Showing posts with label restrict. Show all posts
Showing posts with label restrict. Show all posts

Friday, February 24, 2012

How to restrict users to particular databases

While web hosting I use Sql Server 2000 as the database. Imagine I have hosted 3 Web Sites. All these 3 users want to modify/update their designs. What I did is I created respective 3 users having access to the respective databases only. So that they can registerd the ip and add to the Sql Server 2000 Enterprise Manager. These users are able to access their own databases only. But all these 3 users are able to access the default databases like master,pubs etc. How to restrict this.

Also suggest which is the optimal way to give control to the respective users while using Sql Server 2000.

====Suresh, P.R, Postal Training Centre, Mysore.

Hi,

Pubs is a samples database, for the rest have a look on:

http://groups.google.de/group/microsoft.public.sqlserver.security/browse_frm/thread/b4f926814e2678e9

HTH, Jens K. Suessmeyer.

http://www.sqlserver2005.de|||... and on production servers it is best to drop PUBS & NorthWind databases.

How to restrict user to tab (no mouse) selection -question transferred to VB Forms

How to restrict user to tab (no mouse) selection -question transferred to VB FormsIt seems like the best source of help for a forms (or webform) based application is by posting in one of the variuos Visual Studion forums.

How to restrict user to tab (no mouse) selection

How to restrict user to tab (no mouse) selectionIt seems like the best source of help for a forms (or webform) based application is by posting in one of the variuos Visual Studion forums.

How to restrict un -authorised persons from using database files

hello,

I am using MS SQL db for my web application . I wanna know if there is any way to protect /secure database files from copied or used by any un authorised person.

Right now any one can copy the data base files(.data and .log) files from MS SQL's data folder, and can use it any where without any problem. But i would like to restrict any un authorised person to use it. Please let me if there is any way to avoide this.

Please help me in this problem

All suggesstions are welcome.

thank you.

-Archana

Hi,

you will have to povide additional folder security on your system, or encrypt the data in every column. There is no other way to do this.

HTH, Jens K. Suessmeyer.

http://www.sqlserver2005.de

Sunday, February 19, 2012

how to restrict SQL running thread

Hi,
We have a big report running on SQLRS2000+SP2. The report has multiple
datasets and queries. When report starts running, the database server it
connects to run query and pull data will start 33 threads and immediately
reach 100% CPU usage for all 8 CPUs. Databases is over 1TB and sets on EMC
SAN. There is no blocking during report generation. There is no sub-report,
so I assume there is only one DB connection.
We are wondering is it possible to restrict the number of threads
instantiated or is it possible to serialize the report generation, only run
1 thread at a time. Please help.
Jasonyou can set the maxdop option in your queries to limit the number of CPU
used during the execution of the query.
select ... from ... option (maxdop 1)
this reduce the number of CPU used in a parrallel query
the maxdop option can be setup at the server level instead-of the query
level; but not recommanded until you suffer performance issues
test the query, reducing the maxdop can reduce the query performance.
if the query takes 1min instead-of 10sec. the user will not be happy!
why its a problem for you if the queries use all the CPU?
"Jason Wang" <aa@.aa.com> wrote in message
news:eSLkGBeRGHA.5108@.TK2MSFTNGP09.phx.gbl...
> Hi,
> We have a big report running on SQLRS2000+SP2. The report has multiple
> datasets and queries. When report starts running, the database server it
> connects to run query and pull data will start 33 threads and immediately
> reach 100% CPU usage for all 8 CPUs. Databases is over 1TB and sets on EMC
> SAN. There is no blocking during report generation. There is no
> sub-report, so I assume there is only one DB connection.
> We are wondering is it possible to restrict the number of threads
> instantiated or is it possible to serialize the report generation, only
> run 1 thread at a time. Please help.
> Jason
>

How to restrict evil create scripts?

Hi,

For a service I'm working on I need to ask the user for their database
create script. It's used to re-create the users database schema in a
temporary database on a in-house server in an automated fashion.

