You are working as a trusted DBA responsible for some extremely important SQL Servers for your company. For the sake of security, you have performed the following steps to secure SQL Servers:
- You have removed any and all built-in administrators account from SQL Server logins
- You have removed all the users (except SA) that were part of SYSADMIN server role (Including any Windows Accounts and/or SQL Server logins)
- You have set the password of SA to something extremely complex which is hard to remember.
- For day-to-day operations on SQL Server, you use your domain user account which has DBO permissions on couple of databases but doesn't have SYSADMIN privileges.
What would you do now?
Some quick options I can think of are listed below:
- You will try to look for the SA password on your computer hard-drive or in your emails (If you stored it in some file which is a bad practice)
- You will rebuild Master database or reinstall SQL Server and attach all the user databases. However, this could take some time and also doesn't guarantee that all your logins, users, permissions and server configurations will be recovered unless you plan to restore the Master database from an old backup. However, as you don't remember the SA password, restoring the Master database will not help you and you are back to square one.
- You will call up Microsoft PSS
There's a way with which you can gain SYSADMIN access to your SQL Server. However, that would mean your Windows account will need to be a member of the local administrators group.
SQL Server allows any member of Local Administrators group to connect to SQL Server with SYSADMIN privileges.
Here are the steps you will need to perform:
- Start the SQL Server instance using single user mode (or minimal configuration which will also put SQL Server in single user mode)
From the command prompt type: SQLServr.Exe –m (or SQLServr.exe –f)
(Usually the Binn folder is located at: C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn)
- Once SQL Server service has been started in single user mode or with minimal configuration, you can now use the SQLCMD command from command prompt to connect to SQL Server and perform the following operations to add yourself back as an Admin on SQL Server instance.
SQLCMD –S <Server_Name\Instance_Name>
You will now be logged in to SQL Server as an Admin.
- Once you are logged into the SQL Server using SQLCMD, issue the following commands to create a new account or add an existing login to SYSADMIN server role.
To create a new login and add that login to SYSADMIN server role:
1> CREATE LOGIN '<Login_Name>' with PASSWORD='<Password>'
2> go
1> SP_ADDSRVROLEMEMBER '<Login_Name>','SYSADMIN'
2>go
To add an existing login to SYSADMIN server role, execute the following:
- SP_ADDSRVROLEMEMBER '<LOGIN_NAME>','SYSADMIN'
- Once the above steps are successfully performed, the next step is to stop and start SQL Server services using regular startup options. (This time you will not need –f or –m)
Credits : Saleem Hakani
No comments:
Post a Comment