Add login to sql 2012 server for a virtual account from another sql 2012 server

I have two sql 2012 servers. 
Server A has sql server agent running virtual account: NT Service\SQLSERVERAGENT
Server B has some databases.
Server A is running a scheduled SSIS package that needs access to Server B's databases via Windows Auth
Thus I want to grant access by creating a login on Server B to the virtual account on server A: NT Service\SQLSERVERAGENT
Q1 - Is this possible?
Thanks beforehand.
Paulino

Raul,
As a matter of a test and not with the actual intention to use it this way, I did try to add a login using the DOMAIN\MACHINE_NAME$
concept but it did not work anyway. I will not find it.
So I will use one of the approaches recommended by Mr. Gallardy
Thanks!
Paulino

Similar Messages

  • CHARM error - No Target system for Normal transport generated from another client

    Hi Gurus,
    This is regarding normal change. We have two clients in development. (Workbench and Customizing)
    We were trying to do Automatic import from development client to Quality. When importing the job, I’m getting an error related to Project Status switch. "you cannot import any request for the project at the moment" It works fine for another development client and we can see the target system in Project status switch.
    But, checking the Project Status switch, looks like there’s no Target System defined for Normal transport generated from another client of development.
    I attached some screenshots related to this.
    Can you please help how to add a target system for another client of development ?
    Regards,
    Salman

    yes, client 110 is present in the task list of the project. yes route is defined because it is working for urgent change

  • Can i re-add my device to my icloud account from another device ?

    i lost my iphone 4s ios 7.0.1 it was stolen . i signed in to my icloud from another device and tried find my iphone the mobile was offline but i requested erase my iphone then i knew that after erasing i wouldn't be able to locate it  i read that no way to stop the erase request ( even if it isn't erased yet ) but i read that i can stop erasing by deleting my device from account . if i deleted it can i re-add it by any way or is there any way to stop erase request ?

    Welcome to the Apple Community.
    Some have reported that removing the device from Find my phone stops the erase command, however I haven't verified this.
    If you remove a device from Find my phone, there is no reason it can't be added back at a later date, but this must be done from the phone itself.

  • Is it advisable or practical to run SQL Agent with Account from another domain?

    A SQL Server in domain A needs to mount databases downloaded on a weekly basis to a second SQL Server, in domain B.
    Right now, the two domains, which were deliberately separated for security, have no trust.
    Currently, a manager of the server in domain A uses credentials in domain B to logon to domain B and do a file copy of the databases, which he then mounts on the server in domain A.
    Having noticed that the best way to place a copy of a database onto a remote server is via SQL backup, as opposed to a file copy, because it is five times faster, and suspecting that a SQL restoration
    operation might be as much faster than the current file copy from domain B to A, the idea has been floated that the SQL Agent in domain A could schedule a restoration from databases residing on the hard drive of the server in domain B.
    Can credentials of an account in domain B be used to drive the SQL Agent on the server in domain A, and if so, does this require the establishment of a trust? I suspect that it would, although
    once a user of the server in domain A establishes a connection to a file share in domain those credentials are cached for future use.
    Would using an account in domain B to logon the SQL Agent in domain A -- with or without a trust -- cause all the jobs in domain A to fail on the grounds of missing permissions?

    Thank you for your prompt reply.
    The FTP download seems technically feasible. But, I think, the FTP transfer would not provide the speed our organization has been looking for. We are making do with 100Mbps where we actually
    need 1Gbps.
    The SSIS proposal is not feasible because a trust between the two domains would not be allowed. In any event, if it were a straight file copy, not a SQL backup, we would not obtain the speed
    we seek. You mention, in this context, a 'file copy.' Is this a simple copy from an arbitrary TCP port on Server B to port 445 on server A, or is it a different type of copy, such as that used when a SQL runs a backup job to a network destination?
    What do you think of this: in domain B, where the files reside, use the proxy account to run a backup job to the server in domain A. That would give us the speed we need. But that would also
    require a trust, wouldn't it? Is there any way to get around the need for the trust? If the backup job could run from server in domain B to the server in domain A, another job could be setup on server in domain A to complete the restore.
    When I create the SQL Proxy, do I supply the name of the account in the trusting domain?  When I look at the dialog for the creation of the "new proxy account" on a server without trust
    connections, I am offered only two GUIDs as candidate proxies.  Would that change once I create the trust, and would I be allowed to browse accounts in the trusting domain?
    Are you familiar with the dramatic advantage taht a SQL backup job holds over a copy of files from point A to point B? It's something like ten times faster.
    Yours,
    Bob Hindla.

