullNameSeparatedByDots@.gmail.com> wrote in message
> news:%23ZQC3GxaIHA.1212@.TK2MSFTNGP05.phx.gbl...
>> ADMT does not update SQL DBs. You might do it yourself (scripting) or buy
>> third party software
>> --
>> Cheers,
>> (HOPEFULLY THIS INFORMATION HELPS YOU!)
>> # Jorge de Almeida Pinto # MVP Windows Server - Directory Services
>> BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
>> BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
>> ----
>> * How to ask a question --> http://support.microsoft.com/?id=555375
>> ----
>> * This posting is provided "AS IS" with no warranties and confers no
>> rights!
>> * Always test before implementing!
>> ----
>> #################################################
>> #################################################
>> ----
>> "Robert Nafty" <rob_nafty_spam@.hotmail.co.uk> wrote in message
>> news:ODqqU8waIHA.6024@.TK2MSFTNGP06.phx.gbl...
>> (This message is cross posted to SQL and AD groups).
>> I'm in the process of migrating NT users to Active Directory. For file
>> share access this is fine because I migrate with SID history so
>> everything just works.
>> However I've done some test migrations for users with SQL permissions
>> and they can't access any databases. (As the permissions says their old
>> name).
>> Short of me having to go through every single server for ever user is
>> there a way to update or a way for this to work'
>> Thanks
>> Rob.
>>
>|||Hi
If you need to change the domain then look at
http://support.microsoft.com/kb/298897
This may also be used:
http://support.microsoft.com/kb/246133/
You may have orphaned users in which case see
http://support.microsoft.com/kb/274188/
Also check out http://support.microsoft.com/kb/240872/
John
"Robert Nafty" wrote:
> Thanks.
> Do you know what scripting i would be looking at or what third party tools?
> I've spent a good while searching on this topic and am unable to find
> anything so would appreciated any advice.
>
> Thanks.
> Rob.
>
> "Jorge de Almeida Pinto [MVP - DS]"
> <SubstituteThisWithMyFullNameSeparatedByDots@.gmail.com> wrote in message
> news:%23ZQC3GxaIHA.1212@.TK2MSFTNGP05.phx.gbl...
> > ADMT does not update SQL DBs. You might do it yourself (scripting) or buy
> > third party software
> >
> > --
> >
> > Cheers,
> > (HOPEFULLY THIS INFORMATION HELPS YOU!)
> >
> > # Jorge de Almeida Pinto # MVP Windows Server - Directory Services
> >
> > BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
> > BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
> > ----
> > * How to ask a question --> http://support.microsoft.com/?id=555375
> > ----
> > * This posting is provided "AS IS" with no warranties and confers no
> > rights!
> > * Always test before implementing!
> > ----
> > #################################################
> > #################################################
> > ----
> > "Robert Nafty" <rob_nafty_spam@.hotmail.co.uk> wrote in message
> > news:ODqqU8waIHA.6024@.TK2MSFTNGP06.phx.gbl...
> >> (This message is cross posted to SQL and AD groups).
> >>
> >> I'm in the process of migrating NT users to Active Directory. For file
> >> share access this is fine because I migrate with SID history so
> >> everything just works.
> >>
> >> However I've done some test migrations for users with SQL permissions and
> >> they can't access any databases. (As the permissions says their old
> >> name).
> >>
> >> Short of me having to go through every single server for ever user is
> >> there a way to update or a way for this to work'
> >>
> >> Thanks
> >> Rob.
> >>
> >>
> >
>
>
I'm in the process of migrating NT users to Active Directory. For file share
access this is fine because I migrate with SID history so everything just
works.
However I've done some test migrations for users with SQL permissions and
they can't access any databases. (As the permissions says their old name).
Short of me having to go through every single server for ever user is there
a way to update or a way for this to work'
Thanks
Rob.ADMT does not update SQL DBs. You might do it yourself (scripting) or buy
third party software
--
Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)
# Jorge de Almeida Pinto # MVP Windows Server - Directory Services
BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
----
* How to ask a question --> http://support.microsoft.com/?id=555375
----
* This posting is provided "AS IS" with no warranties and confers no rights!