For security reasons, I need to be sure that the create script can only
create tables, columns etc and not things like snooping in other
databases and/or formatting the server.

Can you give me pointers about what the minimum grants are to let good
script execute successfully and evil scripts fail?

Regards,

WardWard,

I would say as long as your permissions are set right you don't have to
worry. If your user only have rights in their own databases they
shouldn't be able to accessother user databases. Xp_Cmdshell which
would be able to delete files or run other OS commands is (by default)
only available to members of the sysadmin role.
So I would say create a empty datbase and grant the user only db_owner
or ddl_admin rights within the database.

Markus|||Ward Bekker (ward@.NospaaMequanimity.nl) writes:

Quote:

Originally Posted by

For a service I'm working on I need to ask the user for their database
create script. It's used to re-create the users database schema in a
temporary database on a in-house server in an automated fashion.
>
For security reasons, I need to be sure that the create script can only
create tables, columns etc and not things like snooping in other
databases and/or formatting the server.
>
Can you give me pointers about what the minimum grants are to let good
script execute successfully and evil scripts fail?


First of all, which version of SQL Server including service pack do you
have?

As M.Bohse said, run the scripts as a user who only have access in that
database, although in that database he need some privs. Very important:
make sure that cross-database chaining is turned off, and that the
database is not set as trustworthy on SQL 2005.

--
Erland Sommarskog, SQL Server MVP, esquel@.sommarskog.se
Books Online for SQL Server 2005 at
http://www.microsoft.com/technet/pr...oads/books.mspx
Books Online for SQL Server 2000 at
http://www.microsoft.com/sql/prodin...ions/books.mspx|||Hi Erland,

Thanks for the tips!

We are running SQL Server 2005.

Ward

Erland Sommarskog wrote:

Quote:

Originally Posted by

Ward Bekker (ward@.NospaaMequanimity.nl) writes:

Quote:

Originally Posted by

>For a service I'm working on I need to ask the user for their database
>create script. It's used to re-create the users database schema in a
>temporary database on a in-house server in an automated fashion.
>>
>For security reasons, I need to be sure that the create script can only
>create tables, columns etc and not things like snooping in other
>databases and/or formatting the server.
>>
>Can you give me pointers about what the minimum grants are to let good
>script execute successfully and evil scripts fail?


>
First of all, which version of SQL Server including service pack do you
have?
>
As M.Bohse said, run the scripts as a user who only have access in that
database, although in that database he need some privs. Very important:
make sure that cross-database chaining is turned off, and that the
database is not set as trustworthy on SQL 2005.
>
>

|||Ward Bekker (ward@.NospaaMequanimity.nl) writes:

Quote:

Originally Posted by

Hi Erland,
>
Thanks for the tips!
>
We are running SQL Server 2005.


In that case you should grant CONTROL on the dbo schema for the database
user. Maybe they are creating other scheams, but then they need to include
GRANTs for that.

You should also use

select name, is_trustworthy_on, is_db_chaining_on
from sys.databases

to make sure that the databases are not marked as trustworthy, or available
for DB-chaning.

--
Erland Sommarskog, SQL Server MVP, esquel@.sommarskog.se
Books Online for SQL Server 2005 at
http://www.microsoft.com/technet/pr...oads/books.mspx
Books Online for SQL Server 2000 at
http://www.microsoft.com/sql/prodin...ions/books.mspx

How to restrict evil create scripts?

