--creat the login for the Active Directory UserCREATE LOGIN [mydomain\NewUse] FROM WINDOWS;--switch to the right database: if more than one database, repeat for each oneUSE SandBox;GO--Create the user to match the loginCREATE USER [mydomain\NewUser] FROM LOGIN [mydomain\NewUser]--assign permissions--put the user in the correct permissions roleexec sp_addrolemember 'RoleAlreadyCreated', 'mydomain\NewUser'--an example in case you don't have the role with the right permissions yet:CREATE ROLE [AlmostOwners] EXEC sp_addrolemember N'db_ddladmin', N'AlmostOwners'EXEC sp_addrolemember N'db_datareader', N'AlmostOwners'EXEC sp_addrolemember N'db_datawriter', N'AlmostOwners'--can the users EXECUTE procedures? comment out if falseGRANT EXECUTE TO [AlmostOwners]exec sp_addrolemember 'AlmostOwners', ' mydomain\NewUser'