Service account for Windows Update sync
Hi all,
I would like to know if it's possible to change service account used by WSUS 2008R2 SP1 to sync with Windows Update servers, and if so how.
Thanks. Have a good day.
FXE
Hi,
Do you want to use the different account for the WSUS management? Is so, that account must be a member of either the WSUS Administrators or the local Administrators security
groups on the server on which WSUS is installed in order to use the WSUS console.
The related KB:
Step 4: Configure and Synchronize WSUS
http://technet.microsoft.com/en-us/library/cc708455(v=ws.10).aspx
Hope this helps.
We
are trying to better understand customer views on social support experience, so your participation in this
interview project would be greatly appreciated if you have time.
Thanks for helping make community forums a great place.
Similar Messages
-
Domain Group Policy changes causes clients to be unable to connect to WSUS for Windows Updates
Domain Controller is Windows Server 2008 R2 64-bit, Group Policy Management version 6.0.0.1. WSUS server is Windows Server 2008 Enterprise 32-bit, Update Services version 3.2.7600.226. Client machines are Windows 7, some are 64-bit and some are 32-bit.
Every time we make any changes to any of our Group Policies most of our clients stop getting their Windows Updates from the WSUS server within 2-3 days. This occurs when we add a new policy for a group of users, temporarily disable a policy or edit a policy.
Check of the WindowsUpdate.log on affected client machines shows:
2014-06-25 13:40:44:976 760 1610 PT WARNING: GetAuthorizationCookie failure, error = 0x80072EE2, soap client error = 5, soap error code = 0, HTTP status code = 200
2014-06-25 13:40:44:977 760 1610 PT WARNING: Failed to initialize Simple Targeting Cookie: 0x80072ee2
2014-06-25 13:40:44:977 760 1610 PT WARNING: PopulateAuthCookies failed: 0x80072ee2
2014-06-25 13:40:44:977 760 1610 PT WARNING: RefreshCookie failed: 0x80072ee2
2014-06-25 13:40:44:977 760 1610 PT WARNING: RefreshPTState failed: 0x80072ee2
2014-06-25 13:40:44:977 760 1610 PT WARNING: PTError: 0x80072ee2
2014-06-25 13:40:44:977 760 1610 Report WARNING: Reporter failed to upload events with hr = 80072ee2.
A further check of the log files shows:
2014-06-21 19:36:06:995 156 1b0c Misc WARNING: SendRequest failed with hr = 80072ee2. Proxy List used: <proxy server name:8080> Bypass List used : <(null)> Auth Schemes used : <>
We do not use a proxy except for Internet connections. We configure IE with a pac file. This is set through Group Policy since we restrict user accounts from being able to set it.
The clients that are connecting to the WSUS server have these entries instead:
2014-06-24 09:12:16:779 992 270 Agent Setting download properties on call A20329BC-3467-4B7E-B9F4-6AC6ACBA23E1: priority=3, interactive=1, owner is system=0, proxy settings=1, proxy session id=2
I have a routine that will fix the problem but it is time-consuming and pulls me away from other things I should be doing:
Run registry files on client machine (WindowsUpdate and AU) This is not always necessary and is already set by Group Policy and the affected clients already have the registry settings. No idea why it is necessary to do but it the steps below don't always
work unless it is.
netstop bits and netstop wuauserv
ipconfig /flushdns
Delete qmgr*.* files from Downloader folder
Delete Software Distribution folder
Run from command prompt:
sc.exe sdset bits D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;PU)
sc.exe sdset wuauserv D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;PU)
netstart bits and netstart wuauserv
wuauclt /resetauthorization /detectnow
Run Windows Updates again from Control Panel
This routine always fixes the problem but I've found that I must do each step to guarantee success.
How or where is the proxy setting being changed for WSUS that we see in the WindowsUpdate logs and how do I prevent this from happening? It is also curious that it happens to most but not all of the client machines. When it does happen it's not always the
same client machines.You're right - the WSUS server is on the inside and does not need a proxy server. Tried running the netsh winhttp reset proxy command but was still not able to connect to the WSUS server. After running the netsh winhttp reset proxy command received response:
Current WinHTTP proxy setting: Direct access <no proxy server>.
Ran the command at 13:49 and then tried Windows Updates again. Here's snippet from the log file:
2014-06-27 13:49:56:889 548 f6c AU Triggering AU detection through DetectNow API
2014-06-27 13:49:56:890 548 f6c AU Triggering Online detection (interactive)
2014-06-27 13:49:56:890 548 4b8 AU #############
2014-06-27 13:49:56:890 548 4b8 AU ## START ## AU: Search for updates
2014-06-27 13:49:56:890 548 4b8 AU #########
2014-06-27 13:49:56:893 548 4b8 AU <<## SUBMITTED ## AU: Search for updates [CallId = {9CE06AB2-E859-4B4D-8D1A-193AD89623C5}]
2014-06-27 13:49:56:893 548 1260 Agent *************
2014-06-27 13:49:56:893 548 1260 Agent ** START ** Agent: Finding updates [CallerId = AutomaticUpdates]
2014-06-27 13:49:56:893 548 1260 Agent *********
2014-06-27 13:49:56:893 548 1260 Agent * Online = Yes; Ignore download priority = No
2014-06-27 13:49:56:893 548 1260 Agent * Criteria = "IsInstalled=0 and DeploymentAction='Installation' or IsPresent=1 and DeploymentAction='Uninstallation' or IsInstalled=1 and DeploymentAction='Installation' and RebootRequired=1
or IsInstalled=0 and DeploymentAction='Uninstallation' and RebootRequired=1"
2014-06-27 13:49:56:893 548 1260 Agent * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
2014-06-27 13:49:56:893 548 1260 Agent * Search Scope = {Machine}
2014-06-27 13:49:56:893 548 1260 Setup Checking for agent SelfUpdate
2014-06-27 13:49:56:893 548 1260 Setup Client version: Core: 7.6.7600.256 Aux: 7.6.7600.256
2014-06-27 13:49:56:894 548 1260 Misc Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wuident.cab:
2014-06-27 13:49:56:901 548 1260 Misc Microsoft signed: Yes
2014-06-27 13:49:56:927 548 1260 Misc Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wuident.cab:
2014-06-27 13:49:56:934 548 1260 Misc Microsoft signed: Yes
2014-06-27 13:49:56:936 548 1260 Misc Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wsus3setup.cab:
2014-06-27 13:49:56:943 548 1260 Misc Microsoft signed: Yes
2014-06-27 13:49:56:956 548 1260 Misc Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wsus3setup.cab:
2014-06-27 13:49:56:962 548 1260 Misc Microsoft signed: Yes
2014-06-27 13:49:56:974 548 1260 Setup Determining whether a new setup handler needs to be downloaded
2014-06-27 13:49:56:974 548 1260 Setup SelfUpdate handler is not found. It will be downloaded
2014-06-27 13:49:56:974 548 1260 Setup Evaluating applicability of setup package "WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~amd64~~7.6.7600.256"
2014-06-27 13:49:56:976 548 1260 Setup Setup package "WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~amd64~~7.6.7600.256" is already installed.
2014-06-27 13:49:56:976 548 1260 Setup Evaluating applicability of setup package "WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.256"
2014-06-27 13:49:56:989 548 1260 Setup Setup package "WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.256" is already installed.
2014-06-27 13:49:56:989 548 1260 Setup Evaluating applicability of setup package "WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.256"
2014-06-27 13:49:57:007 548 1260 Setup Setup package "WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.256" is already installed.
2014-06-27 13:49:57:007 548 1260 Setup SelfUpdate check completed. SelfUpdate is NOT required.
