Changing sql server service and sql server agent service startup account in SQL Server hosting SharePoint DB

Hi 
i have a sharepoint deployment with one SQL Server (running on VM) hosting the config DB and another SQL Server (Physical Host because VM was running out of space) to host the huge Content DBs. I need to schedule automatic backups of the Content DBs to a
network share. For that i need to run the SQL Server Service with an account having permissions to the share as suggested in https://support.microsoft.com/kb/207187?wa=wsignin1.0
I tried changing the logon as a service account to a domain
account which has permissions to the Network Share and is also in local Administrators group of SQL Server and has "public and sysadmin" roles in SQL Server but that caused an issue. the SharePoint Web Application started showing a White Screen so
I had to revert back to the default accounts i.e. NT Service\SQLSERVERAGENT and NT Service\MSSQLSERVER. I viewed the event logs . These are the types of error i got after changing the logon as a service account to a domain account
1) Information Rights Management (IRM): Retried too many times to initialize IRM client. Cannot retry more. Retried times is:0x5.
System
Provider
[ Name]
Microsoft-SharePoint Products-SharePoint Foundation
[ Guid]
{6FB7E0CD-52E7-47DD-997A-241563931FC2}
EventID
5148
Version
15
Level
2
Task
9
Opcode
0
Keywords
0x4000000000000000
TimeCreated
[ SystemTime]
2015-02-02T04:46:04.750899500Z
EventRecordID
176477
Correlation
[ ActivityID]
{8FACE59C-1E17-50D0-7135-25FDB824CDBE}
Execution
[ ProcessID]
6912
[ ThreadID]
8872
Channel
Application
Computer
Security
[ UserID]
S-1-5-21-876248814-3204482948-604612597-111753
EventData
hex0
0x5
2)
Unknown SQL Exception 0 occurred. Additional error information from SQL Server is included below.
The target principal name is incorrect.  Cannot generate SSPI context.
System
Provider
[ Name]
Microsoft-SharePoint Products-SharePoint Foundation
[ Guid]
{6FB7E0CD-52E7-47DD-997A-241563931FC2}
EventID
5586
Version
15
Level
2
Task
3
Opcode
0
Keywords
0x4000000000000000
TimeCreated
[ SystemTime]
2015-02-02T07:01:35.843757700Z
EventRecordID
176490
Correlation
[ ActivityID]
{50B4E59C-5E3A-50D0-7135-22AD91909F02}
Execution
[ ProcessID]
6912
[ ThreadID]
5452
Channel
Application
Computer
Security
[ UserID]
S-1-5-17
EventData
int0
0
string1
The target principal name is incorrect. Cannot generate SSPI context.

Hi Aparna,
According to your description, you get the above two errors when scheduling backups of Content DB. Right?
Based on those two error messages, they are related to the service principal name(SPN) for SQL Server service. Please verify the if the SPN is registered successfully. You can view it in ADSI Edit or use command line. Please see:
http://blogs.msdn.com/b/psssql/archive/2010/03/09/what-spn-do-i-use-and-how-does-it-get-there.aspx
When installing SQL Server, those two services below should be registered:
        MSSQLSvc/servername:1433      
        MSSQLSvc/servername
Please check if those SPNs or duplicated SPNs exist. You can use command to reset SPN or remove duplicated SPN and add new one. See:
Setspn.
We have also met this issue when this SPN is registered under Administrator. Please try to register it under Computer. You can add it in ADSI Edit.
If you have any question, please feel free to ask.
Simon Hou
TechNet Community Support

Similar Messages

  • Would like to change my security questions and answers on my Apple ID account??

    I would like to Change my Security questions and Answers on my Apple ID account??
    I have tried and have successfully reset my PW but I have forgot my answers to questions!!
    HELP Please!

