<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Windows group authentication for SDE user on SQL Server/ArcGIS 10.3? in Geodatabase Questions</title>
    <link>https://community.esri.com/t5/geodatabase-questions/windows-group-authentication-for-sde-user-on-sql/m-p/807785#M3003</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we're starting to work with ArcGIS 10.3 Enterprise GDB (what used to be called ArcSDE) on MS SQL Server 2012. We're using the following procedure to set up the database:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Create a new database (say DB1) as sysadmin (sa)&lt;/LI&gt;&lt;LI&gt;Create a windows authenticated login (e.g. AD user mydomain\martin)&lt;/LI&gt;&lt;LI&gt;Create a database user sde in the DB1 and map this to mydomain\martin&lt;/LI&gt;&lt;LI&gt;Ccreate a schema sde and grant the necessary privileges (create table, view, function, procedure) to user sde.&lt;/LI&gt;&lt;LI&gt;Login as mydomain\martin on a desktop machine, start ArcCatalog, add a database connection with windows authentication and run the Enable Geodatabase tool.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Works just fine. Question: Can I follow the same workflow except that I use an AD &lt;STRONG&gt;group&lt;/STRONG&gt; login rather than an AD user login to authorize user sde?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, Martin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 17 Feb 2015 16:53:56 GMT</pubDate>
    <dc:creator>MartinAmeskamp</dc:creator>
    <dc:date>2015-02-17T16:53:56Z</dc:date>
    <item>
      <title>Windows group authentication for SDE user on SQL Server/ArcGIS 10.3?</title>
      <link>https://community.esri.com/t5/geodatabase-questions/windows-group-authentication-for-sde-user-on-sql/m-p/807785#M3003</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we're starting to work with ArcGIS 10.3 Enterprise GDB (what used to be called ArcSDE) on MS SQL Server 2012. We're using the following procedure to set up the database:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Create a new database (say DB1) as sysadmin (sa)&lt;/LI&gt;&lt;LI&gt;Create a windows authenticated login (e.g. AD user mydomain\martin)&lt;/LI&gt;&lt;LI&gt;Create a database user sde in the DB1 and map this to mydomain\martin&lt;/LI&gt;&lt;LI&gt;Ccreate a schema sde and grant the necessary privileges (create table, view, function, procedure) to user sde.&lt;/LI&gt;&lt;LI&gt;Login as mydomain\martin on a desktop machine, start ArcCatalog, add a database connection with windows authentication and run the Enable Geodatabase tool.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Works just fine. Question: Can I follow the same workflow except that I use an AD &lt;STRONG&gt;group&lt;/STRONG&gt; login rather than an AD user login to authorize user sde?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, Martin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Feb 2015 16:53:56 GMT</pubDate>
      <guid>https://community.esri.com/t5/geodatabase-questions/windows-group-authentication-for-sde-user-on-sql/m-p/807785#M3003</guid>
      <dc:creator>MartinAmeskamp</dc:creator>
      <dc:date>2015-02-17T16:53:56Z</dc:date>
    </item>
    <item>
      <title>Re: Windows group authentication for SDE user on SQL Server/ArcGIS 10.3?</title>
      <link>https://community.esri.com/t5/geodatabase-questions/windows-group-authentication-for-sde-user-on-sql/m-p/807786#M3004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, we've done some more tests, and I've come to the following conclusion:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Due to the fact that ArcGIS requires the user and schema to be identical when creating datasets, there is no way to have multiple windows-authenticated users create database objects in the same schema.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, SQL Server doesn't allow a login authenticated by a group as database owner, so the dbo-variant of creating the SDE schema doesn't work with groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, if you want to give SDE admin rights (create/update SDE schema) to a group of people, you need DB authentication. Also, if you want to have a group of people to be able to create datasets in a common schema, you also need to use DB authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Accounts that edit and read data can be authenticated by AD group logins.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any comments?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Martin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Feb 2015 08:31:01 GMT</pubDate>
      <guid>https://community.esri.com/t5/geodatabase-questions/windows-group-authentication-for-sde-user-on-sql/m-p/807786#M3004</guid>
      <dc:creator>MartinAmeskamp</dc:creator>
      <dc:date>2015-02-26T08:31:01Z</dc:date>
    </item>
  </channel>
</rss>