2014-06-27 13:49:57:165 548 1260 PT +++++++++++ PT: Synchronizing server updates +++++++++++
2014-06-27 13:49:57:165 548 1260 PT + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL =
http://(FQDN of WSUS server)/ClientWebService/client.asmx
2014-06-27 13:49:57:175 548 1260 PT WARNING: Cached cookie has expired or new PID is available
2014-06-27 13:49:57:175 548 1260 PT Initializing simple targeting cookie, clientId = 6be4a1ae-3313-4855-bdb1-57e3312f03ec, target group = AGENCIES, DNS name = dpk2.clear-rcic.rcc.org
2014-06-27 13:49:57:175 548 1260 PT Server URL =
http://(FQDN of WSUS server)/SimpleAuthWebService/SimpleAuth.asmx
2014-06-27 13:50:57:280 548 1260 Misc WARNING: SendRequest failed with hr = 80072ee2. Proxy List used: <(proxy server):8080> Bypass List used : <(null)> Auth Schemes used : <>
2014-06-27 13:50:57:281 548 1260 PT + Last proxy send request failed with hr = 0x80072EE2, HTTP status code = 0
2014-06-27 13:50:57:281 548 1260 PT + Caller provided proxy = No
2014-06-27 13:50:57:281 548 1260 PT + Proxy list used = webgate.rcc.org:8080
2014-06-27 13:50:57:281 548 1260 PT + Bypass list used = <NULL>
2014-06-27 13:50:57:281 548 1260 PT + Caller provided credentials = No
2014-06-27 13:50:57:281 548 1260 PT + Impersonate flags = 0
2014-06-27 13:50:57:281 548 1260 PT + Possible authorization schemes used =
2014-06-27 13:50:57:281 548 1260 PT WARNING: GetAuthorizationCookie failure, error = 0x80072EE2, soap client error = 5, soap error code = 0, HTTP status code = 200
2014-06-27 13:50:57:281 548 1260 PT WARNING: Failed to initialize Simple Targeting Cookie: 0x80072ee2
2014-06-27 13:50:57:281 548 1260 PT WARNING: PopulateAuthCookies failed: 0x80072ee2
2014-06-27 13:50:57:281 548 1260 PT WARNING: RefreshCookie failed: 0x80072ee2
2014-06-27 13:50:57:281 548 1260 PT WARNING: RefreshPTState failed: 0x80072ee2
2014-06-27 13:50:57:281 548 1260 PT WARNING: Sync of Updates: 0x80072ee2
2014-06-27 13:50:57:281 548 1260 PT WARNING: SyncServerUpdatesInternal failed: 0x80072ee2
2014-06-27 13:50:57:281 548 1260 Agent * WARNING: Failed to synchronize, error = 0x80072EE2
2014-06-27 13:50:57:282 548 1260 Agent * WARNING: Exit code = 0x80072EE2
2014-06-27 13:50:57:282 548 1260 Agent *********
2014-06-27 13:50:57:282 548 1260 Agent ** END ** Agent: Finding updates [CallerId = AutomaticUpdates]
2014-06-27 13:50:57:282 548 1260 Agent *************
2014-06-27 13:50:57:282 548 1260 Agent WARNING: WU client failed Searching for update with error 0x80072ee2
2014-06-27 13:50:57:302 548 e04 AU >>## RESUMED ## AU: Search for updates [CallId = {9CE06AB2-E859-4B4D-8D1A-193AD89623C5}]
2014-06-27 13:50:57:302 548 e04 AU # WARNING: Search callback failed, result = 0x80072EE2
2014-06-27 13:50:57:302 548 e04 AU # WARNING: Failed to find updates with error code 80072EE2
2014-06-27 13:50:57:302 548 e04 AU #########
2014-06-27 13:50:57:302 548 e04 AU ## END ## AU: Search for updates [CallId = {9CE06AB2-E859-4B4D-8D1A-193AD89623C5}]
2014-06-27 13:50:57:302 548 e04 AU #############
2014-06-27 13:50:57:303 548 e04 AU Successfully wrote event for AU health state:0
2014-06-27 13:50:57:303 548 e04 AU AU setting next detection timeout to 2014-06-27 22:50:57
2014-06-27 13:50:57:304 548 e04 AU Setting AU scheduled install time to 2014-06-28 05:00:00
2014-06-27 13:50:57:304 548 e04 AU Successfully wrote event for AU health state:0
2014-06-27 13:50:57:305 548 e04 AU Successfully wrote event for AU health state:0
2014-06-27 13:51:02:285 548 1260 Report REPORT EVENT: {BD25B39C-6570-454C-A046-AF3AF2DEBDD4} 2014-06-27 13:50:57:282-0400 1 148 101 {00000000-0000-0000-0000-000000000000} 0 80072ee2 AutomaticUpdates Failure Software
Synchronization Windows Update Client failed to detect with error 0x80072ee2.
2014-06-27 13:51:02:295 548 1260 Report CWERReporter::HandleEvents - WER report upload completed with status 0x8
2014-06-27 13:51:02:295 548 1260 Report WER Report sent: 7.6.7600.256 0x80072ee2 00000000-0000-0000-0000-000000000000 Scan 101 Managed
2014-06-27 13:51:02:295 548 1260 Report CWERReporter finishing event handling. (00000000)
2014-06-27 13:51:48:184 548 4b8 AU ########### AU: Uninitializing Automatic Updates ###########
2014-06-27 13:51:48:187 548 4b8 DnldMgr FATAL: DM:CBitsJob::SetCallbackHandler: SetNotifyInterface failed with 0x80080008.
2014-06-27 13:51:48:187 548 4b8 DnldMgr FATAL: DM:CBitsJob::SetCallbackHandler: SetNotifyInterface failed with 0x80080008.
2014-06-27 13:51:48:187 548 4b8 DnldMgr FATAL: DM:CBitsJob::SetCallbackHandler: SetNotifyInterface failed with 0x80080008.
2014-06-27 13:51:48:187 548 4b8 DnldMgr FATAL: DM:CBitsJob::SetCallbackHandler: SetNotifyInterface failed with 0x80080008.
2014-06-27 13:51:48:187 548 4b8 Report CWERReporter finishing event handling. (00000000)
2014-06-27 13:51:48:252 548 4b8 Service *********
2014-06-27 13:51:48:252 548 4b8 Service ** END ** Service: Service exit [Exit code = 0x240001]
2014-06-27 13:51:48:252 548 4b8 Service *************
2014-06-27 13:51:53:002 548 160c Misc =========== Logging initialized (build: 7.6.7600.256, tz: -0400) ===========
2014-06-27 13:51:53:002 548 160c Misc = Process: C:\Windows\system32\svchost.exe
2014-06-27 13:51:53:002 548 160c Misc = Module: c:\windows\system32\wuaueng.dll
Ran a batch file which resets the AU and WindowsUpdate registry keys and then runs the steps listed above:
regedit /s C:\WindowsUpdate.reg
regedit /s C:\AU.reg
net stop bits
net stop wuauserv
Ipconfig /flushdns
del C:\ProgramData\Microsoft\Network\Downloader\qmgr*.*
del /F /Q C:\Windows\SoftwareDistribution\*.*
sc.exe sdset bits D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;PU)
sc.exe sdset wuauserv D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;PU)
net start bits
net start wuauserv
wuauclt /resetauthorization /detectnow
After this runs, am able to connect to WSUS server for updates. I mentioned Group Policy changes because this only breaks after the Group Policy changes. It doesn't affect every client machine but most of them. Was wondering how the proxy gets reset from
none to the proxy server for Windows Updates? -
Connect Azure Pack to Service Bus for Windows Server with Custom DNS
Hello! I'm trying to configure Azure Pack to use Service Bus for Windows Server 1.1 with Custom DNS.
All runs on one virtual machine (Windows Server 2012 R2) in Windows Azure.
I following this post:
roysvork.wordpress.com/2014/06/14/developing-against-service-bus-for-windows-1-1
Replace FramDNS "servicebus" to "mymachine.cloudapp.net", and create certificate:
SelfSSL /N:CN=mymachine.cloudapp.net /V:1000 /T
On Windows Azure Virtual Machine:
1.I'll set publuc DNS: mymachine.cloudapp.net
2.Open ports: 10354,10355,10356,10359,10000-10004
3.In hosts file: 127.0.0.1 mymachine.cloudapp.net
4.Create certificate:
SelfSSL /N:CN=mymachine.cloudapp.net /V:1000 /T
PowerShell:
Stop-SBFarm –Verbose
Set-SBFarm -FarmDns 'mymachine.cloudapp.net'
Update-SBHost –Verbose
Start-SBFarm –Verbose
New-SBAuthorizationRule -NamespaceName ServiceBusDefaultNamespace -Name MainRule -Rights Manage, Send, Listen
Afther that i can connect to my ServiceBusDefaultNamespace with SAS.