    Alternatives for Help Resetting Security Questions and/or Rescue Mail
         1. If you have a valid rescue email address, then use this procedure:
             Rescue email address and how to reset Apple ID security questions.
         2. Fill out and submit this form. Select the topic, Account Security. You must
             have a Rescue Email to use this option.
         3. This is the only option if you do not already have a valid Rescue Email.
             These are telephone numbers for contacting Apple Support in your country.
             Apple ID- Contacting Apple for help with Apple ID account security. Select
             the appropriate country and call. Ask to speak to the Account Security Team.
         4. Account security issues almost always require you to speak directly to an
             Apple representative to securely establish your identity as the account holder.
             You can set it up so that Apple calls you, either immediately or at a time
             convenient to you.
                1. Go to www.apple.com/support.
                2. Choose Contact Support and click Contact Us.
                3. Choose Other Apple ID Topics and choose the appropriate topic for
                    your issue.
                4. Follow the onscreen instructions.
             Note: If you have already forgotten your security questions, then you cannot
             set up a rescue email address in order to reset them. You must set up
             the rescue email address beforehand.
    Your Apple ID: Manage My Apple ID.
                            Apple ID- All about Apple ID security questions.

  • MDM web services and the MDM BP services

    Hi *,
    I need to know what is the difference between the standard MDM web services and the MDM BP services.  How do I decide which set to use?
    - Kris

    Sorry but what are BP services? Do you mean Business package?
    If yes the approaches are completely different - you use Web Services when you have to customise the application and build your logic/functionality into the app. CRUD operations are procided by Web Services - you need to form your wrapper application from scratch and develop!
    With BP - it involves least development effort bearing in mind that its all standard content and not yet completely customizable. So based on your requirements plan whether to go for Business Package or Web Services or Java API completely...

  • Mail Services and Backup MX/mail services

    I have a question regarding backup mail services and acceptance of incoming messages.
    As of last week, I am new to the world of Mail Services in OS X Server 10.4. Last week, our current email server died and I was forced to take an Xserve G4 that had OS X Server 10.4.10 (unlimited) and setup mail services in order to receive and send mail. I went to a website called osx.topicdesk.com and followed their instructions for front-line spam defense and clamAV updating (and switching to clamd) which all appears to be working OK.
    Because our old email server was having some hardware issues for the past several months that I had been working on, I had the feeling that failure might happen. So what I did a few months ago was sign up for Google Apps and their mail service. I added their MX records under my primary mail server so that in the case of a failure of my server, all mail would be passed to Gmail and everyone could get to their mail immediately (as any prolonged downtime won't work since this is a daily newspaper). This did work, for when my old server died, all the mail went immediately to the appropriate Google Apps mail accounts. After about a day of setup on the Xserve, I got the mail services running OK. I gave it all the same IP info as the previous server so that the mail would just start working without having to edit DNS records and such.
    The problem I am having seems to be this: While I get most mail, some of my mail is still getting sent to the Google Apps accounts. For example, I have one user, Jane Doe, at [email protected] who gets most of their mail from connecting to the OS X Server, but about 2 - 3 emails a day get passed over to the Google Apps server. I have run DNSStuff.com tests on the mail connections, and I always get a good fast response out of the OS X server. My thinking was that mail would only be passed over to backup mail servers if the first server listed in the MX records was unavailable or offline. In all of my testing, my server has responded every time. The server is connecting via a gigabit network connection (good response), is a dual G4 1.33Ghz, 60GB hard drive with 2GB of RAM. This server doesn't do anything else except run Mail services (and web services for squirrelmail), it doesn't even have file sharing turned on.
    My old email server was a Pentium II 400mhz with 348MB of RAM, and it caught all mail, so I know that the Xserve should be able to handle the load without being busy. Is there any reason that my Xserve would be rejecting mail and they would be siphoned off to the Google accounts?
    Is this even a possible scenario to fix the problem: Setup a backup MX "queue" account somewhere with one of the BackupMX online services that will catch these stray emails and then send it back to the primary server? But then can be turned off quickly to allow mail to go to the Google Apps accounts if my server went down. In other words, the DNS record would show my primary as 1, the backup mx service as 2, the google servers as 3, 4, 5 and so on. Can Backup MX services be turned off quickly like that so that if my server is down and I need email to be accessed immediately then just "turn off" the service (without modifying the DNS since that will take too long to propogate) so that mail bounces over to Google immediately?
    I guess my first troubleshooting attempt should be to figure out why my OS X Server is not accepting all mail.
    Thanks in advance for any help and suggestions.
    G

