Permissions

SQLServerCentral Article

Cloning Master Admin User Permissions in Amazon RDS for SQL Server with Fine-Grained Control

  • Article

This article explores how to securely clone the master user permissions in Amazon RDS for SQL Server using a custom stored procedure, usp_rds_clone_login. It outlines a step-by-step process to generate, review, and apply a script that replicates server- and database-level access from the master user to a new login without directly exposing elevated credentials. The guide emphasizes the principle of least privilege, supports named account management, and enables transparent, auditable permission handling for DBAs and applications. Designed for secure and scalable environments, this solution enhances operational security while maintaining administrative flexibility in Amazon RDS.

★ ★ ★ ★ ★ ★ ★ ★ ★ ★

You rated this post out of 5. Change rating

2025-07-09

1,219 reads

Blogs

Au Revoir for now

By

No, I’m not quitting or retiring. Just going on vacation, but I leave tonight...

Goodbye, Microsoft

By

A few years ago I took a new job at Microsoft, working as a...

The SUM of Nothing: #SQLNewBlogger

By

I caught this interesting item over on Pinal Dave’s blog: Eleven Interview Questions that...

Read the latest Blogs

Forums

Building a SQL Server Fleet Audit That Leadership Actually Reads

By Mayank Sethi

Comments posted to this topic are about the item Building a SQL Server Fleet...

Smart AI Agents and Data Security

By Steve Jones - SSC Editor

Comments posted to this topic are about the item Smart AI Agents and Data...

RegEx Functions IV

By Steve Jones - SSC Editor

Comments posted to this topic are about the item RegEx Functions IV

Visit the forum

Question of the Day

RegEx Functions IV

I have this data in a table in a SQL Server 2025 database:

EmailAddressID EmailAddress
7              dylan0@ADVENTURE-WORKS.COM
8              Diane1@ADVENTURE-WORKS.COM
If I run this query, which row(s) are returned?
SELECT top 10
 *
 FROM person.EmailAddress
 WHERE REGEXP_LIKE(EmailAddress, '^D', 'i')
 AND BusinessEntityID IN (7,8)

See possible answers