It's work perfect. But, When I try to create Service Bus Namespace from Azure Pack Tenant portal - in Log an Exception:
Namespace Provisioning Exception. TrackingId: . SystemId: . Namespace: SomeNamespace.
Method: Activating. Exception: System.Net.Http.HttpRequestException: An error occurred while
sending the request. ---> System.Net.WebException: The underlying connection was closed:
Could not establish trust relationship for the SSL/TLS secure channel. --->
System.Security.Authentication.AuthenticationException: The remote certificate is invalid according
to the validation procedure.
And status of namespace - Activating.
Please help!Hi Alexander,
According to the log, it seems that the validation process of the certificate failed.
Please make sure that the certificate is installed in the client properly.
Usually, self-signed certificate should be installed in the Computer Account-->Trusted Root Certificate Authorities.
Best Regards.
Steven Lee Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected] -
Hi All,
Please help me out against this issue. I have spent so much (3 working days) time just figuring out what is the issue and its solution.
I am learning Tabular Mode and trying to create a mode based on PowerPivot model. I am getting following error message:
'The PowerPivot workbook could not be imported. The service account for the workspace database server does not have permission to read from the PowerPivot workbook.'
Here is my infrastructure:
1. SSAS in Tabular Mode is installed on my Windows 8 Laptop
2. PowerPivot is also in my laptop
3. There is only my account (as Admin of course) for SSAS
Here are my questions:
1. What is this error and how can I cope with that? A step by step explanation would be highly appreciated :-)
2. Do I need to change something in Windows settings or in SSAS?
3. I am confused about my workspace database server as well, Do I have to install SSAS twice; one for development and one for workspace?
Looking forward for the expert advise.
Tahir
Thanks, TAHi,
I suspect you might have more luck if you try the SSAS forum: http://social.msdn.microsoft.com/Forums/sqlserver/en-US/home?forum=sqlanalysisservices
Regards
Jamie
ObjectStorageHelper<T> – A WinRT utility for Windows 8 |
http://sqlblog.com/blogs/jamie_thomson/ |
@jamiet |
About me -
Service Accounts for Reporting Service in SQL Server Failover Cluster setup
I am setting up 2 Report Services (SSRS) in SQL Failover Clustering (Version: 2012SP1) on Windows 2012, as part of scale out architecture.
There are 2 options to configure the service account for SSRS:
Option 1) Using domain accounts, as what I have done for DB Engine and SQL Agent.
Option 2) accept the default, which is virtual account for SSRS. Per documentation URL:
http://msdn.microsoft.com/en-us/library/ms143504.aspx
which is the recommended one? is it option 2?
There is security note on above URL as well, but does not clearly mention that option 1 is not recommended.
Security Note: Always run SQL Server services by using the lowest possible user rights. Use a MSA or virtual account when possible. When MSA and virtual accounts are not possible, use a specific low-privilege user account or domain account instead
of a shared account for SQL Server services. Use separate accounts for different SQL Server services. Do not grant additional permissions to the SQL Server service account or the service groups. Permissions will be granted through group membership or granted
directly to a service SID, where a service SID is supported.
Thanks very much for your help!Hi Luo Donghua,
In SQL Server Failover Cluster Instance, personally two options can run well. If you use the virtual account for SQL Server Reporting Service. Virtual accounts in Windows Server 2008 R2 and Windows 7 are managed local accounts that provide the features to
simplify service administration. The virtual account is auto-managed, and the virtual account can access the network in a domain environment.
Of cause, you can also use domain accounts in your clustering.
Just make sure your service account is set up here, or that it is using a proper built-in account.For more information, see:http://ermahblerg.com/2012/11/08/cluster-ssrs-in-2008/
Thanks,
Sofiya Li
Sofiya Li
TechNet Community Support -
Service Account for SQL Server Agent on SQL Server 2008 R2
This SQL Server instance is SQL Server 2008 R2 (10.50.4000). We had Active Domain Service accounts created to run the service accounts for SQL Server and SQL Server Agent.
It has become company policy to alter the service accounts that run SQL Server and SQL Server Agent. Currently, both were running under the Local System Accounts. We have altered the SQL Server but we are having issues with the SQL Server Agent.
I am told by another DBA that
"The agent is requiring elevated rights. It will startup if it has local admin rights, but not with domain accounts without admin rights."
So I was wondering if anyone has come across this issue and how did they resolve it.
lcerni"The agent is requiring elevated rights. It will startup if it has local admin rights, but not with domain accounts without admin rights."
This is completely not true. It is indeed possible to run agent as a domain account without giving it local admin. Chances are you'll need to update the local acls by adding the account to the local security groups. Please see this article for more information:
http://technet.microsoft.com/en-us/library/ms143504(v=sql.105).aspx
Edit: In addition, it'll need rights to SQL server for that account to connect and do its work. It will need to be given sysadmin:
http://technet.microsoft.com/en-us/library/ms191543.aspx
Sean Gallardy | Blog |
Twitter -
Service Accounts for Browser Services and FD Launcher (Full-text Search)
I am setting up SQL Failover Clustering (Version: 2012SP1) on Windows 2012. There are 2 options to configure the service account for Browser Services and FD Launcher :
Option 1) Using separate domain accounts, as what I have done for DB Engine and SQL Agent.
Option 2) accept the default, which is local service for
browser, and virtual account for
FD Launcher. Per documentation URL: http://msdn.microsoft.com/en-us/library/ms143504.aspx
which is the recommended one? is it option 2?
There is security note on above URL as well, but does not clearly mention that option 1 is not recommended.
Security Note: Always run SQL Server services by using the lowest possible user rights. Use a
MSA or
virtual account when possible. When MSA and virtual accounts are not possible, use a specific low-privilege user account or domain account instead of a shared account for SQL Server services. Use separate accounts for different SQL Server services. Do not
grant additional permissions to the SQL Server service account or the service groups. Permissions will be granted through group membership or granted directly to a service SID, where a service SID is supported.Hi Luo Donghua,
In SQL Server Brower, the default logon account is NT Authority\Local service and cannot be changed during SQL Server setup.SQL Server Browser is not a clustered resource and does
not support failover from one cluster node to the other. SQL Server Browser should be installed and
turned on for each node of the cluster. SQL Server Browser should be run in the security context of a low privileged user to minimize exposure to a malicious attack.
You can change the account after the setup has been completed; For more information, see:http://msdn.microsoft.com/en-us/library/hh510203.aspx.
In SQL Server full text filter daemon launcher, on Windows Vista and Windows Server 2008, the FDHOST Launcher service account also defaults to LOCAL SERVICE. If you provide a domain account in which to run the FDHOST Launcher service, we highly recommend
that you use a low privilege account. On Windows 7 and Windows Server 2008R2 , we use Virtual Account or Managed Service account(MSA) in FD Launcher . We also need to note the account you used for
FD Launcher should be different from the account that you use for the SQL Server service. For more information, see:
http://msdn.microsoft.com/en-us/library/cc281953(v=sql.100).aspx
So I recommend you use the option 2 to configure the service account for Browser Services and FD Launcher.
Thanks,
Sofiya Li
Sofiya Li
TechNet Community Support -
Where is Support for Windows Update issues for Windows Server?
Where is Support for Windows Update Issues for Windows Server?
Windows Update keeps prompting to install an important update, KB2871690 and continually fails with error code 0x800f922
I ran all the fixes I can find, it still fails.
I also tried the manual install, fails.
Microsoft used to provide no charge support for Windows Update issues. They additionally offer online fixes for other versions of windows, but not server, and I can't find a forum.
I also cannot ignore the update, it continually prompts.
I ran the windowsupdate.diagcab and it continually states it fixes Windows Update error 0x80070057, by resetting windows update data store. It further states it fixes Problems installing recent updates.
But it doesn't. I've run it 50 times, and it says the same thing every time.
So there is no support for windows update, and no support for windowsupdate.diagcab.
What's the deal?I've done the SFC/ SCANNOW and DISM
here is the cbs.log
What are we looking for?