    When I first started with the company about 2 years ago, they had a really old Linux box (about 10 years old) that was used to host email. It was horrible. It would run OK, but if it ever went down or had a hiccup, it was an all-day project trying to deal with it. Unfortunately, the company did not want to spend any money on a new server or software of course. The answer I got was "well, it's just email". Sure, but if email EVER goes down for more than 15 seconds, all of the employees go into seizures and scream that the place will have to shut down. I work for a daily newspaper, so everything is running 24/7.
    Knowing that one day that box was going to just die, I looked into some backup MX services. As pterobyte had mentioned is that with a secondary MX, the problem is that no one can get their mail at all until the primary server comes back up. I knew if that server ever went down, I had nothing to take its place, so I would have to order something or get a server from another location to use. Being unfamiliar with OS X Mail Services, I knew it would take me awhile to try to setup all the users and such. All the while at the newspaper, they would be screaming bloody murder that they needed email working for news, ads coming in, etc. And when I say if it goes down for 10 minutes they start getting into fetal positions in the floor screaming, I'm not far off exaggerating. I figured I was going to need something in place for them to check email while I worked on the primary.
    Back in September/October 2007, I discovered that Google hosted free mail services call Google Apps. With Google, I could setup "matching" accounts and would still be able to use my domain name. You just had to use Google's servers as the higher numbered MX records. Luckily, I set up in time for back in November, the Linux box finally died. When it did, all email successfully went to their counterparts on the Google's servers. I had everyone go to the special Google Apps login site and they were able to check their email fine. I ended up having to take a box from another site and then I had another copy of OS X Server 10.4, so I loaded it and successfully setup email (with lots of help from pterobyte's tutorials). They were on Google's systems for about 2 days.
    After the disaster, I went around and setup IMAP accounts on everyone's Thunderbird clients so that if our email server went down, they just simply check that mailbox. The nice thing with the Google IMAP is that they automatically see if emails are hitting that inbox from within their client. Right now, it still remains that the 2 original companies that hit the Google accounts still do. The city government email and email from a sister newspaper. Everything else gets directed to the primary server. Although sometimes that doesn't even work, as tonight I am having to work on a problem involving the Clamd app acting up - taking up nearly 100% of the CPU which in turn caused all the mail to be hung up in the queue. So since the mail server didn't "reject" the mail and grabbed it, their gmail "backup" didn't get anything in it. It was taking me forever to figure out what was going on, so I almost just told them to unplug the network cable from the email server so that everything definitely would be forwarded to gmail.
    My wish is that I had a secondary mail server in house to not even worry about it - or better yet, I wished I could just outsource the email administration itself to someone else (like webmail.us which is now MailSafe). That way for the most part, they wouldn't lose email. But of course, the company doesn't want to spend the money or invest. Just gripe when the older equipment we have won't support what they want to do with it.
    But the story above explains why I did what I did with the Google's servers. I do appreciate everyone's help and input on this particular problem. I am going to look around at the DNS and talk to at least our sister newspaper to see if I can see how they have their DNS setup.
    Thanks!
    G

  • Internal monitor ,debug service and Workflow Document Web Services Service

    hi,
    I have my production oracle apps:R12 12.0.6 ,RHEL 4
    showing following error in oracle forms:
    internal monitor showing actual 0 and target 1,debug service actual 0 and target 1 and Workflow Document Web Services Service actual 0 and target 1.
    Please reply urgently

