Query windows connection with domain logins

My sql server is in SaaS environment. and mixed mode authentication.
Scenerio 1:
Now i have open query windows of sql server and suddenly my domain controller crashed. Would i still able to fire query or not?
Scenerio 2:
Now i have open query windows of sql server and run query. While running query, My DC crashed.. Would it be give result or continue to run? 
I am confused with this scenario and not getting clear answer what exactly happening behind.

If I understand your question correctly, you already have established a session on SQL Server using a domain account, and you want to know what happens with that open session if the DC crashes, correct?
Regarding whether or not you can continue running queries, the answer is a bit tricky as it depends on the scenario as a whole, but you probably shouldn’t rely on it.
The SQL token within the session will probably still be valid since you have already authenticated yourself to SQL Server, but any statement that may use external resources or that may try to access the session Windows token will likely fail and potentially
even terminate the session.
I would strongly recommend having some redundancy on your system, and consider having a read-only DC (RODC) to make sure that you don’t have downtime in scenarios such as this one.
I hope this information helps.
-Raul Garcia
SQL Server Security
This posting is provided "AS IS" with no warranties, and confers no rights.

Similar Messages

  • Unable to make RMI-based JMX connection with post login stored admin creden

    Hello,
    I've installed a stand-alone OC4J on a couple of servers with Red Hat Enterprise Linux Server release 5.1 (Tikanga).
    At one server I am not bale to start the OC4J properly.This server has two network adresses.
    2008-09-08 14:33:12,670 [EMUI_14_32_57_/console/postLogon] WARN app.PostLogonPageHandler testStoredCredentials.490 - unable to make RMI-based JMX connection with post login stored admin credentials
    java.net.ConnectException: Connection refused
    at java.net.PlainSocketImpl.socketConnect(Native Method)
    at java.net.PlainSocketImpl.doConnect(PlainSocketImpl.java:333)
    at java.net.PlainSocketImpl.connectToAddress(PlainSocketImpl.java:195)
    at java.net.PlainSocketImpl.connect(PlainSocketImpl.java:182)
    at java.net.SocksSocketImpl.connect(SocksSocketImpl.java:366)
    What could be the reason of this error? And how can I solve the problem?
    Thanks in advance,
    Regards Leon

    I don't know for sure, but perhaps the password encryption method uses something from the server to generate a key/seed for the encryption?
    Try and manually reset the credentials to see if it helps
    1. Edit the j2ee/home/config/system-jazn-data.xml file.
    2. Find the oc4jadmin user entry and modify the credentials tag to look like the following
                   <user>
                        <name>oc4jadmin</name>
                        <display-name>OC4J Administrator</display-name>
                        <guid>B23216B0102E11DDBF9DE5D93DCAFE54</guid>
                        <description>OC4J Administrator</description>
                        <credentials>!welcome1</credentials>
                   </user>3. Restart the container and see if you can then login using oc4jadmin/welcome1.
    No guarantees, but its worth a shot.
    -steve-

  • Speeding Up Windows 7 Professional Domain Logins

    Anyone know how to speed up domain logins my domain logins can take over a minute sometimes and idk why i went threw the dns and deleted a bunch of old un needed rcords and bought a gigabit switch that helped a bit, i even enabled "Wait For Network
    At Statup And Logon" In group policy another inportant note is that all my workstations are frozen with Faronics Deep Freeze so the user profiles do not stay cached and i have folders redirected to the server like the favorites folder and the documents
    folder but i dont see the problem other than the non cached profiles anyone got any quick tips or tricks would be very helpful thanks :D
    Server OS: Windows Server 2008 Enterprise x86
    Server NIC: Broadcom PCI Fast Gigabit Ethernet Card
    Any Other Needed Details Can Be Posted Here If Needed.
    Viper Technologies Computer Repair Putting The Venomus Bite Back In Your Computer We Are Located In Antigonish ,NS Canada Check Us Out HTTP://WWW.VIPERTECHNOLOGIES.TK