2013-12-04 19:48:19, Info DISM PID=1612 TID=1616 Scratch directory set to 'X:\$WINDOWS.~BT\Windows\TEMP\'. - CDISMManager::put_ScratchDir
2013-12-04 19:48:19, Info DISM PID=1612 TID=1616 DismCore.dll version: 6.2.9200.16384 - CDISMManager::FinalConstruct
2013-12-04 19:48:19, Info DISM PID=1612 TID=1616 Scratch directory set to 'X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360'. -
CDISMManager::put_ScratchDir
2013-12-04 19:48:19, Info DISM PID=1612 TID=1616 Successfully loaded the ImageSession at "X:\$Windows.~BT\sources" - CDISMManager::LoadLocalImageSession
2013-12-04 19:48:20, Info DISM DISM Provider Store: PID=1612 TID=1616 Found and Initialized the DISM Logger. - CDISMProviderStore::Internal_InitializeLogger
2013-12-04 19:48:20, Info DISM DISM Provider Store: PID=1612 TID=1616 Failed to get and initialize the PE Provider. Continuing by assuming
that it is not a WinPE image. - CDISMProviderStore::Final_OnConnect
2013-12-04 19:48:20, Info DISM DISM Provider Store: PID=1612 TID=1616 Finished initializing the Provider Map. - CDISMProviderStore::Final_OnConnect
2013-12-04 19:48:20, Info DISM DISM Provider Store: PID=1612 TID=1616 Getting Provider DISMLogger - CDISMProviderStore::GetProvider
2013-12-04 19:48:20, Info DISM DISM Provider Store: PID=1612 TID=1616 Provider has previously been initialized. Returning the existing instance.
- CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:20, Info DISM DISM Provider Store: PID=1612 TID=1616 Getting Provider DISMLogger - CDISMProviderStore::GetProvider
2013-12-04 19:48:20, Info DISM DISM Provider Store: PID=1612 TID=1616 Provider has previously been initialized. Returning the existing instance.
- CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:20, Info DISM DISM Manager: PID=1612 TID=1616 Successfully created the local image session and provider store. - CDISMManager::CreateLocalImageSession
2013-12-04 19:48:20, Info DISM DISM Provider Store: PID=1612 TID=1616 Getting Provider DISMLogger - CDISMProviderStore::GetProvider
2013-12-04 19:48:20, Info DISM DISM Provider Store: PID=1612 TID=1616 Provider has previously been initialized. Returning the existing instance.
- CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:20, Info DISM DISM.EXE:
2013-12-04 19:48:20, Info DISM DISM.EXE: <----- Starting Dism.exe session ----->
2013-12-04 19:48:20, Info DISM DISM.EXE:
2013-12-04 19:48:20, Info DISM DISM.EXE: Host machine information: OS Version=6.2.9200, Running architecture=amd64, Number of processors=4
2013-12-04 19:48:20, Info DISM DISM.EXE: Dism.exe version: 6.2.9200.16384
2013-12-04 19:48:20, Info DISM DISM.EXE: Executing command line: X:\$Windows.~BT\sources\dism.exe /logpath:X:\$Windows.~BT\sources\Panther\cbs.log
/scratchdir:X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360 /image:X:\ /is-serviceable
2013-12-04 19:48:20, Info DISM DISM Provider Store: PID=1612 TID=1616 Getting the collection of providers from a local provider store type. - CDISMProviderStore::GetProviderCollection
2013-12-04 19:48:20, Info DISM DISM Provider Store: PID=1612 TID=1616 Provider has not previously been encountered. Attempting to initialize
the provider. - CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:20, Info DISM DISM Provider Store: PID=1612 TID=1616 Loading Provider from location X:\$Windows.~BT\sources\FolderProvider.dll
- CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:20, Info DISM DISM Provider Store: PID=1612 TID=1616 Connecting to the provider located at X:\$Windows.~BT\sources\FolderProvider.dll.
- CDISMProviderStore::Internal_LoadProvider
2013-12-04 19:48:20, Info DISM DISM Provider Store: PID=1612 TID=1616 Provider has not previously been encountered. Attempting to initialize
the provider. - CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:20, Info DISM DISM Provider Store: PID=1612 TID=1616 Loading Provider from location X:\$Windows.~BT\sources\WimProvider.dll -
CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:20, Warning DISM DISM Provider Store: PID=1612 TID=1616 Failed to Load the provider: X:\$Windows.~BT\sources\WimProvider.dll. - CDISMProviderStore::Internal_GetProvider(hr:0x8007007e)
2013-12-04 19:48:20, Info DISM DISM Provider Store: PID=1612 TID=1616 Provider has not previously been encountered. Attempting to initialize
the provider. - CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:20, Info DISM DISM Provider Store: PID=1612 TID=1616 Loading Provider from location X:\$Windows.~BT\sources\VHDProvider.dll -
CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:20, Warning DISM DISM Provider Store: PID=1612 TID=1616 Failed to Load the provider: X:\$Windows.~BT\sources\VHDProvider.dll. - CDISMProviderStore::Internal_GetProvider(hr:0x8007007e)
2013-12-04 19:48:20, Info DISM DISM Provider Store: PID=1612 TID=1616 Provider has not previously been encountered. Attempting to initialize
the provider. - CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:20, Info DISM DISM Provider Store: PID=1612 TID=1616 Loading Provider from location X:\$Windows.~BT\sources\ImagingProvider.dll
- CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:20, Warning DISM DISM Provider Store: PID=1612 TID=1616 Failed to Load the provider: X:\$Windows.~BT\sources\ImagingProvider.dll. - CDISMProviderStore::Internal_GetProvider(hr:0x8007007e)
2013-12-04 19:48:20, Info DISM DISM Provider Store: PID=1612 TID=1616 Provider has not previously been encountered. Attempting to initialize
the provider. - CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:20, Info DISM DISM Provider Store: PID=1612 TID=1616 Loading Provider from location X:\$Windows.~BT\sources\CompatProvider.dll
- CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:20, Info DISM DISM Provider Store: PID=1612 TID=1616 Connecting to the provider located at X:\$Windows.~BT\sources\CompatProvider.dll.
- CDISMProviderStore::Internal_LoadProvider
2013-12-04 19:48:20, Info DISM DISM.EXE: Got the collection of providers. Now enumerating them to build the command table.
2013-12-04 19:48:20, Info DISM DISM.EXE: Attempting to add the commands from provider: DISM Log Provider
2013-12-04 19:48:20, Info DISM DISM.EXE: Attempting to add the commands from provider: FolderManager
2013-12-04 19:48:20, Info DISM DISM.EXE: Attempting to add the commands from provider: Compatibility Manager
2013-12-04 19:48:20, Info DISM DISM.EXE: Succesfully registered commands for the provider: Compatibility Manager.
2013-12-04 19:48:20, Warning DISM DISM.EXE: Failed to load WimManager. Try running from the Deployment Tools Command Prompt. If the issue persists, ensure that wimgapi.dll
and wimserv.exe are up to date.
2013-12-04 19:48:20, Warning DISM DISM.EXE: Failed to add any commands.
2013-12-04 19:48:20, Info DISM DISM Provider Store: PID=1612 TID=1616 Getting the collection of providers from a local provider store type. - CDISMProviderStore::GetProviderCollection
2013-12-04 19:48:20, Info DISM DISM Manager: PID=1612 TID=1616 physical location path: X:\ - CDISMManager::CreateImageSession
2013-12-04 19:48:20, Info DISM DISM Manager: PID=1612 TID=1616 Copying DISM from "X:\Windows\System32\Dism" - CDISMManager::CreateImageSessionFromLocation
2013-12-04 19:48:20, Info DISM DISM Manager: PID=1612 TID=1616 Successfully loaded the ImageSession at "X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360\0C032313-F68B-4BD3-B62F-52A81CE58FCD"
- CDISMManager::LoadRemoteImageSession
2013-12-04 19:48:20, Info DISM DISM Image Session: PID=1644 TID=1656 Instantiating the Provider Store. - CDISMImageSession::get_ProviderStore
2013-12-04 19:48:20, Info DISM DISM Provider Store: PID=1644 TID=1656 Initializing a provider store for the IMAGE session type. - CDISMProviderStore::Final_OnConnect
2013-12-04 19:48:20, Info DISM DISM Provider Store: PID=1644 TID=1656 Provider has not previously been encountered. Attempting to initialize
the provider. - CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:20, Info DISM DISM Provider Store: PID=1644 TID=1656 Loading Provider from location X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360\0C032313-F68B-4BD3-B62F-52A81CE58FCD\OSProvider.dll
- CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:20, Info DISM DISM Provider Store: PID=1644 TID=1656 Connecting to the provider located at X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360\0C032313-F68B-4BD3-B62F-52A81CE58FCD\OSProvider.dll.
