Home Forums SQL Server 2008 Security (SS2K8) Replacing individual logins with AD Groups potential pitfalls? RE: Replacing individual logins with AD Groups potential pitfalls?

  • Rachel Lee-244397 (7/7/2014)


    Hi, not trying to hijack this post, but I have a question I cannot seem to find the answer to.

    When a user is a member of multiple AD groups, that have corresponding logins all on the same instance, with different default databases, which 'group' rules?

    for example.

    ADGroup1, read access to DB1, defaultDB =DB1,

    ADGroup2, dbo access to DB2, defaultDB DB2,

    ADGroup3, read access to DB3, defaultDB = DB3.

    upon connecting, what will be the default db?

    thanks for any input...

    I just tested this and my observations are if no user exactly matches the login and only groups define the login than its alphabetical by database name. This seems to be confirmed by this person HERE

    I could not find any official MS documentation on this so again I am not 100% sure.