* Always test before implementing!
----
#################################################
#################################################
----
"Robert Nafty" <rob_nafty_spam@.hotmail.co.uk> wrote in message
news:ODqqU8waIHA.6024@.TK2MSFTNGP06.phx.gbl...
> (This message is cross posted to SQL and AD groups).
> I'm in the process of migrating NT users to Active Directory. For file
> share access this is fine because I migrate with SID history so everything
> just works.
> However I've done some test migrations for users with SQL permissions and
> they can't access any databases. (As the permissions says their old name).
> Short of me having to go through every single server for ever user is
> there a way to update or a way for this to work'
> Thanks
> Rob.
>|||Thanks.
Do you know what scripting i would be looking at or what third party tools?
I've spent a good while searching on this topic and am unable to find
anything so would appreciated any advice.
Thanks.
Rob.
"Jorge de Almeida Pinto [MVP - DS]"
<SubstituteThisWithMyFullNameSeparatedByDots@.gmail.com> wrote in message
news:%23ZQC3GxaIHA.1212@.TK2MSFTNGP05.phx.gbl...
> ADMT does not update SQL DBs. You might do it yourself (scripting) or buy
> third party software
> --
> Cheers,
> (HOPEFULLY THIS INFORMATION HELPS YOU!)
> # Jorge de Almeida Pinto # MVP Windows Server - Directory Services
> BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
> BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
> ----
> * How to ask a question --> http://support.microsoft.com/?id=555375
> ----
> * This posting is provided "AS IS" with no warranties and confers no
> rights!
> * Always test before implementing!
> ----
> #################################################
> #################################################
> ----
> "Robert Nafty" <rob_nafty_spam@.hotmail.co.uk> wrote in message
> news:ODqqU8waIHA.6024@.TK2MSFTNGP06.phx.gbl...
>> (This message is cross posted to SQL and AD groups).
>> I'm in the process of migrating NT users to Active Directory. For file
>> share access this is fine because I migrate with SID history so
>> everything just works.
>> However I've done some test migrations for users with SQL permissions and
>> they can't access any databases. (As the permissions says their old
>> name).
>> Short of me having to go through every single server for ever user is
>> there a way to update or a way for this to work'
>> Thanks
>> Rob.
>>
>|||maybe SQL scripts, vbs scripts
third party tooling, try Quest
--
Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)
# Jorge de Almeida Pinto # MVP Windows Server - Directory Services
BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
----
* How to ask a question --> http://support.microsoft.com/?id=555375
----
* This posting is provided "AS IS" with no warranties and confers no rights!
* Always test before implementing!
----
#################################################
#################################################
----
"Robert Nafty" <rob_nafty_spam@.hotmail.co.uk> wrote in message
news:u6y7cDyaIHA.356@.TK2MSFTNGP03.phx.gbl...
> Thanks.
> Do you know what scripting i would be looking at or what third party
> tools?
> I've spent a good while searching on this topic and am unable to find
> anything so would appreciated any advice.
>
> Thanks.
> Rob.
>
> "Jorge de Almeida Pinto [MVP - DS]"
> <SubstituteThisWithMyFullNameSeparatedByDots@.gmail.com> wrote in message
> news:%23ZQC3GxaIHA.1212@.TK2MSFTNGP05.phx.gbl...
>> ADMT does not update SQL DBs. You might do it yourself (scripting) or buy
>> third party software
>> --
>> Cheers,
>> (HOPEFULLY THIS INFORMATION HELPS YOU!)
>> # Jorge de Almeida Pinto # MVP Windows Server - Directory Services
>> BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
>> BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
>> ----
>> * How to ask a question --> http://support.microsoft.com/?id=555375
>> ----
>> * This posting is provided "AS IS" with no warranties and confers no
>> rights!
>> * Always test before implementing!