- CDISMProviderStore::Internal_LoadProvider
2013-12-04 19:48:20, Info DISM DISM OS Provider: PID=1644 TID=1656 Defaulting SystemPath to X:\ - CDISMOSServiceManager::Final_OnConnect
2013-12-04 19:48:20, Info DISM DISM OS Provider: PID=1644 TID=1656 Defaulting Windows folder to X:\Windows - CDISMOSServiceManager::Final_OnConnect
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Attempting to initialize the logger from the Image Session. - CDISMProviderStore::Final_OnConnect
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Provider has not previously been encountered. Attempting to initialize
the provider. - CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Loading Provider from location X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360\0C032313-F68B-4BD3-B62F-52A81CE58FCD\LogProvider.dll
- CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Connecting to the provider located at X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360\0C032313-F68B-4BD3-B62F-52A81CE58FCD\LogProvider.dll.
- CDISMProviderStore::Internal_LoadProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Found and Initialized the DISM Logger. - CDISMProviderStore::Internal_InitializeLogger
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Provider has not previously been encountered. Attempting to initialize
the provider. - CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Loading Provider from location X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360\0C032313-F68B-4BD3-B62F-52A81CE58FCD\PEProvider.dll
- CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:22, Warning DISM DISM Provider Store: PID=1644 TID=1656 Failed to Load the provider: X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360\0C032313-F68B-4BD3-B62F-52A81CE58FCD\PEProvider.dll.
- CDISMProviderStore::Internal_GetProvider(hr:0x8007007e)
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Failed to get and initialize the PE Provider. Continuing by assuming
that it is not a WinPE image. - CDISMProviderStore::Final_OnConnect
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Finished initializing the Provider Map. - CDISMProviderStore::Final_OnConnect
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Getting Provider DISMLogger - CDISMProviderStore::GetProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Provider has previously been initialized. Returning the existing instance.
- CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:22, Info DISM DISM Manager: PID=1612 TID=1616 Image session successfully loaded from the temporary location: X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360\0C032313-F68B-4BD3-B62F-52A81CE58FCD
- CDISMManager::CreateImageSession
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Getting Provider OSServices - CDISMProviderStore::GetProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Provider has previously been initialized. Returning the existing instance.
- CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:22, Info DISM DISM OS Provider: PID=1644 TID=1656 Setting SystemPath to X:\ - CDISMOSServiceManager::SetSystemPath
2013-12-04 19:48:22, Info DISM DISM.EXE: Target image information: OS Version=6.2.9200.16384, Image architecture=amd64
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Getting the collection of providers from an image provider store type. -
CDISMProviderStore::GetProviderCollection
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Provider has not previously been encountered. Attempting to initialize
the provider. - CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Loading Provider from location X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360\0C032313-F68B-4BD3-B62F-52A81CE58FCD\CbsProvider.dll
- CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Connecting to the provider located at X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360\0C032313-F68B-4BD3-B62F-52A81CE58FCD\CbsProvider.dll.
- CDISMProviderStore::Internal_LoadProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Encountered a servicing provider, performing additional servicing initializations.
- CDISMProviderStore::Internal_LoadProvider
2013-12-04 19:48:22, Info DISM DISM Package Manager: PID=1644 TID=1656 Finished initializing the CbsConUI Handler. - CCbsConUIHandler::Initialize
2013-12-04 19:48:22, Info DISM DISM Package Manager: PID=1644 TID=1656 Loaded servicing stack for offline use only. - CDISMPackageManager::RefreshInstanceAndLock
2013-12-04 19:48:22, Info DISM DISM Package Manager: PID=1644 TID=1656 Loaded servicing stack for offline use only. - CDISMPackageManager::RefreshInstanceAndLock
2013-12-04 19:48:22, Info DISM DISM Package Manager: PID=1644 TID=1656 Loaded servicing stack for online use only. - CDISMPackageManager::RefreshInstanceAndLock
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Provider has not previously been encountered. Attempting to initialize
the provider. - CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Loading Provider from location X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360\0C032313-F68B-4BD3-B62F-52A81CE58FCD\MsiProvider.dll
- CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Connecting to the provider located at X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360\0C032313-F68B-4BD3-B62F-52A81CE58FCD\MsiProvider.dll.
- CDISMProviderStore::Internal_LoadProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Encountered a servicing provider, performing additional servicing initializations.
- CDISMProviderStore::Internal_LoadProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Provider has not previously been encountered. Attempting to initialize
the provider. - CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Loading Provider from location X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360\0C032313-F68B-4BD3-B62F-52A81CE58FCD\IntlProvider.dll
- CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Connecting to the provider located at X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360\0C032313-F68B-4BD3-B62F-52A81CE58FCD\IntlProvider.dll.
- CDISMProviderStore::Internal_LoadProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Encountered a servicing provider, performing additional servicing initializations.
- CDISMProviderStore::Internal_LoadProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Provider has not previously been encountered. Attempting to initialize
the provider. - CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Loading Provider from location X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360\0C032313-F68B-4BD3-B62F-52A81CE58FCD\IBSProvider.dll
- CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:22, Warning DISM DISM Provider Store: PID=1644 TID=1656 Failed to Load the provider: X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360\0C032313-F68B-4BD3-B62F-52A81CE58FCD\IBSProvider.dll.
- CDISMProviderStore::Internal_GetProvider(hr:0x8007007e)
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Provider has not previously been encountered. Attempting to initialize
the provider. - CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Loading Provider from location X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360\0C032313-F68B-4BD3-B62F-52A81CE58FCD\DmiProvider.dll
- CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Connecting to the provider located at X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360\0C032313-F68B-4BD3-B62F-52A81CE58FCD\DmiProvider.dll.
- CDISMProviderStore::Internal_LoadProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Encountered a servicing provider, performing additional servicing initializations.
- CDISMProviderStore::Internal_LoadProvider
2013-12-04 19:48:22, Info DISM DISM OS Provider: PID=1644 TID=1656 Get the registry path to the SOFTWARE hive located at X:\Windows\system32\config\SOFTWARE
and determine if it is loaded. - CDISMOSServiceManager::DetermineBootDrive
2013-12-04 19:48:22, Info DISM DISM Driver Manager: PID=1644 TID=1656 Further logs for driver related operations can be found in the target operating
system at %WINDIR%\inf\setupapi.offline.log - CDriverManager::Initialize
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Provider has not previously been encountered. Attempting to initialize
the provider. - CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Loading Provider from location X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360\0C032313-F68B-4BD3-B62F-52A81CE58FCD\UnattendProvider.dll
- CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Connecting to the provider located at X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360\0C032313-F68B-4BD3-B62F-52A81CE58FCD\UnattendProvider.dll.
- CDISMProviderStore::Internal_LoadProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Encountered a servicing provider, performing additional servicing initializations.
- CDISMProviderStore::Internal_LoadProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Provider has not previously been encountered. Attempting to initialize
the provider. - CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Loading Provider from location X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360\0C032313-F68B-4BD3-B62F-52A81CE58FCD\Wow64provider.dll
- CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:22, Warning DISM DISM Provider Store: PID=1644 TID=1656 Failed to get the IDismObject Interface - CDISMProviderStore::Internal_LoadProvider(hr:0x80004002)
2013-12-04 19:48:22, Warning DISM DISM Provider Store: PID=1644 TID=1656 Failed to Load the provider: X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360\0C032313-F68B-4BD3-B62F-52A81CE58FCD\Wow64provider.dll.
- CDISMProviderStore::Internal_GetProvider(hr:0x80004002)
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Provider has not previously been encountered. Attempting to initialize
the provider. - CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Loading Provider from location X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360\0C032313-F68B-4BD3-B62F-52A81CE58FCD\SmiProvider.dll
- CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Connecting to the provider located at X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360\0C032313-F68B-4BD3-B62F-52A81CE58FCD\SmiProvider.dll.
- CDISMProviderStore::Internal_LoadProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Encountered a servicing provider, performing additional servicing initializations.