    Hi,
    It means, those managers are down.
    1. Did you try to restart "Workflow Document Web Services Service" by clicking restart button from Administor Screen ?
    2. Were they up and running ? if yes, was there any recent change ?
    3. Please check internal manager log and look for any error
    4. Use the below Navigation to get more details
    From OAM > workflow > Service components > click Web Services OUT Agent > View Log
    Thanks
    Edited by: user763619 on Jan 16, 2011 9:53 PM

  • What is Field services and examples of field services in SAP

    Please can u tell me what is meant by field service in SAP and what are field services available in SAP.
    Best Regards
    KishoreKumar.T

    Hi,
    I'm not sure if that's what you mean but have a look <a href="http://help.sap.com/saphelp_nw2004s/helpdata/en/25/ef24234254e94ebdd35a83b3bf20f3/content.htm">here</a>
    Roy

  • O2UK: Why is my iPhone constantly picking up service, and then saying 'No Service' or 'Searching'?!

    My iPhone 3GS searches for signal, gets some signal then it drops out and says no-service and then starts searching again.. it worked fine yesterday.. and this morning only since i got to work has it stopped. I've even walked down to the local shop to try and get signal so its not the building i'm in. My partner has the same phone with the same carrier (O2) and has no problem.
    I am on O2 Simplicity, just upgraded from a blackberry.. at this rate looks like im going to have to go back to it beacuse i cannot use this phone like this..
    I will go to the applestore tomorrow.

    Maybe you are currently in an area of low signal? Or inside a thick-walled building?
    In my work office my phone does this as they have some tin-foil type insulation which the phone signals can't penetrate well.

  • I have just changed my ID password and I can not access my account.

    I have just changed my ID password and I cannot access my account.

    If you are referring to your user ID on your Mac:  https://discussions.apple.com/thread/5478030?tstart=0

  • Oce, Print server/Qserver and NDPS Printer agents

    We have an Oce TDS600 (the controller for an Oce 9600 plotter and a large format scanner). We tried a long time ago to set it up as a NDPS printer but it never worked right. We then went to the tried and true queue based printing (printer, print server and queue) and things were cooking along well until we upgraded the server hosting all of this from NW 5.1 to NW 6.5. Two of the three printers being serviced through "qserver mode" would not print. The main printer we use, the Oce was one of these (the other was an HP 2800CP large format color inkjet plotter). the printer that kept working was a Xerox DocuColor 3535.
    The only clues we had were that the print server was listed as being down. We tied recreating the printers, print servers and queues, no joy. After a day of panic, the only thing that got it working was to set up NDPS printer agents and have them service the queues through LPR. This broke the log jamb and allowed us to get the back log of print jobs in the queues.
    So, what did I mess up? What about NW 6.5 doesn't like legacy printing? We still cant print directly through the NDPS Printer agents, but we can print through the queues. There are LPR communication problems between the PA and the TDS600 controller. I couldn't find anything on the naming for the LPR printer for this model of Oce Printer (the external controller is not an EFI fiery) so I left it at the default of "PASSTHROUGH".
    Any clues?

    Daniel,
    > So, what did I mess up? What about NW 6.5 doesn't like legacy printing? We still cant print directly
    through the NDPS Printer agents, but we can print through the queues. There are LPR communication
    problems between the PA and the TDS600 controller. I couldn't find anything on the naming for the LPR
    printer for this model of Oce Printer (the external controller is not an EFI fiery) so I left it at the
    default of "PASSTHROUGH".
    >
    Well, PASSTHROUGH is virtually always wrong. The following TID gives the correct name to use for a
    number of printers:
    http://support.novell.com/cgi-bin/se...?/10080373.htm
    If your printer is not listed, then check the printer documentation. While many printers do not include
    instructions on how to use the printer from Novell's NDPS or iPrint, they generally include instructions
    on how to access the printer from Unix machines or from Windows machines using LPR. In those
    instructions or sample configuration files, you generally find the correct name to use in the LPR
    configuration.
    Marcel Cox
    Novell Support Connection SysOp
    http://support.novell.com/forums/

  • Please help me to fix the problem of my iphone 3gs, its says no service and could not activate your phone...the server is temporrili unavailable,try to connect it to itunes or wait a few minutes...i tried maany times but it does'nt work..please help me

    had a problem with my iphone 3gs.it came from recovery mode,after it it says no service,then activate your iphone..then i follow the steps appeare in the screen..after it it sys could not activate your phone.the server is temporrily unvailable or try to connect to itunes..I tried it many times since january 30 2013 night time.until now it does'nt work...how can u help me to fix my iphone..thanks

    so what cn u suggest to do to operate again my phone..