>> ----
>> #################################################
>> #################################################
>> ----
>> "Robert Nafty" <rob_nafty_spam@.hotmail.co.uk> wrote in message
>> news:ODqqU8waIHA.6024@.TK2MSFTNGP06.phx.gbl...
>> (This message is cross posted to SQL and AD groups).
>> I'm in the process of migrating NT users to Active Directory. For file
>> share access this is fine because I migrate with SID history so
>> everything just works.
>> However I've done some test migrations for users with SQL permissions
>> and they can't access any databases. (As the permissions says their old
>> name).
>> Short of me having to go through every single server for ever user is
>> there a way to update or a way for this to work'
>> Thanks
>> Rob.
>>
>|||Hi
If you need to change the domain then look at
http://support.microsoft.com/kb/298897
This may also be used:
http://support.microsoft.com/kb/246133/
You may have orphaned users in which case see
http://support.microsoft.com/kb/274188/
Also check out http://support.microsoft.com/kb/240872/
John
"Robert Nafty" wrote:
> Thanks.
> Do you know what scripting i would be looking at or what third party tools?
> I've spent a good while searching on this topic and am unable to find
> anything so would appreciated any advice.
>
> Thanks.
> Rob.
>
> "Jorge de Almeida Pinto [MVP - DS]"
> <SubstituteThisWithMyFullNameSeparatedByDots@.gmail.com> wrote in message
> news:%23ZQC3GxaIHA.1212@.TK2MSFTNGP05.phx.gbl...
> > ADMT does not update SQL DBs. You might do it yourself (scripting) or buy
> > third party software
> >
> > --
> >
> > Cheers,
> > (HOPEFULLY THIS INFORMATION HELPS YOU!)
> >
> > # Jorge de Almeida Pinto # MVP Windows Server - Directory Services
> >
> > BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
> > BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
> > ----
> > * How to ask a question --> http://support.microsoft.com/?id=555375
> > ----
> > * This posting is provided "AS IS" with no warranties and confers no
> > rights!
> > * Always test before implementing!
> > ----
> > #################################################
> > #################################################
> > ----
> > "Robert Nafty" <rob_nafty_spam@.hotmail.co.uk> wrote in message
> > news:ODqqU8waIHA.6024@.TK2MSFTNGP06.phx.gbl...
> >> (This message is cross posted to SQL and AD groups).
> >>
> >> I'm in the process of migrating NT users to Active Directory. For file
> >> share access this is fine because I migrate with SID history so
> >> everything just works.
> >>
> >> However I've done some test migrations for users with SQL permissions and
> >> they can't access any databases. (As the permissions says their old
> >> name).
> >>
> >> Short of me having to go through every single server for ever user is
> >> there a way to update or a way for this to work'
> >>
> >> Thanks
> >> Rob.
> >>
> >>
> >
>
>
Friday, March 23, 2012
Migrate to New Domain
I migrated my SQL 7 server running on Win 2K Server from
the existing domain to a new domain using the Active
Directory Migration tool but now SQL won't start and I
cannot get it to start whether I log on to the old or new
domains. Does anyone have an insight?Wht error do yo get? I guess SQL Server service can't logo to Windows
domain. Check te username and password SQL Server service is using.
--
Dejan Sarka, SQL Server MVP
Associate Mentor
Solid Quality Learning
More than just Training
www.SolidQualityLearning.com
"Kevin" <anonymous@.discussions.microsoft.com> wrote in message
news:54af01c42cdd$7a56a5f0$a101280a@.phx.gbl...
> I migrated my SQL 7 server running on Win 2K Server from
> the existing domain to a new domain using the Active
> Directory Migration tool but now SQL won't start and I
> cannot get it to start whether I log on to the old or new
> domains. Does anyone have an insight?
the existing domain to a new domain using the Active
Directory Migration tool but now SQL won't start and I
cannot get it to start whether I log on to the old or new
domains. Does anyone have an insight?Wht error do yo get? I guess SQL Server service can't logo to Windows
domain. Check te username and password SQL Server service is using.