    Domain Controller/DNS Server These Settings Are Mostly Set Manually On The Server
    Ethernet adapter Local Area Connection:
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : Embedded Broadcom NetXtreme 5721 PCI-E Gi
    gabit NIC
       Physical Address. . . . . . . . . : 00-17-A4-0D-E9-FB
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
       Link-local IPv6 Address . . . . . : fe80::1087:ae2a:f484:489%10(Preferred)
       IPv4 Address. . . . . . . . . . . : 192.168.3.10(Preferred)
       Subnet Mask . . . . . . . . . . . : 255.255.255.0
       Default Gateway . . . . . . . . . : 192.168.3.105
                                           192.168.3.1
       DHCPv6 IAID . . . . . . . . . . . : 251664292
       DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-17-97-3C-2D-00-17-A4-0D-E9-FB
       DNS Servers . . . . . . . . . . . : ::1
                                           192.168.3.10
       NetBIOS over Tcpip. . . . . . . . : Enabled
    Client Machine Info Over Wireless LAN (Settings Are Same For LAN Clients)
    Wireless LAN adapter Wireless Network Connection:
       Connection-specific DNS Suffix  . : ZIRICOMc
       Description . . . . . . . . . . . : Intel(R) Centrino(R) Advanced-N 6235
       Physical Address. . . . . . . . . : C4-85-08-CE-5E-F0
       DHCP Enabled. . . . . . . . . . . : Yes
       Autoconfiguration Enabled . . . . : Yes
       Link-local IPv6 Address . . . . . : fe80::9596:2096:57b6:ba61%13(Preferred)
       IPv4 Address. . . . . . . . . . . : 192.168.3.19(Preferred)
       Subnet Mask . . . . . . . . . . . : 255.255.255.0
       Lease Obtained. . . . . . . . . . : Wednesday, May 01, 2013 12:33:46 AM
       Lease Expires . . . . . . . . . . : Wednesday, May 01, 2013 12:57:03 AM
       Default Gateway . . . . . . . . . : 192.168.3.105
       DHCP Server . . . . . . . . . . . : 192.168.3.10
       DHCPv6 IAID . . . . . . . . . . . : 298091784
       DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-18-6F-74-E2-C4-85-08-CE-5E-F0
       DNS Servers . . . . . . . . . . . : 192.168.3.10
       Primary WINS Server . . . . . . . : 192.168.3.10
       NetBIOS over Tcpip. . . . . . . . : Enabled
    Viper Technologies Computer Repair Putting The Venomus Bite Back In Your Computer We Are Located In Antigonish ,NS Canada Check Us Out HTTP://WWW.VIPERTECHNOLOGIES.TK

  • Windows 8.1 Domain Login VERY SLOW.

    Hi
    I have 2 labs of Windows 8.1 machines, I7's Processors with 8 gig of memory and a login to the domain can roughly take 3-5 minutes. Have anyone of you that also have windows 8.1 running in a lab environment experienced slow domain logins? We do not use roaming
    profiles in our environment?
    My default profile is about 250 megs, I have cleaned the profile the best I can, there is no temp files or downloads in the profile.
    I have noticed the webcache is quite big 35 megs thats in the profile is there anyway to delete this?,
    Can anyone suggest anything I can look into? to speed things up to get the login to a reasonable time?.

    Hi,
    I recommend you check this solution of this issue:
    When Logging into a Windows Domain is SLOW...
    http://www.oregontechsupport.com/articles/domain-login-slow.php
    Please Note: Since the website is not hosted by Microsoft, the link may change without notice. Microsoft does not guarantee the accuracy of this information.
    Kate Li
    TechNet Community Support

  • Windows 2003 Server Domain Login issues

    We have installed Windows 2008 R2 Servers in our existing environment which was running on Windows 2003 R2.  I have configured Windows 2008 as DNS and Global Catalog Server, transferred all the FSMO roles to new Server and tested all the clients were
    able to logon to the Domain controller with not issues.  Added one more Windows 2008 R2 Server as and ADC before completing demoting the Windows 2003 R2 Domain controller.  For a test phase I have shutdown the Windows 2003 R2 DC and noticed that
    few of the member Servers running Windows 2003 OS are not login to Domain whereas Windows 2008 Member Servers, Windows XP, 7 and 8 machines are able to login to domain.  Once I bring up the Windows 2003 R2 DC those machines are able to login to the Domain.

    Hi shujathmsa,
    à
    For a test phase I have shutdown the Windows 2003 R2 DC and noticed that few of the member Servers running Windows 2003 OS are not login to Domain
    Based on your description, it seems that this issue just occurred in Windows Server 2003. Would you please
    let me know the complete error message that you can get when join Windows Server 2003 to the domain?
    Meanwhile, please follow the path:
    C:\Windows\debug folder and check NetSetup.LOG file if find some relevant clues.
    If any update, please feel free to let us know.
    Hope this helps.
    Best regards,
    Justin Gu

  • Query Window "Connection must be open" error?