  • Managed Metadata Service and Content Type Hubs - Service Connection necessary?

    I created a site collection and activated the content type hub feature at the site collection level. We have an existing managed metadata service but I am unable to edit its settings, so I created a new MMS in a new database, however; there is no "service
    connection" row below the MMS row for the new MMS Application, but there is one for the old MMS Application. Will this still work with my content type hub? If not, how can I get the service connection setting/row? I have to do this via PowerShell since
    the menus in the ribbon are not usable due to our JavaScript settings...

    Are you using Custom claim provider??
    If you are then try this:
    http://social.technet.microsoft.com/Forums/sharepoint/en-US/120ab535-63d2-4205-a51f-1987e9c0cf79/sharepoint-fba-the-content-type-texthtml-charsetutf8-of-the-response-message-does-not-match-the
    http://www.chapmanconsulting.ca/post/2010/04/23/The-Case-of-the-Failing-SharePoint-2010-FBA-Configuration.aspx
    #RoHsTr

  • Taxonomy feedback service, and all other collaboration services

    Although feedback service is enabled in the taxonomy repository, which
    is based on a CM repository hosting the files, feedback is not possible
    on the taxonomy Iview.
    Here some details:
    this is the Displayed Properties in the CollectionRenderer for the
    layoutset:
    rnd:icon,rnd:displayname(contentLink),rnd:action, rnd:command
    (command=give_feedback/style=small
    button),contentlength,modified,modifiedby,created
    this is what i see in my iview:
    ICON Name actionhover 24 KB 15.11.06 Plotkowiak, Thomas 15.11.06
    17:17:25
    I am missing here the feedback function button.
    When I apply the same thing, to the CM repository everything works as
    it should, but when it is applied to the taxonomy all the collaboration
    services do not work.
    All the services are enabled on the taxonomy (see below)
    Repository Services
    Name
    comment
    feedback
    layout
    personalnote
    properties
    rating
    subscription
    Page 1 / 1
    I am using EP6 SP17.
    Thank you for your help.

    Hi Thomas,
    I've got a similar problem in my portal which is EP 7.0 SP9. Giving feedback wasn't enable regardless of setting appropriate command in CollectionListRenderer's property 'displayed properties'. We've created OSS message and they said that this is a bug and there is no workaround available till SP10. You should try to check the latest SP release for your portal version. There could be a solution of your problem.
    Regards,
    Michal

  • I need to change my admin password and im logged into the admin account now ..but i do not remember the original password.. how do i do that?

    im unsure of operating system... got it in aug of 2011

    Forgetting""" passwords etc..
    Here's a Tip...within your Address/Contacts - use a psuedo name/within the phone number/email address
    insert the password...

  • Question : Service Accounts for SQL Server 2012

    Hello,
    I am planning to create AD accounts for SQL Server 2012 services that will be installed on Windows 2012 server.
    I was reading the following
    Configure Windows Service Accounts and Permissions
    and
    Windows Privileges and Rights
    Is there a recommendation / document that would list that assocation of SQL Server Services with Actvie Directory service accounts / privileges required for installation and starting the services.
    Isn't it recommended to create separate account for every service and they should not be local accounts ?
    Hope to hear soon as to what industry standards are being followed for production systems ?
    Thank you very much in advance.
    Regards
    Nikunj