  • My Mac Outlook 2011 Stopped Sending Emails for all POP Accounts from Different Providers

    I've had this problem before, but this time I am truly dumbfounded. My Outlook 2011 has randomly stopped sending emails, but I can still receive them. This has happened a few times and I normally change the ports/SSL and I can get it to work. But now I am at a loss. I have several email accounts that I manage. One of which is GMAIL, using IMAP, and this is the only account that currently works find receiving and sending. My POP accounts, four of them, all cannot send emails. They can only receive. One of them is with GoDaddy, and the other three are with an Asian company. I can't find any help on this. I've upgraded Office to the latest version. I've even deleted the accounts and added them back in, and I still can't send email. I'm frankly getting exhausted and sick of this type of problem happening. I honestly use this program and my MacBook Air to send clients information...only to find out hours later that a mail never sent because it's been stuck in my <hidden> Outbox in Outlook 2011. This has hurt me now badly on several occassions. Please HELP!

    All SMTP servers are set correctly as far as I can tell, the connection doctor says everything is fine, and I removed all my accounts to re-add them.  I added one and tried to send a message--stuck in the outbox--failed.  I added another account and deleted the first one and tried to send a message--stuck in the outbox--failed.  I'm pretty convinced the problem is with Mac's Mail client...I can send email from anywhere I've tried except for Mac's Mail client.  Thanks for the help.
    MtM

  • How can I set the file name and folder for output to PDF from another application?

    I am developing an application in Microsoft Access where the printed reports are to be saved in PDF format for archive purposes. I can send the output to Adobe X, but the default file name is the Access report name and the folder selected is the one last used.
    What I need to do is to create the file with a specific name (which changes for each run) and to a specific folder (which also changes for each run).
    The language I'm using is Visual Basic for Applications which is located in an Access form that controls the report production.
    Any suggestions, please?

    Got it - many thanks.

  • Authorizations set for one query different from another query

    Hello All,
    Here is my requirements for 2 differents BW queries :
    For some particular user
    1-Query A have to show data from company code 1 & company code 2
    2-Query B have to show data from company code 1
    How can I manage such authorization with RSEACADMIN ?
    I was thinking of using infoObject 00TCTQUERID .
    What do you suggest ?
    I will try to do some test and come back later with my tests results.
    Regards
    Catherine

    Hello,
    Thanks for your help on this. I will not use query restrictions with S_RS_COMP or  S_RS_COMP1.
    Also, Query A and query B are created on the same cube, so I cannot use 2 differents analysis authorization. I wish I was able to say this analysis authorization applies to query A and this analysis authorizations apply to query B.
    So far, this is not possible.
    I think my only possibility is to create a multiprovider and copy query B to this multiprovider. Then I will create 2 differents analysis authorizations for each cube.
    I don't think that I will find a better solution.
    I will test it asap.
    Regards
    C.

  • Execute BBP_BID_INV for specific bid invitation from another transaction

    Hi!
    Is it possible to start BBP_BID_INV in web-interface mode for some specifig bid invitation (in display or change mode) from webdynpro application?

    Kathirvel,
        Thanks for your answer, i will use this function, but i found a flag to process the function BBP_PD_BID_CREATE in bapi mode (I_BAPIMODE = 'X') and after put this flag the BID was generated.
    Regards,
    Roberto Aran

  • Corrupt hard-drive, swapped for an older drive from another similar MacBook Pro

    My original hard drive is corrupt, I swapped to an older drive which has snow lepoard on it, when installing Yosemite it freezes now i cant boot into the old OS and installer freezes extracting.
    Disk utility says the disk is fine, with no issues.
    The original disk failed and would not boot, disk utility says it was corrupt. I have another MacBook pro so i swapped the HD's, it is 320GB compared to the 500GB (failed drive).
    It was working fine on Snow Leopard but when I ran the upgrade in the App Store, it freezes everytime at the same point in the install ( extracting the same .pkg file).
    Any ideas?

    You apparently have a MBP that came with an OSX newer than Snow Leopard.  If that is the case, the Snow Leopard HDD will not boot in the newer MBP.  If you erase that HDD and install the OSX that came with your MBP (or a newer one), then it will be compatible.
    Ciao.

  • Calendar sync broken for Google Apps accounts

    The Calendar no longer syncs with my Google Apps account; not in either direction.  It pops up the sync notification and reports success, but nothing changes.  I tried removing and adding the account.  This actually broke in 1.2.1, but by the time I noticed, I assumed a fix was around the corner.  1.3.1 didn't help.  I even created a brand new test account using the newly enhanced support for Google Apps.  Mail and contacts work fine, but the calendar won't budge.  Palm, I can give you the test account to play with if you'd like.
    My standard Gmail account calendar syncs just fine.  Saw the troubleshooting for standard account calendars and tried playing with the invitation options in my Apps account to no avail.
    Post relates to: Pre p100eww (Sprint)

