We have SQL-2005 STD SP3 installed in Windows 2003 x64 Cluster environment. All SQL services are running under domain account which is in local admin group on each node. I am told to downgrade the rights of the domain account to the minimum by removing it from local admin group. Can anybody recommend how to do it safely without breaking functionality of our production cluster? In cluster environment I don't see windows sql groups that I could assign service accounts, so I guess I should do it manually. Thanks in advance
Chances are that simply removing the current account from the Local Administrators group will not impact your operations. Use the SQL Server Configuration utility to assign accounts if you intend to change to a different ID. It ensures that proper group memberships and rights are applied on the server.