RDM Roles with Active Directory groups not working

RDM Roles with Active Directory groups not working

avatar

Hi
Until now we used single user Logins and we d like to change the authetication to Roles with Active Directory Groups
As store we use a central SQL Server
I tryed to connect to the database by using ODBC with a user which is a member of my new Role and this defenitely works
The Connection Setting with RDM is not working by deactivating the integrated security Active Directory and adding the User in Format DOMAIN\User or USER@DOMAIN.X and a Password

Any idea why?

Thanks Andi
edited by forcefreak on 3/4/2014
edited by forcefreak on 3/4/2014

All Comments (5)

avatar

With the .NET provider you need to specify Integrated but you can't specify the username and password. What message do you get?

http://stackoverflow.com/questions/830929/database-windows-authentication-username-password

David Hervieux

avatar

Unable to connect to the server !
Login failed for user 'DOMAIN\MYUSER'

When I deactivate the "Integrated security (Active Directory)", can i still use an AD user in the user field?

avatar

No, you can't specify user/password and use integrated security(SSPI) they are mutually exclusive.

In the case where the connection string contains both, SSPI will always take precedence.

http://blogs.msdn.com/b/spike/archive/2008/11/14/connectionstrings-mixing-usernames-and-windows-authentication-who-goes-first.aspx

When using SSPI, the login is negotiated via security tokens between the client and server not an actual user/password.

If you need to connect using other credentials (other than the one currently logged into the Windows box) you can use the Run-As command method outlined here:
http://help.remotedesktopmanager.com/index.html?tipsandtricks_runas_rdm.htm

When checking "Integrated security (Active Directory)" does the "Test Server" button succeed?

Stéfane Lavergne

avatar

Does every user need to be created in RMAD or is the memebership of the Role group enough?

avatar

Not necessarily. You need to make sure the role group has login rights to the server and a mapped user in the database.

Something like:

http://dba.stackexchange.com/questions/2572/how-do-i-assign-an-entire-active-directory-group-security-access-in-sql-server-2

Stéfane Lavergne