    Hi:
    If I right-click on an Oracle connection and select "Query Window" from the menu I get a query window, but no matter what I try to do, hitting the Execute button results in :
    ERROR
    Connection must be open for this operation.
    Why does it think this connection is not open?
    Thanks.

    If you have MetaLink, you might take a look at Note:404340.1 (ODP.NET: Connection must be open for this operation)
    Perhaps that will be of some help.
    - Mark

  • RAC on windows 2000 with domain controller

    Guys,
    I need advise on the following implementation.
    We have 2 IBM Xseries 365 Servers , 1 FastT600 Storage Windows 2000 Advanced Server, Oracle 9i, Oracle RAC
    We have plan of integrating 2 servers in Windows 2000 Cluster, one server would act as Domain Controller and second will act as Additional Domain Controller in the MS Cluster. We would be installing Oracle 9i Enterprise s/w on each one of these server's internal disks and datafiles on shared storage ( FastT600 ).. We would need to install Oracle RAC as well. As per Oracle recommandation, the cluster nodes shouldn't act as Domain controller. We didn't find any logical and techinical answer for this recommandation. Can anyone guide me as why is it so? and any issue may arise if we don't have separate doamin controller?
    Is it really required to have separate Domain controller ?
    Early replies would be appretiated..
    Thanks & Regards,
    Sam

    Hello hanspjacobsen,
    1. According to the subjects System Requrements - Windows 2008 R2 Domain Controllers do support
    Windows 8.1/2012 R2 admx deployment with some limitations regarding down-level server version of course. So yes - you can download and use it. Doubtfully the GPO presence in AD could
    harm Exchange in any way.
    2. With the course of updates for Exchange 2010 and Windows Server - I'm pretty sure we can expect Exchange 2010 supporting W2012 R2 DCs with close upcoming updates. So the full interoperability for those two is just a matter of little time.
    ▲ Vote if Helpful / Mark if Answer
    MCSE: Messaging 2013 Charter / Private Cloud / Server Infrastructure
    MaximumExchange.ru

  • Connecting iMac to Windows network with domain

    i tried to connect my new iMac to the windows network at the office.  it would not find the server.  any suggestions

    johnthompson1993 wrote:
    Hi,
    To connect, I need to 'configure encryption as AES', which I'm not sure how to do on OS X. Furthermore, after signing in with my college ID I am required to 'Use the domain name [domain name]' and 'configure your browser to use the college proxy servers [example.example.net] on port [123]
    The encryption should be configured automatically. To use the proxy:
    1. Open System Preferences
    2. Click on Network
    3. Select Airport from the list on the left
    4. Click on Advanced, near the bottom right
    5. One of the tabs will be called Proxy. Configure your settings there.

  • Simultaneous connections with different logins

    Hi,
    We have successfully configured our CR25wiNG to work with our AD (tight integration).
    From time to time, we need to connect to a file server (Windows Server 2012) using RDP
    with a specific user. After logged in to the server, Cyberoam disconnect the former
    user and automatically redirect to the captive portal page.
    How can we avoid this behavior ?
    This topic first appeared in the Spiceworks Community

    Hi pyro61,
    Unfortunately there's not a really great solution for you.  The
    way an SCXI chassis works is that it multiplexes all of the channels
    that are in the scan list.  The only way that you can get rid of
    some of the samples would be to do it in software and programmatically
    look at only half of the data except for that one point per second that
    you want.
    You can either sample all 64 channels at their maximum rate
    (200 kS/s / 64 = 3,125 S/s), or you can pick some rate lower than that
    rate.  If you need to sample the different modules at different
    rates then you will have to have those different modules in different
    chassis.  Otherwise you are limited to one rate per chassis.
    Note: If you have the modules configured for parallel mode,
    then you could read multiple modules at multiple rates; however, in
    your case this will not work because you are only using one DAQ board
    (the SCXI-1600),
    the modules you are using are not supported for parallel mode, and
    because you can only read 8 channels at a time when in parallel mode.
    My best recommendation would be to sample as fast as you can, and then discard the unwanted thermocouple data.
    Regards,
    Otis
    Training and Certification
    Product Support Engineer
    National Instruments