- CDISMProviderStore::Internal_LoadProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Provider has not previously been encountered. Attempting to initialize
the provider. - CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Loading Provider from location X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360\0C032313-F68B-4BD3-B62F-52A81CE58FCD\EmbeddedProvider.dll
- CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:22, Warning DISM DISM Provider Store: PID=1644 TID=1656 Failed to Load the provider: X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360\0C032313-F68B-4BD3-B62F-52A81CE58FCD\EmbeddedProvider.dll.
- CDISMProviderStore::Internal_GetProvider(hr:0x8007007e)
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Provider has not previously been encountered. Attempting to initialize
the provider. - CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Loading Provider from location X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360\0C032313-F68B-4BD3-B62F-52A81CE58FCD\AppxProvider.dll
- CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Connecting to the provider located at X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360\0C032313-F68B-4BD3-B62F-52A81CE58FCD\AppxProvider.dll.
- CDISMProviderStore::Internal_LoadProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Encountered a servicing provider, performing additional servicing initializations.
- CDISMProviderStore::Internal_LoadProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Provider has not previously been encountered. Attempting to initialize
the provider. - CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Loading Provider from location X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360\0C032313-F68B-4BD3-B62F-52A81CE58FCD\AssocProvider.dll
- CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Connecting to the provider located at X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360\0C032313-F68B-4BD3-B62F-52A81CE58FCD\AssocProvider.dll.
- CDISMProviderStore::Internal_LoadProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Encountered a servicing provider, performing additional servicing initializations.
- CDISMProviderStore::Internal_LoadProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Provider has not previously been encountered. Attempting to initialize
the provider. - CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Loading Provider from location X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360\0C032313-F68B-4BD3-B62F-52A81CE58FCD\TransmogProvider.dll
- CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Connecting to the provider located at X:\$WINDOWS.~LS\PackageTemp\3a4a5dfb-c322-402c-a12e-4f1ed21dd360\0C032313-F68B-4BD3-B62F-52A81CE58FCD\TransmogProvider.dll.
- CDISMProviderStore::Internal_LoadProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1656 Encountered a servicing provider, performing additional servicing initializations.
- CDISMProviderStore::Internal_LoadProvider
2013-12-04 19:48:22, Info DISM DISM Transmog Provider: PID=1644 TID=1656 Current image session is [OFFLINE] - CTransmogManager::GetMode
2013-12-04 19:48:22, Info DISM DISM Transmog Provider: PID=1644 TID=1656 Determined WinDir path = [X:\Windows] - CTransmogManager::GetWinDirPath
2013-12-04 19:48:22, Info DISM DISM Transmog Provider: PID=1644 TID=1656 GetProductType: ProductType = [ServerNT] - CTransmogManager::GetProductType
2013-12-04 19:48:22, Info DISM DISM Transmog Provider: PID=1644 TID=1656 Product Type: [ServerNT] - CTransmogManager::Initialize
2013-12-04 19:48:22, Info DISM DISM Transmog Provider: PID=1644 TID=1656 Product Type ServerNT : [Yes] - CTransmogManager::Initialize
2013-12-04 19:48:22, Info DISM DISM.EXE: Got the collection of providers. Now enumerating them to build the command table.
2013-12-04 19:48:22, Info DISM DISM.EXE: Attempting to add the commands from provider: DISM Log Provider
2013-12-04 19:48:22, Info DISM DISM.EXE: Attempting to add the commands from provider: OSServices
2013-12-04 19:48:22, Info DISM DISM.EXE: Attempting to add the commands from provider: DISM Package Manager
2013-12-04 19:48:22, Info DISM DISM.EXE: Succesfully registered commands for the provider: DISM Package Manager.
2013-12-04 19:48:22, Info DISM DISM.EXE: Attempting to add the commands from provider: MsiManager
2013-12-04 19:48:22, Info DISM DISM.EXE: Succesfully registered commands for the provider: MsiManager.
2013-12-04 19:48:22, Info DISM DISM.EXE: Attempting to add the commands from provider: IntlManager
2013-12-04 19:48:22, Info DISM DISM.EXE: Succesfully registered commands for the provider: IntlManager.
2013-12-04 19:48:22, Info DISM DISM.EXE: Attempting to add the commands from provider: DriverManager
2013-12-04 19:48:22, Info DISM DISM.EXE: Succesfully registered commands for the provider: DriverManager.
2013-12-04 19:48:22, Info DISM DISM.EXE: Attempting to add the commands from provider: DISM Unattend Manager
2013-12-04 19:48:22, Info DISM DISM.EXE: Succesfully registered commands for the provider: DISM Unattend Manager.
2013-12-04 19:48:22, Info DISM DISM.EXE: Attempting to add the commands from provider: SmiManager
2013-12-04 19:48:22, Info DISM DISM.EXE: Attempting to add the commands from provider: AppxManager
2013-12-04 19:48:22, Info DISM DISM.EXE: Succesfully registered commands for the provider: AppxManager.
2013-12-04 19:48:22, Info DISM DISM.EXE: Attempting to add the commands from provider: AssocManager
2013-12-04 19:48:22, Info DISM DISM.EXE: Succesfully registered commands for the provider: AssocManager.
2013-12-04 19:48:22, Info DISM DISM.EXE: Attempting to add the commands from provider: Edition Manager
2013-12-04 19:48:22, Info DISM DISM.EXE: Succesfully registered commands for the provider: Edition Manager.
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1672 Getting Provider DISM Package Manager - CDISMProviderStore::GetProvider
2013-12-04 19:48:22, Info DISM DISM Provider Store: PID=1644 TID=1672 Provider has previously been initialized. Returning the existing instance.
- CDISMProviderStore::Internal_GetProvider
2013-12-04 19:48:22, Info DISM DISM Package Manager: PID=1644 TID=1672 Processing the top level command token(is-serviceable). - CPackageManagerCLIHandler::Private_ValidateCmdLine
2013-12-04 19:48:22, Info DISM DISM Package Manager: PID=1644 TID=1672 Attempting to route to appropriate command handler. - CPackageManagerCLIHandler::ExecuteCmdLine
2013-12-04 19:48:22, Info DISM DISM Package Manager: PID=1644 TID=1672 Routing the command... - CPackageManagerCLIHandler::ExecuteCmdLine
2013-12-04 19:48:23, Info DISM DISM Provider Store: PID=1644 TID=1672 Found the OSServices. Waiting to finalize it until all other providers
are unloaded. - CDISMProviderStore::Final_OnDisconnect
2013-12-04 19:48:23, Info DISM DISM Provider Store: PID=1644 TID=1672 Found the OSServices. Waiting to finalize it until all other providers
are unloaded. - CDISMProviderStore::Final_OnDisconnect
2013-12-04 19:48:23, Info DISM DISM Provider Store: PID=1644 TID=1672 Found the PE Provider. Waiting to finalize it until all other providers
are unloaded. - CDISMProviderStore::Final_OnDisconnect
2013-12-04 19:48:23, Info DISM DISM Provider Store: PID=1644 TID=1672 Finalizing the servicing provider(DISM Package Manager) - CDISMProviderStore::Internal_DisconnectProvider
2013-12-04 19:48:23, Info DISM DISM Package Manager: PID=1644 TID=1672 Finalizing CBS core. - CDISMPackageManager::Finalize
2013-12-04 19:48:23, Info DISM DISM Provider Store: PID=1644 TID=1672 Disconnecting Provider: DISM Package Manager - CDISMProviderStore::Internal_DisconnectProvider
2013-12-04 19:48:23, Info DISM DISM Provider Store: PID=1644 TID=1672 Finalizing the servicing provider(MsiManager) - CDISMProviderStore::Internal_DisconnectProvider
2013-12-04 19:48:23, Info DISM DISM Provider Store: PID=1644 TID=1672 Disconnecting Provider: MsiManager - CDISMProviderStore::Internal_DisconnectProvider
2013-12-04 19:48:23, Info DISM DISM Provider Store: PID=1644 TID=1672 Finalizing the servicing provider(IntlManager) - CDISMProviderStore::Internal_DisconnectProvider
2013-12-04 19:48:23, Info DISM DISM Provider Store: PID=1644 TID=1672 Disconnecting Provider: IntlManager - CDISMProviderStore::Internal_DisconnectProvider
2013-12-04 19:48:23, Info DISM DISM Provider Store: PID=1644 TID=1672 Finalizing the servicing provider(DriverManager) - CDISMProviderStore::Internal_DisconnectProvider
2013-12-04 19:48:23, Info DISM DISM Provider Store: PID=1644 TID=1672 Disconnecting Provider: DriverManager - CDISMProviderStore::Internal_DisconnectProvider
2013-12-04 19:48:23, Info DISM DISM Provider Store: PID=1644 TID=1672 Finalizing the servicing provider(DISM Unattend Manager) - CDISMProviderStore::Internal_DisconnectProvider
2013-12-04 19:48:23, Info DISM DISM Provider Store: PID=1644 TID=1672 Disconnecting Provider: DISM Unattend Manager - CDISMProviderStore::Internal_DisconnectProvider