    #1 is good already.  I tried changing the other differences: Default View was month, Location had my zip code, Automatically Add Invitations was set to Yes.
    #2 using network settings correctly had me in Central, but it said Regina, Canada.  Changed it to Chicago and rebooted, but I'm still not syncing either way on my account nor the test account.
    Here's the really odd thing.  My Pre has all four of your entires on the test account from the 3rd and 4th.  I just tried creating entries for the test account from both my Pre and desktop, and I'm not seeing any syncing.  I've forced it about five times over the past 20 minutes.
    Sounds like we're down to it either being homebrew's fault or something stuck in my launch day profile that would survive a wipe.  I wiped my phone under 1.3.1 to undo a lot of homebrew cruft, but I still can't say I ever tested this in a virgin state.  Enh.  Go ahead and close the ticket.  My workaround is fine with me.  Feel free to keep using the test account for other stuff if you want.

  • Licensing for Windows Virtual Desktops (VDI) - do I need Virtual Desktop Access (VDA) licenses?

    Hello.  I am trying to figure out what type of licenses I need to achieve the following:
    - Windows Server 2008 R2 running Hyper-V
    - 25 virtual desktop on Hyper-V running Windows 7 Professional
    Do I need a "full" license of Windows 7 Professional for each virtual machine, AND another license (let's say maybe Windows 7 Starter) running on the actual PC's that the users will be using?
    I came across this article regarding Virtual Desktop Access licenses, do I need that?  Or would I be fine just purchasing 1 copy of Windows 7 for each PC?  In that case should I choose Starter or Professional?  The desktop PC's that users
    are using are older Pentium 4's so I wanted to keep the load on them minimal.
    Thanks!

    Hi,
    Please check the following links.
    Microsoft’s new VDI licensing: VDI Suites
    http://blogs.technet.com/b/virtualization/archive/2009/07/13/microsoft_1920_s-new-vdi-licensing_3a00_-vdi-suites.aspx
    Virtual desktop infrastructure delivers the flexibility you need
    http://www.microsoft.com/windows/enterprise/solutions/virtualization/improve-flexibility.aspx
    Licensing Windows for VDI Environments
    http://download.microsoft.com/download/5/0/5/5059CBF7-F736-4D1E-BF90-C28DADA181C5/Microsoft%20VDI%20and%20Windows%20VDA%20FAQ%20v2%200.pdf
    Best Regards,
    Vincent Hu
    Does this article still applicable for Windows 7 or Windows 8.1 VDI deployment ?
    /* Server Support Specialist */

  • Secure login to sql 2012 database for webusers

    We build up a new website in .net mvc 4.0 on a w2012 server with MSSQL 2012 database.
    We use windows autentification and normal anonymous access through NT AUTHORITY\IUSR who is also a login in the database.
    But we make extra login possibility for users who are registered and they can insert and modify data in some tables in the database. And I'am afraid of giving NT AUTHORITY\IUSR insert and update for some column in tables.
    I think of set up a new login for the database. Run a new connection string on login and set up special permission for that extra user on the database, set up a new role and let the new user become member, but also let the user become a member of the ordinary
    user(roles) in the database.
    Have anyone any idea what is the best practice here and the most secure way to do it? 
    Any links for other resources about this topic?
    Or perhaps my fear for using NT AUTHORITY\IUSR is groundless
    And perhaps someone has links to resources for using SQL server as a backendserver for websites. 
    Knut from Norway!

    I don't know much about web servers, which may explain your alternatives entirely.
    But, if you use the same connection string for reads that you do for updates, then you must control all permission for writes in the web app. And you must be sure that you only use parameterised SQL or stored procedures, so that there is no risk for SQL
    injection.
    If you give special logins for the users with read access, they would need their own accounts in SQL Server. If this is an intranet site, the web server may be able to impersonate these users and then connect to SQL Server. If that does not work out, you
    would have to create SQL logins for these.
    Obviously, this requires more administration, but it is also more secure, because you are adding a line of defence. Even if your application is free from SQL injection vulnerabilities today, some new badly educated kid on the block could open a hole two
    years later.
    Erland Sommarskog, SQL Server MVP, [email protected]

  • Install Active Directory Domain Controller on Windows server 2008 enterprise, dont login on Sql Server 2008 R2

    I install Active Directory Domain Controller on Windows server 2008 enterprise and dont login on Sql Server 2008 R2. Before install ADDC, I have logon SQL Server 2008r2 Success, After when i install ADDC is don't logon on SQL Server 2008r2 -->not success.
    I have uninstalled ADDC but i still can't login on SQL server 2008r2.
    please help me. it  is very very disaster!
    I think is loss account SQL server 2008r2!

