NAS 4.03 minimum permissions in SQL Server
davmac1
Member Posts: 1,283
We are trying to determine minimum permissions needed to run NAS to keep our SOX auditors happy.
The only reliable combination we have found is NAV SUPER permissions and dbo rights to the database. If we don't give dbo rights, it has problems reading Navision tables.
The NAV license is loaded in the SQL Server.
Is there a lesser set of rights that work for NAS?
The only reliable combination we have found is NAV SUPER permissions and dbo rights to the database. If we don't give dbo rights, it has problems reading Navision tables.
The NAV license is loaded in the SQL Server.
Is there a lesser set of rights that work for NAS?
David Machanick
http://mibuso.com/blogs/davidmachanick/
http://mibuso.com/blogs/davidmachanick/
0
Comments
-
The users just need public role. Get in contact with a partner to setup your db correctly.0
-
-
Are you sure it's not something with the code that is creating this issue? No NAV client, including NAS, should ever need to be DBO.There are no bugs - only undocumented features.0
-
Our dbas have locked down permissions in SQL Server
Should I be looking at an approle account?David Machanick
http://mibuso.com/blogs/davidmachanick/0 -
Define "locked down". NAV only requires the minimum permissions of membership in the "Public" roles both at server and database level. It requires no additional permissions on the SQL end.
What error is NAS reporting?There are no bugs - only undocumented features.0 -
And best use the Standard Security Model and not the Enhanced one.
The dbowner is only needed if you need to change/insert tables like when importing objects.Regards,Alain Krikilion
No PM,please use the forum. || May the <SOLVED>-attribute be in your title!0 -
What is the exact error the NAS reports? I'm think one possibility is that the NAS process is trying to insert a non-blank value into an auto-increment field. And that's why it only works as DBO.There are no bugs - only undocumented features.0
-
Inbetween other tasks, I have been checking the code, and it is doing a transferfields to an archive table where the primary key is autoincrement. Probably the result of copy and paste.
When I archive, I typically add a separate key field for the archive table.
I will ask the provider to look at changing it. (We have internal rules on who can change what.)David Machanick
http://mibuso.com/blogs/davidmachanick/0 -
Hi
We had a similiar problem caused by table inserts in tables containing autoincrement values in pk. The problem arised if the value for the autoincrement part was not zero. In this case SQL server executed "Set Identity_Insert", but this was only possible in the context of a dbo or higher.
Solution was to eliminate the C/AL code causing the autoincrement value to be <> 0 or dont use autoincrement.
Also look here: viewtopic.php?f=23&t=14145
Hope this helps
Thomas0
Categories
- All Categories
- 75 General
- 75 Announcements
- 66.7K Microsoft Dynamics NAV
- 18.8K NAV Three Tier
- 38.4K NAV/Navision Classic Client
- 3.6K Navision Attain
- 2.4K Navision Financials
- 116 Navision DOS
- 851 Navision e-Commerce
- 1K NAV Tips & Tricks
- 772 NAV Dutch speaking only
- 611 NAV Courses, Exams & Certification
- 2K Microsoft Dynamics-Other
- 1.5K Dynamics AX
- 253 Dynamics CRM
- 103 Dynamics GP
- 6 Dynamics SL
- 1.5K Other
- 991 SQL General
- 383 SQL Performance
- 34 SQL Tips & Tricks
- 28 Design Patterns (General & Best Practices)
- Architectural Patterns
- 9 Design Patterns
- 4 Implementation Patterns
- 53 3rd Party Products, Services & Events
- 1.6K General
- 1K General Chat
- 1.6K Website
- 77 Testing
- 1.2K Download section
- 23 How Tos section
- 249 Feedback
- 12 NAV TechDays 2013 Sessions
- 13 NAV TechDays 2012 Sessions