Hi,
For a service I'm working on I need to ask the user for their database
create script. It's used to re-create the users database schema in a
temporary database on a in-house server in an automated fashion.
For security reasons, I need to be sure that the create script can only
create tables, columns etc and not things like snooping in other
databases and/or formatting the server.
Can you give me pointers about what the minimum grants are to let good
script execute successfully and evil scripts fail?
Regards,
Ward
Ward Bekker
"Asp.Net Discussions for the Professional Developer"
http://www.dotnettaxi.com
"Free .Net 2.0 C# to/from VB.Net Code Converter"
http://www.dotnettaxi.com/Tools/Converter.aspxI would consider using Virtual Server isolation.
Set up a virtual server, save copies of the vhd/vmc files (set the file
properties to read only), and then each time you have such a script, use a
virtualized environment and 'evil' scripts won't have anything to sniff
around it.
When finished, just delete the VM.
Arnie Rowland, Ph.D.
Westwood Consulting, Inc
Most good judgment comes from experience.
Most experience comes from bad judgment.
- Anonymous
"Ward Bekker" <ward@.NospaaMequanimity.nl> wrote in message
news:eb7es3$c9a$1@.news.cistron.nl...
> Hi,
> For a service I'm working on I need to ask the user for their database
> create script. It's used to re-create the users database schema in a
> temporary database on a in-house server in an automated fashion.
> For security reasons, I need to be sure that the create script can only
> create tables, columns etc and not things like snooping in other databases
> and/or formatting the server.
> Can you give me pointers about what the minimum grants are to let good
> script execute successfully and evil scripts fail?
> Regards,
> Ward
>
> --
> Ward Bekker
> "Asp.Net Discussions for the Professional Developer"
> http://www.dotnettaxi.com
> "Free .Net 2.0 C# to/from VB.Net Code Converter"
> http://www.dotnettaxi.com/Tools/Converter.aspx|||Hi Arnie,
Interesting approach. Is great as a "second line" of defense. SQL Server
can have advanced security configuration, so I was wondering what could
be done in that level. Do you have any idea's about how that?
Thank you,
Ward
Arnie Rowland wrote:
> I would consider using Virtual Server isolation.
> Set up a virtual server, save copies of the vhd/vmc files (set the file
> properties to read only), and then each time you have such a script, use a
> virtualized environment and 'evil' scripts won't have anything to sniff
> around it.
> When finished, just delete the VM.
>

How To Restrict End User to update field in database manually....

Dear Freinds..

I want to protect a field in a table...i want to restrict users to update the value in that field...by manually logging into that database...it can be updated only through the application...if any body manually update the field value...it has to be captured in log with old value...is it possible to do this sql server...if any of u says yes 'its possible' then :beer: other wise :eek:Why do you allow users to manually log into the database in the first place? If you follow good database application design principles and limit all access to the database to stored procedures, you won't have this problem.|||triggers and history tables

http://weblogs.sqlteam.com/brettk/archive/2004/10/20/2242.aspx|||Dear Blindman,

thks for ur opinion ,i respect ur opinion.our aplication is a huge distributed application its running across 4000 location...we are having all the security design in database level..still worrying about some smart users...and our clients very concern on some values should not be tampered on database...since they had those worst experience previously...and more over 100 people are giving support for this app..who is having rights to access the database.......

Cheers
Sathesh.M|||Can you give the support users SELECT permissions, but not UPDATE permissions? That woud allow them to "see" the data, but not to change it.

-PatP|||triggers and history tables

http://weblogs.sqlteam.com/brettk/archive/2004/10/20/2242.aspx

Damn it. I have to start reading your blog. I just wrote something very similar but mine does not have any caveats and I had to deal with synchronizing some existing history tables with the live tables.|||Can you give the support users SELECT permissions, but not UPDATE permissions? That woud allow them to "see" the data, but not to change it.

-PatP
...and even then, you should not allow them to view the tables directly. You should create SQL Views for the data they are allowed to see and then grant SELECT access to those views.|||...and even then, you should not allow them to view the tables directly. You should create SQL Views for the data they are allowed to see and then grant SELECT access to those views.Yeah, but I was trying to KISS.

-PatP

How to restrict editing of SQL Server 2005 data via ODBC link?