  • MS OUTLOOK PROMPT USERNAME AND PASSWORD REPEATLY WHEN WE LOGIN WINDOWS 8.1 WITH DOMAIN USER ON WINDOWS SERVER 2008R2

    Dear Sir
       My name is sandeep and i have a technical issue with MS office Outlook 2007 standard. the problem is i have windows 8.1 pro. and i have installed office 2007 standard on it. i have also joined this windows 8.1  to Domain Network(I have
    domain Server on Windows server 2008R2) now problem is that when i login with domain user on this windows 8.1 and configure my MS outlook the it prompts user name and password again and again showing error "
    Server responded -ERR access denied"  and if i login windows 8.1 with its local administrator user the all runs file then ms outlook does
    not prompt for username and password. this problem with only windows 8.1 domain login.. please suggest what to do and how this problem will be resolved..
    Regards
    sandeep Kumar

    Hi,
    Did it work correctly before when logging in with domain user account? If so, please try opening Control Panel > Credential Manager and remove the cached credential entry of the Outlook account, and then restart Outlook to test the issue again.
    See:
    https://support.microsoft.com/en-us/kb/2762344/en-us
    Please also try logging into your email account from webmail access to see if there is any error.
    Please let me know the result.
    Regards,
    Steve Fan
    TechNet Community Support
    It's recommended to download and install
    Configuration Analyzer Tool (OffCAT), which is developed by Microsoft Support teams. Once the tool is installed, you can run it at any time to scan for hundreds of known issues in Office
    programs.
    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact
    [email protected]

  • Invoke-sqlcmd with domain user name and password

    I am trying to execute below small SQL script from powershell by passing my domain user name and password..but it is throwing an error login failed for the user.
    Howerver I am able to execute the same query by passing normal user 'non domain' and password. The issue is only when i am trying to connect with domain username.
    Can you please suggest if there is any way to execute below query with domain user..
    Invoke-Sqlcmd
    -query "select name from master.sys.databases"
    -ServerInstance "CM-NCKM-DBTST04\SQL2012" -username "sos\9venk" -password "xxxx"
    Thanks
    Venkat
    venkat

    Hi Venkat,
    Agree with Mike, to connect sql via powershell, you can refer to this article about authentications:
    Connecting to SQL Server through Powershell
    Please try to gather credentials using Get-Credential, and then use New-PSSession -Authentication CredSSP to open the pssession.
    A similar discussion about this issue is for your reference:
    Invoke-SQLCmd with Different Credential
    If there is anything else regarding this issue, please feel free to post back.
    Best Regards,
    Anna Wang
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected]

  • Odbc connectivity with Data services 4.2

    Hi guys
    i have very general question to ask...
    presently i have dataflow which has one source table connects to query transform and further query transform connects with target table.. query transform has no filter, no order, no group by ... it is simple select * from source table ......... company where the source tables resides have given us their odbc driver to connect and extract same data... but it takes very long time to copy at our end.. i admit that data is more than 100 million (takes more than 4 hrs) records.. but could you please help me to debug what can be done to increase the performance and how can i check why it takes very long time...
    ODBC connection set up in administrative tools->ODBC application.. is there any other way to set up the odbc....
    when i run same query on the tool provided by them to connect with LIVE system.. it takes half of the time taken by data services to copy..
    I have tried changing the dataflow properties between in-memory/ pageable with degree of parallelism.
    what can i check on my end if anything wrong going at my end... before i tell anything to source company to see...
    I would be very greatful if anyone can help me to understand same.
    regards

    Hi,
    If your database is SQL server, install a SQL native client on the DS machine to connect to the DB. You don't need a ODBC for connection of DS with DB.
    Check this, assuming your DB is SQL.
    Can Data Services 4.1 Datastore connect to 32-bit MSSQL 2005 DB?
    SAP Data Services 4.1 - SQL Server Native Client issue
    Arun

