• Nice question.

    I couldn't remember what the configuration setting that allows contained users is called, so at first dithered but then I recalled that it has to be set to allow contained users to be created; that meant that having an account in the contained DB implied the setting was already done so I picked the have an account answer and got the point.

    Esoteric stuff for me, this; I read up a bit on denali last year but have never used it, not even played with it. The contained domain user concept worries me, either as a potential insecurity or as a big hole in containment because I don't understand what happens when the domain user ceases to exist in the domain (or the database is moved to an instance in a different domain). Maybe we will see a QoTD on that some time?

    Tom