I have a sql server 2005 database with Delphi 2006 in the front end and for querrying and reporting we use MS Access 2003 by connecting to this database via ODBC connection. I recently found out that the SQL Server 2005 data connected thus can be edited (updated) from MS Access. I do not want end users to modify/update the SQL Server 2005 data from MS Access while I also want them to have the ability to insert/update/delete rights using the appropriate application interface. For now, I am handling this by creating a user id that is not permitted to update, insert and delete and using the same account in the ODBC. Is there a way in SQL Server 2005 you can control insert/update/delete rights for all users that will be applicable only in the ODBC mode?

Any help will be greatly appreciated.

thulo

Hi Thulo,

If I understand your question correctly, you want to be able to grant permissions to database objects based on the type of the client (ODBC, OLEDB, SqlClient, etc.), is this correct? Unfortunately, this isn't possible by design - the main goal is to provide the same functionality no matter what client is used. Instead, the SQL Server security model recommends what you are actually already doing - grant permissions "per database user". The user is the main permissions-related abstract here (having in mind the schemas, too). The user is related to the corresponding login object, which controls the connectivity part (having in mind endpoints permissions, too).

I understand that the user-based permissions concept might seem like more work, but it would pay off long term when the requirements to your application change.

HTH,
Jivko Dobrev - MSFT
--
This posting is provided "AS IS" with no warranties, and confers no rights.

|||

Hi Jivko,

You got my question right and that answers my question. Thanks so much for your help.

thulo

how to restrict developers from create / delete tables

Can anybody tell me a simple way of removing CREATE/DELETE table rights.
I want developers to be able to do anything but CREATE/DELETE tables.
Thank you.Well by default no one has any abilities in SQL Server. So if they can
already create and delete tables you must have put them in a role that has
these permissions. Chances are you made them dbo? If so you need to remove
them from the dbo role and assign them to a role that has what permissions
you want.
Andrew J. Kelly SQL MVP
"UnkleVo" <isharko@.att.net> wrote in message
news:a3538463.0407140656.53522073@.posting.google.com...
> Can anybody tell me a simple way of removing CREATE/DELETE table rights.
> I want developers to be able to do anything but CREATE/DELETE tables.
>
> Thank you.

how to restrict data insertion upto 50 MB in a table

how to restrict data insertion upto 50 MB in a table?You can put a table in a filegroup and set the file(s) in that group to
a fixed size. Take a look at the ON filegroup clause of the CREATE
TABLE statement and also the ALTER DATABASE filegroup options.

You can also logically restrict a table to some maxium number of rows

CREATE TABLE t1 (... x INTEGER NOT NULL UNIQUE CHECK (x BETWEEN 1 AND
10000), ...)

--
David Portas, SQL Server MVP

Whenever possible please post enough code to reproduce your problem.
Including CREATE TABLE and INSERT statements usually helps.
State what version of SQL Server you are using and specify the content
of any error messages.

SQL Server Books Online:
http://msdn2.microsoft.com/library/...US,SQL.90).aspx
--

How to Restrict all SQL Databases Size

Hello -

I have over 100 MSSQL Databases on my SQL SERVER. How do I restrict
all the MSSQL databases and its transaction logs to 100 MB.

Can someone help me with any script which will do that.

Thanks,

Rubal Jain
www.Rubal.netHi

This will depend on how/what these databases are and what you want to set
the sizes to.
A start could be the script created by:

EXEC master..sp_MSForEachdb 'USE ? SELECT ''ALTER DATABASE '' + db_name() +
'' MODIFY FILE ( name= '' + RTRIM(name) + '', MAXSIZE=200)'' FROM sysfiles
WHERE status & 0x40 <> 0x40 '

John

"Rubal Jain" <rubaljain@.yahoo.com> wrote in message
news:7a30b199.0407150445.56b2a480@.posting.google.c om...
> Hello -
> I have over 100 MSSQL Databases on my SQL SERVER. How do I restrict
> all the MSSQL databases and its transaction logs to 100 MB.
> Can someone help me with any script which will do that.
> Thanks,
> Rubal Jain
> www.Rubal.net

