FIX: Unable to Grant Logins from Global Group with SQL Security

ID: Q178111


The information in this article applies to:
  • Microsoft SQL Server version 6.5

BUG #: 17507 (SQLBUG_65)

SYMPTOMS

Granting logins to members of global groups or expanding a global group in SQL Security Manager may cause an error message if either of the following conditions is true:

  • The MSSQLServer service account is not a member of the domain that the global group belongs to.

    -or-


  • The MSSQLServer service account is not a member of a domain that is trusted by the global group's domain.


The error message that you receive is:
Msg No 0, Severity 1, State 1
Unable to successfully query domain controller.


WORKAROUND

To work around this problem, do any one of the following:

  • Start the MSSQLServer service as the local system account.


  • Start the MSSQLServer service as a domain user account from the global group's domain, making sure that the domain user account is also a member of the local Administrators group on the SQL Server. However, if there are other global groups from other trusted domains, you will not be able to see those users unless the domain of the service account is trusted by the domains of the other global groups.


  • Instead of adding global groups to the local group on the SQL Server, add the users from the trusted domain directly to the local group on the SQL Server.



STATUS

Microsoft has confirmed this to be a problem in SQL Server version 6.5. This problem has been corrected in U.S. Service Pack 5a for Microsoft SQL Server version 6.5. For information about downloading and installing the latest SQL Server Service Pack, see http://support.microsoft.com/support/sql/.

For more information, contact your primary support provider.


Additional query words:

Keywords : SSrvStProc kbbug6.50
Version : winnt:6.5
Platform : winnt
Issue type : kbbug


Last Reviewed: November 17, 1999
© 2000 Microsoft Corporation. All rights reserved. Terms of Use.