FIX: Unable to Grant Logins from Global Group with SQL Security
ID: Q178111
|
The information in this article applies to:
-
Microsoft SQL Server version 6.5
BUG #: 17507 (SQLBUG_65)
SYMPTOMS
Granting logins to members of global groups or expanding a global group in
SQL Security Manager may cause an error message if either of the following
conditions is true:
- The MSSQLServer service account is not a member of the domain that the global group belongs to.
-or-
- The MSSQLServer service account is not a member of a domain that is
trusted by the global group's domain.
The error message that you receive is:
Msg No 0, Severity 1, State 1
Unable to successfully query domain controller.
WORKAROUND
To work around this problem, do any one of the following:
- Start the MSSQLServer service as the local system account.
- Start the MSSQLServer service as a domain user account from the global group's domain, making sure that the domain user account is also a member of the local Administrators group on the SQL Server. However, if there are other global groups from other trusted domains, you will not be able to see those users unless the domain of the service account is trusted by the domains of the other global groups.
- Instead of adding global groups to the local group on the SQL Server, add the users from the trusted domain directly to the local group on the SQL Server.
STATUS
Microsoft has confirmed this to be a problem in SQL Server
version 6.5. This problem has been corrected in U.S. Service Pack 5a
for Microsoft SQL Server version 6.5. For information about
downloading and installing the latest SQL Server Service Pack, see
http://support.microsoft.com/support/sql/.
For more information, contact your primary support provider.
Additional query words:
Keywords : SSrvStProc kbbug6.50
Version : winnt:6.5
Platform : winnt
Issue type : kbbug