--
Dejan Sarka, SQL Server MVP
Associate Mentor
Solid Quality Learning
More than just Training
www.SolidQualityLearning.com
"Kevin" <anonymous@.discussions.microsoft.com> wrote in message
news:54af01c42cdd$7a56a5f0$a101280a@.phx.gbl...
> I migrated my SQL 7 server running on Win 2K Server from
> the existing domain to a new domain using the Active
> Directory Migration tool but now SQL won't start and I
> cannot get it to start whether I log on to the old or new
> domains. Does anyone have an insight?
Migrate to active directory
Hi,
I want to migrate my sqlserver to active directory.
Someone can tell me what is the procedure and how can i do ?
Someone have already do this migration ?
RegardsHi,
I want to migrate my sqlserver to active directory.
Someone can tell me what is the procedure and how can i do ?
Someone have already do this migration ?
Regards
Um, do you mean publish your SQL Server to AD? Migrate would imply that you are taking the data out of SQL and putting it somewhere in AD. Publish is an SQL feature that MS put in to allow users to search for SQL metadata (server names, db names, replication publications) through the AD interface.
Can you clarify?
Regards,
hmscott|||it's only the migration of the physical server to AD|||A lot of this answer is going to depend on your AD structure. There are more questions that I can reasonably run up in an online thread, but you'd start with the basics: How many trees, do they have mutual trust, how many OUs total, how many OUs in the AD tree you're targeting.
Whatever you do, do NOT make your SQL Server a DC. That is extremely painful for both SQL and AD.
-PatP|||no i don't want to migrat the sqlserver to DC.
I have DC and system server and database server i want to migrate database server in the AD domain.
regards|||no i don't want to migrat the sqlserver to DC.
I have DC and system server and database server i want to migrate database server in the AD domain.
regards
Just to be sure that I understand:
1. You have a standalone database server (ie, not a member of any AD domain).
2. You have a domain to which you want to join the standalone server
Correct?
If so, I have never done this before. All the servers I have built have been built as a member of a domain before I installed SQL. That being said, I don't think that you will have any issues. Simply join the server to the domain the regular way. Once that is done, you can then change the startup service account for SQL Server (and for SQL Agent if deisred).
I don't think anything bad will happen, but as I said, I haven't done this myself (or if I have, it was ages ago).
Regards,
hmscott
I want to migrate my sqlserver to active directory.
Someone can tell me what is the procedure and how can i do ?
Someone have already do this migration ?
RegardsHi,
I want to migrate my sqlserver to active directory.
Someone can tell me what is the procedure and how can i do ?
Someone have already do this migration ?
Regards
Um, do you mean publish your SQL Server to AD? Migrate would imply that you are taking the data out of SQL and putting it somewhere in AD. Publish is an SQL feature that MS put in to allow users to search for SQL metadata (server names, db names, replication publications) through the AD interface.
Can you clarify?
Regards,
hmscott|||it's only the migration of the physical server to AD|||A lot of this answer is going to depend on your AD structure. There are more questions that I can reasonably run up in an online thread, but you'd start with the basics: How many trees, do they have mutual trust, how many OUs total, how many OUs in the AD tree you're targeting.
Whatever you do, do NOT make your SQL Server a DC. That is extremely painful for both SQL and AD.
-PatP|||no i don't want to migrat the sqlserver to DC.
I have DC and system server and database server i want to migrate database server in the AD domain.
regards|||no i don't want to migrat the sqlserver to DC.
I have DC and system server and database server i want to migrate database server in the AD domain.
regards
Just to be sure that I understand:
1. You have a standalone database server (ie, not a member of any AD domain).
2. You have a domain to which you want to join the standalone server
Correct?
If so, I have never done this before. All the servers I have built have been built as a member of a domain before I installed SQL. That being said, I don't think that you will have any issues. Simply join the server to the domain the regular way. Once that is done, you can then change the startup service account for SQL Server (and for SQL Agent if deisred).
I don't think anything bad will happen, but as I said, I haven't done this myself (or if I have, it was ages ago).
Regards,
hmscott
Subscribe to:
Posts (Atom)