SQL Clone
SQLServerCentral is supported by Redgate
 
Log in  ::  Register  ::  Not logged in
 
 
 


permission to windowsgroup


permission to windowsgroup

Author
Message
sej2008
sej2008
Mr or Mrs. 500
Mr or Mrs. 500 (541 reputation)Mr or Mrs. 500 (541 reputation)Mr or Mrs. 500 (541 reputation)Mr or Mrs. 500 (541 reputation)Mr or Mrs. 500 (541 reputation)Mr or Mrs. 500 (541 reputation)Mr or Mrs. 500 (541 reputation)Mr or Mrs. 500 (541 reputation)

Group: General Forum Members
Points: 541 Visits: 394
I have created 3 users in windows which are part of windows group named
wingrp1. I created a login in sql from this wingrp1 i.e myserver\wingrp1.
now if i give permission to this group it applies to all 3 windows users.but what I want is that a separate permission should be granted to this user in sql.
Is it possible?so when they login they access different objects.
Is there a way to grant different permission to users in a windows group in sql2008.
Thanks in advance.
Orlando Colamatteo
Orlando Colamatteo
SSCoach
SSCoach (19K reputation)SSCoach (19K reputation)SSCoach (19K reputation)SSCoach (19K reputation)SSCoach (19K reputation)SSCoach (19K reputation)SSCoach (19K reputation)SSCoach (19K reputation)

Group: General Forum Members
Points: 19047 Visits: 14398
but what I want is that a separate permission should be granted to this user in sql.
Is it possible?so when they login they access different objects.

Yes. Drop the SQL Server Login you created based on Windows Group myserver\wingrp1 and add individual SQL Server Logins for each Windows User, e.g. myserver\winusr1, myserver\winusr2 and myserver\winusr3. With this approach each SQL Server Login can have a separate set of permissions in the database instance.

__________________________________________________________________________________________________
There are no special teachers of virtue, because virtue is taught by the whole community. --Plato
kevaburg
kevaburg
SSCrazy
SSCrazy (2.3K reputation)SSCrazy (2.3K reputation)SSCrazy (2.3K reputation)SSCrazy (2.3K reputation)SSCrazy (2.3K reputation)SSCrazy (2.3K reputation)SSCrazy (2.3K reputation)SSCrazy (2.3K reputation)

Group: General Forum Members
Points: 2271 Visits: 1023
I would create a new Active Directory group and move that user into it. The reason, based on our environment here, is that we get alot of requests to create users with the same rights and permissions as another user. Simply adding those users to an existing group simplifies management enormously.

The disadvantage of using single-user logins as opposed to group-based logins is that you then have to touch each individuals account in order to make a simple change. The centralised management of users for a single purpose is something that I believe is greatly underestimated.

In situations where one user has membership in several groups (a very possible scenario), the permissions are grouped together in all situations except where an explicit DENY has been issued. Try it.....I think you will be pleasntly surprised!
Go


Permissions

You can't post new topics.
You can't post topic replies.
You can't post new polls.
You can't post replies to polls.
You can't edit your own topics.
You can't delete your own topics.
You can't edit other topics.
You can't delete other topics.
You can't edit your own posts.
You can't edit other posts.
You can't delete your own posts.
You can't delete other posts.
You can't post events.
You can't edit your own events.
You can't edit other events.
You can't delete your own events.
You can't delete other events.
You can't send private messages.
You can't send emails.
You can read topics.
You can't vote in polls.
You can't upload attachments.
You can download attachments.
You can't post HTML code.
You can't edit HTML code.
You can't post IFCode.
You can't post JavaScript.
You can post emoticons.
You can't post or upload images.

Select a forum

































































































































































SQLServerCentral


Search