    Hello,
    I stronly recommend you post the detail error message to us while you try to connect to SQL Server instance, it's useful for us to do further investigation.
    Microsoft recommends that you do not install SQL Server 2008 R2 on a domain controller, there are some limitations:
    You cannot run SQL Server services on a domain controller under a local service account or a network service account.
    After SQL Server is installed on a computer, you cannot change the computer from a domain member to a domain controller. You must uninstall SQL Server before you change the host computer to a domain controller.
    After SQL Server is installed on a computer, you cannot change the computer from a domain controller to a domain member. You must uninstall SQL Server before you change the host computer to a domain member.
    SQL Server failover cluster instances are not supported where cluster nodes are domain controllers.
    SQL Server Setup cannot create security groups or provision SQL Server service accounts on a read-only domain controller. In this scenario, Setup will fail.
    On Windows Server 2003, SQL Server services can run under a domain account or a local system account.
    So, I would suggest you try to open up Windows Services list and changed the account for SQL Server service.
    Regards,
    Elvis Long
    TechNet Community Support

  • SQL Server 2012 Express Install on Windows 7 SP1 Embedded not using virtual account?

    Hi there,
    I did a default installation of SQL Server 2012 Express on Windows 7 embedded Standard SP1.
    When I look at the SQLSERVER service credential it is configured to run under "NETWORK SERVICE" instead of the virtual account "NT SERVICE\MSSQL$SQLEXPRESS".
    This is different from SQL 2012 Express installation on a non-embedded Windows 7.
    Why is this difference?
    Secondly, because of this, I am unable to take a backup of databases to any folder other than the default SQL folder.

    Hi Chandrasekaran,
    As Local Service account, the Network Service account and high privileged Local System account could be used by many services.
     It becomes harder to track which service is actually accessing resources and performing actions, because all the services are using the one Network Service account or other account.
    In Windows7 and Windows Server 2008R2, it introduces a new type of account called a virtual account, which emulates creating many unique instances of the Network Service account, so each service runs with its own instance of the Network Service account.
      For example, when you install SQL 2012 on Windows Server 2008 R2 or Windows 7 and later you’ll see the services run with virtual service accounts named like:
    in the format NT SERVICE\<SERVICENAME>.
    According to your description, when the SQLSERVER service was run under “NETWORK SERVICE”, you only back up database to the default SQL folder. It may be caused by the NETWORK SERVICE account has limited local privileges, just accesses network
    resource with the computer credential. I recommend you change the account to Local System account, by default, which has full permissions on your computer.
    For more information about SQL Server service account and virtual account, you can review the following articles.
    http://www.travisgan.com/2013/06/sql-server-service-account-and-per.html
    http://www.sqlservercentral.com/blogs/sqldbauk/2014/01/13/sql-server-2012-and-virtual-service-accounts/
    http://msdn.microsoft.com/en-us/library/ms143504(v=sql.110).aspx
    Regards,
    Sofiya Li
    Sofiya Li
    TechNet Community Support

  • After sql server 2012 installation, I have changed sql server database engine service account from network service user to system user. What is disadvantages of this process?

         After
     sql server 2012 installation, I   attached my production db. Because of some reasons, i
     changed sql engine account from network service user to system user by means of sql server configuration manager.
         Now , there isn’t
     a problem at sql server running system.  But
    I have doubts that
     this can produce problems later. Because  sql server database engine account must have privileges that listed below;
    Log on as a service (SeServiceLogonRight)
    Replace a process-level token (SeAssignPrimaryTokenPrivilege)
    Bypass traverse checking (SeChangeNotifyPrivilege)
    Adjust memory quotas for a process
    (SeIncreaseQuotaPrivilege)
    Permission to start SQL Writer
    Permission to read the Event Log service
    Permission to read the Remote Procedure Call service
     While sql server installation, setup gives these
     privileges to network service user automatically, but changing user by means of sql confugarition manager does not give these
    privileges.
    Now, system user has privileges listed below. And sql server has been running for 1,5 months without any problems.
    Log on as a service (SeServiceLogonRight)
         Bypass traverse checking
    (SeChangeNotifyPrivilege) (Everyone user has his privileges. So i think that system user has this privilege also)
    What problems can occur because of this situation? Shall i give other privileges to system user and restart sql server or not? And how can i give these privileges to system user listed below;
    Replace a process-level token (
    this can be set from user rights assignments)
    Adjust memory quotas for a process
    (this can be set from user rights assignments)
    Permission to start SQL Writer ( 
    ? - give advice )
    Permission to read the Event Log service (
    ? - give advice )
    Permission to read the Remote Procedure Call service (
    ? - give advice )

     Our server is  windows server 2008 r2 enterprise edition. I have looked the bunch of permissions in user rights menu  that is in local security policy settings gui.
    And i have seen those permissions below were not granted to system user;
    Bypass traverse checking (SeChangeNotifyPrivilege)
    Adjust memory quotas for a process
    (SeIncreaseQuotaPrivilege)
    So, briefly you say, don't panic ?

Maybe you are looking for