2013-12-04 19:48:23, Info DISM DISM Provider Store: PID=1644 TID=1672 Finalizing the servicing provider(SmiManager) - CDISMProviderStore::Internal_DisconnectProvider
2013-12-04 19:48:23, Info DISM DISM Provider Store: PID=1644 TID=1672 Disconnecting Provider: SmiManager - CDISMProviderStore::Internal_DisconnectProvider
2013-12-04 19:48:23, Info DISM DISM Provider Store: PID=1644 TID=1672 Finalizing the servicing provider(AppxManager) - CDISMProviderStore::Internal_DisconnectProvider
2013-12-04 19:48:23, Info DISM DISM Provider Store: PID=1644 TID=1672 Disconnecting Provider: AppxManager - CDISMProviderStore::Internal_DisconnectProvider
2013-12-04 19:48:23, Info DISM DISM Provider Store: PID=1644 TID=1672 Finalizing the servicing provider(AssocManager) - CDISMProviderStore::Internal_DisconnectProvider
2013-12-04 19:48:23, Info DISM DISM Provider Store: PID=1644 TID=1672 Disconnecting Provider: AssocManager - CDISMProviderStore::Internal_DisconnectProvider
2013-12-04 19:48:23, Info DISM DISM Provider Store: PID=1644 TID=1672 Finalizing the servicing provider(Edition Manager) - CDISMProviderStore::Internal_DisconnectProvider
2013-12-04 19:48:23, Info DISM DISM Provider Store: PID=1644 TID=1672 Disconnecting Provider: Edition Manager - CDISMProviderStore::Internal_DisconnectProvider
2013-12-04 19:48:23, Info DISM DISM Provider Store: PID=1644 TID=1672 Releasing the local reference to OSServices. - CDISMProviderStore::Internal_DisconnectProvider
2013-12-04 19:48:23, Info DISM DISM Provider Store: PID=1644 TID=1672 Disconnecting Provider: OSServices - CDISMProviderStore::Internal_DisconnectProvider
2013-12-04 19:48:24, Info DISM DISM OS Provider: PID=1644 TID=1672 Successfully unloaded all registry hives. - CDISMOSServiceManager::Final_OnDisconnect
2013-12-04 19:48:24, Info DISM DISM Provider Store: PID=1644 TID=1672 Releasing the local reference to DISMLogger. Stop logging. - CDISMProviderStore::Internal_DisconnectProvider
2013-12-04 19:48:24, Info DISM DISM.EXE: Image session has been closed. Reboot required=no.
2013-12-04 19:48:24, Info DISM DISM.EXE:
2013-12-04 19:48:24, Info DISM DISM.EXE: <----- Ending Dism.exe session ----->
2013-12-04 19:48:24, Info DISM DISM.EXE:
2013-12-04 19:48:24, Info DISM DISM Provider Store: PID=1612 TID=1616 Found the OSServices. Waiting to finalize it until all other providers
are unloaded. - CDISMProviderStore::Final_OnDisconnect
2013-12-04 19:48:24, Info DISM DISM Provider Store: PID=1612 TID=1616 Disconnecting Provider: FolderManager - CDISMProviderStore::Internal_DisconnectProvider
2013-12-04 19:48:24, Info DISM DISM Provider Store: PID=1612 TID=1616 Disconnecting Provider: Compatibility Manager - CDISMProviderStore::Internal_DisconnectProvider
2013-12-04 19:48:24, Info DISM DISM Provider Store: PID=1612 TID=1616 Releasing the local reference to DISMLogger. Stop logging. - CDISMProviderStore::Internal_DisconnectProvider -
Use SIA service account for SQL Server reporting connections (BIP4.1)
Is it possible to use the SIA service account as a proxy for a SQL Server connection using OLE DB? This way, anytime a report was refreshed, the SIA service account would be used when authenticating to the reporting database? This is a common pattern in software development to minimize database maintenance (when there is sufficient security being enforced at the application layer - BOBJ provides this).
This would make SQL Server database security management very easy for the DBAs (just add the BOBJ service account to the database and assign dbreader).
I would think this would be an option, but a Relational Connection only provides the following 3 Authentication modes when using the IDT to create and publish a Relational Connection (OLEDB/MSSQL):
Use BusinessObjects credential mapping
This takes the username and password from the "Database Credentials" section of the BusinessObjects User object for the user in the current session. It passes the info as hard-coded SQL authentication.
Use single sign-on when refreshing reports at view time
This is ONLY for end-to-end single-sign-on (as the error message in the next paragraph specifies) and uses the Windows AD credentials for the user in the current session. It is this method of authentication that I'd like to use, i.e. Windows Integrated Security, but I'd like to have the SIA account act as the account that makes the connection, not end-to-end.
Use specified username and password
This is for hard-coding usernames and passwords (only SQL authentication in OLE DB).
I've tried leaving the "Cache security context" option OFF in Windows AD Authentication settings, hoping it would default to using the service account for authentication to the database... to no avail. It fails during tests in the IDT with the message:
"Single Sign-On failed in the CMS. Please contact your system administrator for details. : The authentication provider (secWinAD) associated with this logon session does not have inter-process Single Sign-On enabled. Contact your system administrator for details. (FWB 00019)"
Alternatively, a SQL user could be hard-coded into the connection (same simple maintenance on the DBA side), but we'd really like to rely on Windows Integrated Security if possible!
Is there a way?
Any help is greatly appreciated!
DavidHey David,
Did you ever solve this? We get the same SSO error when indexing information spaces in Explorer.
Thanks,
Brandon -
Creating Service Accounts For Components of SQL Server
Hello , am trying to install SQL Server 2014 on a windows 8 but dont know how to create the service accounts for the various components .
Hello , am trying to install SQL Server 2014 on a windows 8 but dont know how to create the service accounts for the various components .
Hi,
You need to refer to below BOL article
Configure service account
Service account setup
Please mark this reply as answer if it solved your issue or vote as helpful if it helped so that other forum members can benefit from it
My Technet Wiki Article
MVP -
I cannot get Icloud for windows update 4.0.2 to install on my Win 8.1 PC
I cannot get Icloud for windows update 4.0.2 to install on my Win 8.1 Pro PC its an AMD 64 bit processor.
I get a message that saysI cannot get Icloud for windows update 4.0.2 to install on my Win 8.1 Pro PC
I get the update notification and authorize its installation and it try's but fails.
I have down loaded the update and tried installation manually but it doesn't work.
I get the following message after it fails:
Errors occurred while installing the updates. If the problem persists, choose Tools > Dowmnload only and try installing manually.
I have tried this many times to no availI have been getting the same message for a few days now. Apple must have an a bug in this update
-
Microsoft releases fix for Windows Update corruption errors
See ZDnet article Microsoft releases fix for Windows Update corruption errors found @
http://www.zdnet.com/microsoft-releases-fix-for-windows-update-corruption-errors-7000026582/
The Microsoft KB article is found @
http://support.microsoft.com/kb/947821
Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread. ”Hi Rick,
Really thanks for your sharing.
This will definitly help others in this forum.
Kate Li
TechNet Community Support -
AD sync service account for cloud based application
i have a cloud based application that i am setting up AD sync with. in their directions below i have bolded the ones i need answers too. my domain functional level is windows server 2003
The active directory synchronization requires the following:
A domain user which has the following properties:
The password is known and does not expire - completed
The domain user account has read permissions to all objects in the entire domain within active directory
Confirm that if the domain has been upgraded to Windows 200x functional level from Windows NT4, 2000 or 2003 that we have the appropriate Group permissions below available to the domain user account for the synchronization in addition
to read permissions to the entire domain:
Pre-Windows 2000 Compatible Access
Pre-Windows 2003 Compatible Access
The username and password are passed using the appropriate communication channels - completed
i have created a service account in my AD called myappldap. does a domain user have read permissions to all objects in the entire domain within active directory without adding the to any other security groups except domain users? Or do i have to click on
the top level domain object in AD>go to properties>security>and give them read permission and proprogate down those premissions? Also i do not see Pre-windows 2003 compatible access as a security object i can give this service account read permissions
to. i just wanted to confirm that this is because i am still running a functional domain of windows server 2003?A domain user has complete Read on everything in the forest.
