migrating all windows group and account permissions to secondary accounts and groups

  • Hi Experts,

    I am working on a requirement. could you help me on this?

    we have 4000~ servers with different versions. higher management wants to move all windows accounts and windows global groups to new groups and individual accounts and then remove existing groups and accounts. here is example i want to take to explain.

    domain1\brahma is individual account has access to different servers.

    domain1\myDBA global group has access to different servers. this group has 2 users domain1\brahma and domain1\john.

    so windows team will create following items

    domain1\brahma_sql and domain1\john_sql users.

    domain1\myDBA_sql group and add the domain1\brahma_sql and domain1\john_sql.

    Now as a DBA my task is apply the existing permissions of groups and users to new accounts and groups then remove existing accounts and groups. do you have any suggestions how to deal with this without breaking anything?

    I need scripts if you have anything. contacted Microsoft and they don't have anything to fulfill this.

    many thanks in advance for your time.

    Thanks,

    Brahma

  • Far from a complete solution for your case, but at least a starting point. Look at this blog post from Sebastian Meine:

    http://sqlity.net/en/2584/script-database-permissions/[/url]

    [font="Times New Roman"]Erland Sommarskog, SQL Server MVP, www.sommarskog.se[/font]

Viewing 2 posts - 1 through 1 (of 1 total)

You must be logged in to reply to this topic. Login to reply