    From MSDN:
    Each service in SQL Server represents a process or a set of processes to manage authentication of SQL Server operations with Windows. Each service can be configured to use its own service account. This facility is exposed
    at installation. SQL Server provides a special tool, SQL Server Configuration Manager, to manage the services configuration.
    When choosing service accounts, consider the principle of least privilege. The service account should have exactly the privileges that it needs to do its job and no more privileges. You also need to consider account isolation; the service accounts should
    not only be different from one another, they should not be used by any other service on the same server. Do not grant additional permissions to the SQL Server service account or the service groups.
    From Glen Berry's Blog:
    You should request that a dedicated domain user account be created for use by the SQL Server service. This should just be a regular, domain account with no special rights on the domain. You do not need or want this account to be a local admin on the machine
    where SQL Server will be installed. The SQL Server setup program will grant the necessary rights on the machine to that account during installation.
    You will also want a separate, dedicated domain user account for the SQL Server Agent service. If you are going to be installing and using other SQL Server related services such as SQL Server Integration Services (SSIS), SQL Server Reporting Services (SSRS),
    or SQL Server Analysis Services (SSAS), you will want dedicated domain accounts for each service. The reason you want separate accounts for each service is because they require different rights on the local machine, and having separate accounts is both more
    secure and more resilient, since a problem with one account won’t affect all of the SQL Server Services.
    Depending on your organization, getting these domain accounts created could take anywhere from minutes to weeks to complete, so make sure to allow time for this. For each one of these accounts, you will need their logon credentials for the SQL Server setup
    program. You are going to want to make sure that the accounts don’t have a temporary password that must be changed during the next login. If they are set up that way, make sure to change them to use a strong password, and record this information in a secure
    location.
    Please Mark This As Answer if it solved your issue
    Please Mark This As Helpful if it helps to solve your issue
    Thanks,
    Shashikant

  • Pass Server Info and find service existed or not

    Hi All,
            I have written batch code which is running fine to find weather service is existed or not.But I want to pass parameter which holds server name and find weather the service is existed or not .Can any one help me how can i do it
    @echo off
    net start | find "SQL Server Analysis Services (MSSQLSERVER)" > nul 2>&1
    if %ERRORLEVEL%==0 echo "MS SQLServer Analysis Service running"
    if %ERRORLEVEL%==1 echo "MS SQLServer Analysis Service not running"
    Pause
    Samar

    I would highly recommend that you start to learn PowerShell, instead of trying to work with batch files at this point.  It's the future of command-line functionality in Microsoft products, and it's going to be harder and harder to find tools that enable
    you to perform the same tasks on the old command prompt.
    For this specific question, though, all that's missing from JRV's example is the /node:"ComputerName" parameter to wmic.exe.

Maybe you are looking for

  • Outlook 2010 / 2013 Send on Behalf of does not cache Resolved email address in the From Dropdown

    This is insane Microsoft. Makes me wonder if you use your own product Office 2013 / Exchange 2010 - Proper mail box permission - Proper Send On Behalf of Permission 1. Open A Message > Select From > Choose Other Address > Choose From Again > Pick the

  • Keep getting error 69 with iTunes 5.0, and it wont let me

    keep getting error 69 with iTunes 5.0... Im pretty sure its the version's fault, but it wont let me install a previous version I have on CD either. Even after uninstalling iTunes I get error "1623: installation failed" everytime I try to install the

  • How do you when Ipod's battery is dead?

    Accidently left my cased ipod in my jacket pocket and threw it into the wash. It was only in there for a couple of minutes but thats all it took. I knew the Ipod wasn't too wet because I couldn't see any water under the screen, but the battery was go

  • Help! My monitor suddently switches to 16 colors

    While working on my computer Mac Pro, my monitor DELL 2407FPWs uddenly changes from millions to 16 colors by itself. I went to Display in System Pref and it still shows Millions of color. This problem only affects my account and no other accounts are

  • Load order in wls 7 sp4

    Hi, I have a strange problem with the load order in wls 7.0 sp4. I have 2 ear files ear1 and ear2. I have one war file in each of the ear files. I set the load order of ear1 to 1000 and ear2 to 100. I see the load order in the console correctly, but