As for the Pre-Windows 2000 Compatible group, that's a reduced security group to allow NULL password for pre-Windows 2000 DCs, such as the way NT4 RRAS (VPN servers) used. In Windows 2000 and newer, we can eliminate that group, since it's a security concern.
More info to read up on it, here:
http://social.technet.microsoft.com/Forums/windowsserver/en-US/e8dfacba-985f-4042-abeb-f341bf37522f/prewindows-2000-compatible-access-group?forum=winserverDS
Everyone group does not include anonymous security identifier
http://support.microsoft.com/kb/278259
As for Pre-Windows 2003, I haven't come across anything that would say
pre-2003. It almost appears that the software is using NULL or some other kind of reduces security on the password. Then again, I could totally be wrong. Is that specifically how the third party software specifies it in the docs?
Can you post a link to it?
Ace Fekay
MVP, MCT, MCSE 2012, MCITP EA & MCTS Windows 2008/R2, Exchange 2013, 2010 EA & 2007, MCSE & MCSA 2003/2000, MCSA Messaging 2003
Microsoft Certified Trainer
Microsoft MVP - Directory Services
Complete List of Technical Blogs: http://www.delawarecountycomputerconsulting.com/technicalblogs.php
This posting is provided AS-IS with no warranties or guarantees and confers no rights. -
Group managed service accounts for SQL Server
Hey guys,
Unfortunately I missed that (g/s)MSAs aren't supported yet for SQL Servers but I'm using them without any worries since ages.
As i digged a bit deeper I could find different informations due to the related TechNet entrys. So it seems Microsofts Informations about (s)MSAs and gMSAs aren't consistent.
I'm not a SQL Server guy and use SQL only for System Center testing stuff so i would like to get a real world exps of SQL Server guys.
Should I continue using gMSAs or are there any worries I should know?
some sources I found so far:
Not supported:
"Hi Adam,
Thank you for your feedback. Windows Server 2012 Group Managed Service Account is not currently supported as SQL 2012 released earlier than Windows Server 2012. We will consider to support gMSA in future SQL Server release.
Regards,
Min He, Program Manager, SQL Server"
11.2012 -
https://connect.microsoft.com/SQLServer/feedback/details/767211/gmsa-for-sql-server-failover-Clusters
gMSA are not yet available, are not yet supported for SQL Server. gMSA exist and are available and supported in Windows Server 2012 and higher. SQL does not support them , but
from an OS perspective, they exist and are supported.
http://blogs.msdn.com/b/sqlosteam/archive/2014/02/19/msa-accounts-used-with-sql.aspx
Within the FAQ Task Scheduler isn't supported as well ...
http://technet.microsoft.com/en-us/library/ff641729%28WS.10%29.aspx
... but also PFEs using them for Tasks... this is confusin... 0o
http://blogs.msdn.com/b/arvindsh/archive/2014/02/03/managed-service-accounts-msa-and-sql-2012-practical-tips.aspx
supported?:
Configure Windows Service Accounts and Permissions
... New Account Types Available with Windows 7 and Windows Server 2008 R2
http://technet.microsoft.com/en-us/library/ms143504(v=sql.110).aspx#Default_Accts
The MSA must be created in the Active Directory by the domain administrator before SQL Server setup can use it for SQL Server services.
others sources won't mentioning s/gMSAs...
I couldn't find clear informations about using gMSA for SQL Server 2014.
only the same page which also Looks like the page for 2008 R2 and SQL 2012.
Configure Windows Service Accounts and Permissions
SQL Server 2014
http://msdn.microsoft.com/en-us/library/ms143504.aspx
annoying topic so far... ;)Hi Enrico
aside from what Dan says about the risk for support, on which I agree, the following thread may clear it up a bit:
http://social.msdn.microsoft.com/Forums/sqlserver/en-US/acb2048c-ffce-4d44-b882-6aafc7eb689d/managed-service-accounts-to-run-sql-server-service?forum=sqlsecurity
Andreas Wolter (Blog |
Twitter)
MCM - Microsoft Certified Master SQL Server 2008
MCSM - Microsoft Certified Solutions Master Data Platform, SQL Server 2012
www.andreas-wolter.com |
www.SarpedonQualityLab.com -
Question : Service Accounts for SQL Server 2012
Hello,
I am planning to create AD accounts for SQL Server 2012 services that will be installed on Windows 2012 server.
I was reading the following
Configure Windows Service Accounts and Permissions
and
Windows Privileges and Rights
Is there a recommendation / document that would list that assocation of SQL Server Services with Actvie Directory service accounts / privileges required for installation and starting the services.
Isn't it recommended to create separate account for every service and they should not be local accounts ?
Hope to hear soon as to what industry standards are being followed for production systems ?
Thank you very much in advance.
Regards
NikunjFrom MSDN:
Each service in SQL Server represents a process or a set of processes to manage authentication of SQL Server operations with Windows. Each service can be configured to use its own service account. This facility is exposed
at installation. SQL Server provides a special tool, SQL Server Configuration Manager, to manage the services configuration.
When choosing service accounts, consider the principle of least privilege. The service account should have exactly the privileges that it needs to do its job and no more privileges. You also need to consider account isolation; the service accounts should
not only be different from one another, they should not be used by any other service on the same server. Do not grant additional permissions to the SQL Server service account or the service groups.
From Glen Berry's Blog:
You should request that a dedicated domain user account be created for use by the SQL Server service. This should just be a regular, domain account with no special rights on the domain. You do not need or want this account to be a local admin on the machine
where SQL Server will be installed. The SQL Server setup program will grant the necessary rights on the machine to that account during installation.
You will also want a separate, dedicated domain user account for the SQL Server Agent service. If you are going to be installing and using other SQL Server related services such as SQL Server Integration Services (SSIS), SQL Server Reporting Services (SSRS),
or SQL Server Analysis Services (SSAS), you will want dedicated domain accounts for each service. The reason you want separate accounts for each service is because they require different rights on the local machine, and having separate accounts is both more
secure and more resilient, since a problem with one account won’t affect all of the SQL Server Services.
Depending on your organization, getting these domain accounts created could take anywhere from minutes to weeks to complete, so make sure to allow time for this. For each one of these accounts, you will need their logon credentials for the SQL Server setup
program. You are going to want to make sure that the accounts don’t have a temporary password that must be changed during the next login. If they are set up that way, make sure to change them to use a strong password, and record this information in a secure
location.
Please Mark This As Answer if it solved your issue
Please Mark This As Helpful if it helps to solve your issue
Thanks,
Shashikant
Maybe you are looking for
-
My 'Design View' has stopped working in CS5. How can I get it functioning again?
I've looked through the existing topics and couldn't find an answer. I hadn't made anything in DreamweaverCS5 for a a few months, but when I went today to create a new HTML document, I couldn't do anything in 'Design View' . I have not changed anythi
-
How to apply 3 way color correction to multiple clips in Final Cut Pro?
I have multiple clips from the same time and space footage that need color correction. I have worked on one of the clips and found the settings I like. Is there a way to apply that correction to other clips without starting from scratch on each one?
-
FCPX 10.1 Chroma Key Strength Slider Crash
Hello fellow users I will apologize in advance as I am just the IT guy and am not well versed in editing lingo, but here it goes. My chief editor came to me with a problem that he has had since the first FCPX. I will post the crash report below, but
-
Hi! I'm using WebLogic 7.0.2 and using the weblogic.servlet.FileServlet to serve up various pages (HTML, Word, Powerpoint). If I change an HTML file and access it agin things are find since
-
Add Hyperlink in Mail as Word or Phrase Instead of Long Link Address
I've been trying to figure out how to insert a hyperlink in an email message as a short word or phrase instead of having to Add it as the actual address. I've been using the Add Hyperlink command for some time. But it seems like it only remains a liv