  • Help with Windows Domain Login on Mac

    Hello Everyone,
    We have two Mac Pros at my work running Mac OS 10.5.8 and they are attached to the Windows Server / Domain so when the Mac is turned on you login with your Domain credentials (using Win Server to Authenticate). Now all of this has been working fine since the computers were purchased a year ago, until two days ago that is. I turned on the Mac Pro in the morning and tried to login, and the Mac would freeze and do nothing. I restarted and tried again, using the same credentials I always use, but nothing worked. I called the IT guys and had my windows user account reset thinking that the password was expired, still didn't help, so I asked them to reset the whole account, still didn't help.
    At this point I asked a few of my co-workers to login on my Mac using their login info, and they had no problems at all. I decided to dig deeper into this problem and logging in under a "local" Mac account I went into the "Accounts" preferences to check what was going on, to my surprise my Domain account was visible (normally it wasn't unless you were logged in) and under the account it said "sharing only".
    I am still trying to figure out why my Domain account was changed from "Admin, Managed" to "Sharing Only"? So I decided that the easy fix here was to use a previously made (and tested) image file which I created when the Mac Pro was first setup and all the software was installed. So after cloning the image to the Mac HD I turned on the Mac and tried to login, again nothing happened. I can login using the local account, and my co-workers can login fine, but my domain login just refuses to work. I have also tired to login on other Macs in the department and I can login just fine on each one, the only Mac that doesn't let me login is my machine.
    I have run out of ideas, short of re-installing the entire system from scratch.. which I really don't want to do unless I have to. But if anyone out there has any ideas I would more than welcome them.
    Thanks in advance..

    It's probably related to some type of DRM (copy-protection) on the digital copy, and not due to it being any particular type of file format. The DRM scheme probably only works under Windows. And if that is the case, I don't think you will be able to get it to work under Mac OS X, short of running VMware Fusions or Parallels Desktop (or Sun's free VirtualBox) and installing Windows to run under Mac OS X.
    Considering the popularity of Macs recently, and higher use of Macs among creative folks, it's pretty stupid for the studio/distributor to make a key feature Windows-only.

  • MAP don´t login in the clients when the pcs don't connect with a domain

    I have a network with a normal pcs (as home pcs) with out domain; but i try audit the network but always launch the same error "Failed - Access Denied". I read in the internet and this problem is present when the netlogon service is down , but
    this service can't enable because this service only enable when the clients is connect with a domain controller. I need a solution. We have an ideas or solutions?
    Thank You!!

    Inventorying workgroups can be difficult, especially when it comes to remote access and network security. Because workgroups are not centrally managed, some of the items discussed in this
    wiki article on preparing your workgroup environment may require you to visit each machine individually.
    For non-domain credentials, you do not use the <systemname>\<user> format, you simply enter the user name. Regarding how to enter the credentials, if you have an account that uses the same username and password on all machines and is an administrator
    on all of those machines, then you can enter that in the All computers credentials page of the wizard. You can also do this if they are different user names. However, if some machines have an account with the same user name, such as Administrator,
    but different passwords on each machine, you will need to use the Manually enter computer names discovery method, and then enter the information for each group or each machine.
    As you can tell, workgroup environments can quickly negate any benefit that the agentless inventory nature of MAP provides.
    Please remember to click "Mark as Answer" on the post that helps you, and to click
    "Unmark as Answer" if a marked post does not actually answer your question. Please
    VOTE as HELPFUL if the post helps you. This can be beneficial to other community members reading the thread.

  • Very slow Windows domain login over IPSec VPN

    Hi
    I'm experiencing very slow Windows domain logins over an IPSec VPN connection. The AD is in Site 1, some users are in Site 2. Two Cisco ASA firewalls connect both sites by an IPSec VPN over the Internet.
    I made some registery changes on the Windows XP client on site2 to let Kerberos communicate over TCP instead of UDP. Still the logins take extremely long (45 minutes). Profiles are very small, so there had to be a problem with Kerberos, MTU sizes or somethin like that. I already changed the clients MTU settings to 1000 byes, but login is still very slow. I made some sniffer logs...
    Does anybody know what the problem can be ?
    Regards
    Remco

    Hi Remco,
    The most common issue with slowness over VPN is going to be fragementation. In general below are the recommendations to avoid fragmentation
    1. For TCP traffic, use "ip tcp adjust-mss 1360" on the Internal LAN Interface on the Router. If you are using GRE then configure "ip mtu 1400" under the Tunnel Interface.
    If you are not using GRE then the value of "ip tcp adjust-mss" depends on the type of transform-set being used E.g. AES\3DES etc, so you can increase the value of TCP adjust command from 1360 to a higher value. Though I will start from 1360 first for testing.
    Also take a look at the below article for MTU Issues
    http://www.cisco.com/en/US/customer/tech/tk827/tk369/technologies_white_paper09186a00800d6979.shtml
    Thanks,
    Naman

Maybe you are looking for