question

DJUOxford avatar image
DJUOxford asked

Removed builtin/administrators group, instance not broadcasting.

Hello, I removed the builtin/administrtors group and from a sql2005 sp3 instance and now the instance does not show when browsing for it, either using management studio , or if you try to connect an odbc connection. You can however type in the name of the server and connect using the management studio software or connect via an odbc. All applictions are still working, but i'm concerned as to why this happened, any help would be greatly apprecited. Thank you
security
3 comments
10 |1200

Up to 2 attachments (including images) can be used with a maximum of 512.0 KiB each and 1.0 MiB total.

Kev Riley avatar image Kev Riley ♦♦ commented ·
@BradleySQL - for security reasons. Why should the administrators of a windows server need to have admin (or any) permissions to a SQL database?
1 Like 1 ·
ThomasRushton avatar image ThomasRushton ♦♦ commented ·
As Kev says, it's a demarcation thing. In the wonderful world of SOX, for example, "Segregation of Duty" is one of the mantras, and that means that I, employed as a SQL Server DBA, am not allowed to do basic server-level maintenance, even though I may be the best qualified to do so (which I'm not, I hasten to add). This is a particular nuisance in the small hours of the morning when there's a problem and I need to reboot a SQL server...
1 Like 1 ·
BradleySQL avatar image BradleySQL commented ·
Why would you remove the builtin/administrators group? Just curious.
0 Likes 0 ·
Tim avatar image
Tim answered
Is this a default instance or named instance? If named you need SQL Browser to be enabled and running.
1 comment
10 |1200

Up to 2 attachments (including images) can be used with a maximum of 512.0 KiB each and 1.0 MiB total.

Manikreddy avatar image Manikreddy commented ·
Is it good practice to start SQL Browser for critical applications instead of creating alias..?
0 Likes 0 ·
Fatherjack avatar image
Fatherjack answered
potentially the SQL Browser service is running under an account that is in the group that has been removed, therefore it's not broadcasting the server name. Check the service account and maybe change it to see if it is resolved. This isnt actually a big issue in most cases. Only people who know the instance exists will be able to connect so you avoid 'chancers' attempting to connect.
10 |1200

Up to 2 attachments (including images) can be used with a maximum of 512.0 KiB each and 1.0 MiB total.

Write an Answer

Hint: Notify or tag a user in this post by typing @username.

Up to 2 attachments (including images) can be used with a maximum of 512.0 KiB each and 1.0 MiB total.