Domain User Account Privileges
Domain user or domain administrator.
Domain user account privileges. Set permissions for the service account. A trusted domain should not duplicate the user accounts from one domain to the other. This latter setting is a quick way to unlock an account when a user has forgotten a password or is locked out of the account for some other reason. A user account can only be listed in a domain one time.
It s recommended to set permissions on the parent ou depending on the companies ou structure. A user account can be listed in all domains but only one time. But there are several types of account privileges you can apply to an account. Many server to server activities can be performed only with a domain user account.
This user should have local administrator privilege on the admin server machine. This account should be the same as sql server service account. There is also an area on the account tab that allows the account to be unlocked. So a user will have the privileges of a normal non admin user on any box in the domain.
Launch active directory users and computers click on the view menu and on the drop down check the advanced features option. Navigate to the ou right click on your target ou and select properties. If the service must interact with network services access domain resources like file shares or if it uses linked server connections to other computers running sql server you might use a minimally privileged domain account. Many user rights in active directory and on domain controllers are granted specifically to the administrators group not to eas or das.
This user should have local administrator privilege on both the sql server machine and storage server. By default all new users are part of the domain users group. So we are aware of the two common account privileges windows 10 offers by default. That group in turn is part of the users group on all machines in the domain.
Remotely login to the user s workstation as a domain admin or physically sit in front of the user s windows pc. By default every domain s ba group contains the local domain s built in administrator account the local domain s da group and the forest root domain s ea group. From the local users and groups snap in browse to groups double click on the administrators group locate your domain user account grant him her membership to the administrators. Sql server sql instance domain user or domain administrator.