How to restrict access to database to only IUSR_<machinename>

Hello Mark,
Thanks for your message.
What do you mean " I removed TCP/IP and Named Pipes from the SQL Server
Registration from within Enterprise Manager and rebooted the machine."? Do
you mean you have performed the following steps?
1. Right-click 'MYSERVER\SERVER' in SQL Enterprise Manager(SEM), click
Properties.
2. Click General tab in the Properties window, click Network Configuration.
3. Remove TCP/IP and Named Pipes from the "SQL Server Network Utility."
Please let me know what steps you performed.
If SQL Server service didn't start, SQL Server Agent service will not be
started. Please make sure the SQL Server service has been started. You can
follow the steps below to start SQL Server service:
Click Start > All Programs > SQL Server > Service Manager > start SQL
Server service in Service Manager > start SQL Server Agent service in
Service Manager
If you still are unable to start the SQL Server Agent service, please
follow the steps below to attempt to start the SQL Server Agent Services
from a command line, then send the error log files to me.
1. Open a command line window.
2. Run the following command in the command line window:
"C:\Program Files\Microsoft SQL Server\<instance name>\Binn\sqlagent" -c -v
Note: Above command is just a sample. You need to replace the directory
"C:\Program Files\Microsoft SQL Server\<instance name>\ with the real
directory which you installed the SQL Server.
3. Compress all the log files under the directory "C:\Program
Files\Microsoft SQL Server\<instance name>\LOG" and send it to me for
research.
In addition, you can open "SQL Server Network Utility." by clicking Start >
All Programs > SQL server > SQL Server Network Utility, then you can
re-enable TCP/IP and Named Pipes in the SQL Server Network Utility.
If anything is unclear, get in touch.
Sophie Guo
Microsoft Online Partner Support
Get Secure! - www.microsoft.com/security
========================================
=============
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
========================================
=============
This posting is provided "AS IS" with no warranties, and confers no rights.>>Do you mean you have performed the following steps?
Yes, that is correct. When I did that, and rebooted the machine, the
SQLServerAgent would not start. (It would start, then immediately stop).
Therefore I could not open my database using Enterprise Manager.
NOTE: I had also set the 'Hide Server' switch, and suspect this may have
been part of the problem as well.
SOLUTION: I went into the registry under
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Mi
crosoft SQL
Server\MIRACLECAT\MSSQLServer\SuperSocke
tNetLib\Tcp and set the TcpHideFlag
back to zero and then rebooted and all worked again.
I think I may just depend on Windows Server 2003 blocking post 1433 (SQL
Server Port) and let it go at that since temporarily losing my SQL databases
put quite a scare into me
Thanks for all your help however.
Mark
"Sophie Guo [MSFT]" <v-sguo@.online.microsoft.com> wrote in message
news:HCsqCPf%23EHA.3360@.cpmsftngxa10.phx.gbl...
> Hello Mark,
> Thanks for your message.
> What do you mean " I removed TCP/IP and Named Pipes from the SQL Server
> Registration from within Enterprise Manager and rebooted the machine."?
> Do
> you mean you have performed the following steps?
> 1. Right-click 'MYSERVER\SERVER' in SQL Enterprise Manager(SEM), click
> Properties.
> 2. Click General tab in the Properties window, click Network
> Configuration.
> 3. Remove TCP/IP and Named Pipes from the "SQL Server Network Utility."
> Please let me know what steps you performed.
> If SQL Server service didn't start, SQL Server Agent service will not be
> started. Please make sure the SQL Server service has been started. You can
> follow the steps below to start SQL Server service:
> Click Start > All Programs > SQL Server > Service Manager > start SQL
> Server service in Service Manager > start SQL Server Agent service in
> Service Manager
> If you still are unable to start the SQL Server Agent service, please
> follow the steps below to attempt to start the SQL Server Agent Services
> from a command line, then send the error log files to me.
> 1. Open a command line window.
> 2. Run the following command in the command line window:
> "C:\Program Files\Microsoft SQL Server\<instance
> name>\Binn\sqlagent" -c -v
> Note: Above command is just a sample. You need to replace the directory
> "C:\Program Files\Microsoft SQL Server\<instance name>\ with the real
> directory which you installed the SQL Server.
> 3. Compress all the log files under the directory "C:\Program
> Files\Microsoft SQL Server\<instance name>\LOG" and send it to me for
> research.
>
> In addition, you can open "SQL Server Network Utility." by clicking Start
> All Programs > SQL server > SQL Server Network Utility, then you can
> re-enable TCP/IP and Named Pipes in the SQL Server Network Utility.
> If anything is unclear, get in touch.
> Sophie Guo
> Microsoft Online Partner Support
> Get Secure! - www.microsoft.com/security
> ========================================
=============
> When responding to posts, please "Reply to Group" via your newsreader so
> that others may learn and benefit from your issue.
> ========================================
=============
> This posting is provided "AS IS" with no warranties, and confers no
> rights.
>

