This is a discussion on security of mssql database? within the SQL Server forums, part of the Microsoft SQL Server category; --> Hello, another question from a newbie to mssql. Is there a way of allowing access to database only by ...
| |||||||
| FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
| ||||
| Hello, another question from a newbie to mssql. Is there a way of allowing access to database only by providing username and password (disabling trusted connection and preventing administrator to access database through enterprise manager or otherwise without supplying username and password)? What I would like is that my application upon instalation creates database with appropriate tables (already done this) and somehow solely creates and manages user list and passwords so that there is no access to database other through application. (Application would create a backdoor account should something go wrong) |
| ||||
| You can't deny a SYSADMIN from accessing your database. You just have to ensure that only the right people have the SYSADMIN role. To secure your database through your application, read about Application Roles in Books Online. Make sure all access to data is through stored procedures so that you don't have to grant permissions directly on tables. -- David Portas SQL Server MVP -- |