• Sorry, I didn't know "global" had a specific meaning. I probably meant an AD account. No, I don't have access to the DC. I have access to an app that lets me manage group membership for groups I "own". I own the group that has permission for the specific network share. (Well, my client does, anyway....)

    The standard practice in this scenario is to use a basic low priv domain user account.

    That's what I needed. Sometimes it takes alot to get through to my thick skull. I think the "sqlserveragent" generic account controlled by corporate IT is likely the direction I need to go. Again, I have to wait until Monday when my contact returns. We should have 12" of snow and -13 degrees Fahrenheit by then, so I hope he comes to work (though he is in Virginia....)

    Thanks, Perry and Will. If not for your advice, I might have assigned it to a generic account I controlled. As you said, if my account is deleted, the whole shebang breaks, so that was a good call. I'll post what I find out.

    Jim