How to restrict access to database to only IUSR_<machinename>

Hello Mark,
Based on the problem description, it seems that you'd like to let all the
application which is running internally can access SQL server successfully.
However, outside users cannot access SQL server from internet.
If this is what you want, you can remove TCP/IP and Named Pipes in the "SQL
Server Network Utility." You can follow the steps below:
a. On the Microsoft SQL Server 2000 server, start the SQL Server Network
Utility.
b. Click the General tab, and then select the instance you want from the
Instances drop-down menu.
c. Highlight TCP/IP, and then click Disable.
d. Highlight Named Pipes, and then click Disable.
By doing so, users still can access SQL server internally instead of
internet.
I hope above information is helpful.
Sophie Guo
Microsoft Online Partner Support
Get Secure! - www.microsoft.com/security
========================================
=============
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
========================================
=============
This posting is provided "AS IS" with no warranties, and confers no rights.I think I boo-boo'd
I removed TCP/IP and Named Pipes from the SQL Server Registration from
within Enterprise Manager and rebooted the machine.
Now the SQL Server agent won't start, and therefore I can't get into the SQL
Server Registration again since the agent isn't running.
The SQLServerAgent is stopped, and when I attempt to start it, it just
starts and immediately stops again.
The event viewer shows the following:
SQLServerAgent could not be started (reason: Unable to connect to server
'MYSERVER\SERVER'; SQLServerAgent cannot start).
Is there anything I can do to recover?
Thanks!
"Sophie Guo [MSFT]" <v-sguo@.online.microsoft.com> wrote in message
news:OWhx%23YW%23EHA.3360@.cpmsftngxa10.phx.gbl...
> Hello Mark,
> Based on the problem description, it seems that you'd like to let all the
> application which is running internally can access SQL server
> successfully.
> However, outside users cannot access SQL server from internet.
> If this is what you want, you can remove TCP/IP and Named Pipes in the
> "SQL
> Server Network Utility." You can follow the steps below:
> a. On the Microsoft SQL Server 2000 server, start the SQL Server Network
> Utility.
> b. Click the General tab, and then select the instance you want from the
> Instances drop-down menu.
> c. Highlight TCP/IP, and then click Disable.
> d. Highlight Named Pipes, and then click Disable.
>
> By doing so, users still can access SQL server internally instead of
> internet.
> I hope above information is helpful.
> Sophie Guo
> Microsoft Online Partner Support
> Get Secure! - www.microsoft.com/security
> ========================================
=============
> When responding to posts, please "Reply to Group" via your newsreader so
> that others may learn and benefit from your issue.
> ========================================
=============
> This posting is provided "AS IS" with no warranties, and confers no
> rights.
>

