16.01.2013 Views

Microsoft Sharepoint Products and Technologies Resource Kit eBook

Microsoft Sharepoint Products and Technologies Resource Kit eBook

Microsoft Sharepoint Products and Technologies Resource Kit eBook

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

700 Part VIII: Securing SharePoint <strong>Products</strong> <strong>and</strong> <strong>Technologies</strong><br />

The single sign-on service account must be a member of the public database<br />

role on the SharePoint Portal Server configuration database.<br />

Note On a single server deployment, if the single sign-on service runs<br />

under an account that is a member of the local Administrators group, you<br />

do not need to ensure that the user has the public right on the configuration<br />

database. However, for security reasons it is recommended that you do not<br />

run the service under an account that is a member of the local Administrators<br />

group.<br />

To assign rights on the configuration database, do the following:<br />

1. On the SQL Server computer, open SQL Server Enterprise Manager.<br />

2. Exp<strong>and</strong> the <strong>Microsoft</strong> SQL Servers node.<br />

3. Exp<strong>and</strong> the SQL Server Group node.<br />

4. Exp<strong>and</strong> the (local) (Windows NT) node.<br />

5. Exp<strong>and</strong> the Security node.<br />

6. Click Logins, <strong>and</strong> then do one of the following:<br />

■ If the logon name does not exist, right-click Logins, click New Login,<br />

<strong>and</strong> then in the Name box, type the account for the user in the format<br />

DOMAIN\user_name.<br />

■ If the logon name already exists, right-click the logon name, <strong>and</strong> then<br />

click Properties.<br />

7. Click the Database Access tab.<br />

8. In the Specify which databases can be accessed by this login section,<br />

select the check box for the configuration database.<br />

9. In the Database roles for database_name section, select the public<br />

check box.<br />

10. Click OK.<br />

11. Close SQL Server Enterprise Manager.<br />

The single sign-on service account must be a member of the Server Administrators<br />

server role on the SQL Server instance where the single sign-on database is<br />

located.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!