How to restrict access to database to only IUSR_<machinename>

I am running IIS and SQL Server on the same Win2003 Server machine. Is there
a way to set up security such that only IUSR_<machine> is allowed to access
the SQL Server 2000, even if outsiders have the connection string to the
database?
Thanks for any assistance!only create the account iusr_computername
"Mark Findlay" <mfindlay@.speakeasy.org> wrote in message
news:%23OLNjKN%23EHA.2192@.TK2MSFTNGP14.phx.gbl...
> I am running IIS and SQL Server on the same Win2003 Server machine. Is
there
> a way to set up security such that only IUSR_<machine> is allowed to
access
> the SQL Server 2000, even if outsiders have the connection string to the
> database?
> Thanks for any assistance!
>|||Unfortunately that's not a reasonable alternative for me since there are
many accounts on that machine that make use of other resources on that
machine.
I believe the solution is to block port 1433, but I don't know how to block
port 1433 on Windows Server 2003. Can anyone assist?
Thanks!
"Olu Adedeji" <i-oluade@.microsoft.com> wrote in message
news:eKLc6hQ%23EHA.2452@.TK2MSFTNGP14.phx.gbl...
> only create the account iusr_computername
> "Mark Findlay" <mfindlay@.speakeasy.org> wrote in message
> news:%23OLNjKN%23EHA.2192@.TK2MSFTNGP14.phx.gbl...
> there
> access
>

How to restrict access our DB on SQL server.

Hi,
How can we restrict our DB if connecting thru other applications like SQL query analyzer, Excel & even Enterprise manager?
but this DB should be accessible by our application (from front end) only...
I learned about "Application Role" in SQL server 2000 but to apply this
we will have to change our code thousand places.
Have any idea...Pl. do suggest?
Thanx in advance!!!!
Regards,
Paresh...
Message posted via http://www.sqlmonster.com
Don't give out the passwords and they won't be able to login. If they have
a login and password then they can get in and do what ever the current
permissions allow them to.
Andrew J. Kelly SQL MVP
"paresh goyal via SQLMonster.com" <forum@.SQLMonster.com> wrote in message
news:d15479cc26b24cf0a782a131acead60a@.SQLMonster.c om...
> Hi,
> How can we restrict our DB if connecting thru other applications like SQL
> query analyzer, Excel & even Enterprise manager?
> but this DB should be accessible by our application (from front end)
> only...
> I learned about "Application Role" in SQL server 2000 but to apply this
> we will have to change our code thousand places.
> Have any idea...Pl. do suggest?
> Thanx in advance!!!!
> Regards,
> Paresh...
> --
> Message posted via http://www.sqlmonster.com
|||Sounds like you're looking for a solution that might not exist. If your
users that currently use the applications login to SQL with their own
userids, they can use the same userids with any query tool and do whatever
they have permissions for. You could try to use different ports, server
aliases, etc... to make it tougher for them to discover where the actual
sql db sits but it's just a speed bump, not a barrier.
aK.
"paresh goyal via SQLMonster.com" <forum@.SQLMonster.com> wrote in message
news:d15479cc26b24cf0a782a131acead60a@.SQLMonster.c om...
> Hi,
> How can we restrict our DB if connecting thru other applications like SQL
query analyzer, Excel & even Enterprise manager?
> but this DB should be accessible by our application (from front end)
only...
> I learned about "Application Role" in SQL server 2000 but to apply this
> we will have to change our code thousand places.
> Have any idea...Pl. do suggest?
> Thanx in advance!!!!
> Regards,
> Paresh...
> --
> Message posted via http://www.sqlmonster.com

How to Restrict

I have one table named "serving" and I want that against serving ID there
should be 42 records not more or less than that, how can I restrict that ?
Waiting for your reply
Thanks
NOOR
Use an Insert Trigger taht will do Select Count(*) from the table, and if
the number is > 42, rollback the transaction.
Dejan Sarka, SQL Server MVP
Associate Mentor
Solid Quality Learning
More than just Training
www.SolidQualityLearning.com
"Noorali Issani" <naissani@.softhome.net> wrote in message
news:OG7VB%23xMEHA.3208@.TK2MSFTNGP10.phx.gbl...
> I have one table named "serving" and I want that against serving ID there
> should be 42 records not more or less than that, how can I restrict that ?
> Waiting for your reply
> Thanks
> NOOR
>