Hi,
we're starting to work with ArcGIS 10.3 Enterprise GDB (what used to be called ArcSDE) on MS SQL Server 2012. We're using the following procedure to set up the database:
Works just fine. Question: Can I follow the same workflow except that I use an AD group login rather than an AD user login to authorize user sde?
Thanks, Martin
Solved! Go to Solution.
Hi, we've done some more tests, and I've come to the following conclusion:
Due to the fact that ArcGIS requires the user and schema to be identical when creating datasets, there is no way to have multiple windows-authenticated users create database objects in the same schema.
Also, SQL Server doesn't allow a login authenticated by a group as database owner, so the dbo-variant of creating the SDE schema doesn't work with groups.
So, if you want to give SDE admin rights (create/update SDE schema) to a group of people, you need DB authentication. Also, if you want to have a group of people to be able to create datasets in a common schema, you also need to use DB authentication.
Accounts that edit and read data can be authenticated by AD group logins.
Any comments?
Martin
Hi, we've done some more tests, and I've come to the following conclusion:
Due to the fact that ArcGIS requires the user and schema to be identical when creating datasets, there is no way to have multiple windows-authenticated users create database objects in the same schema.
Also, SQL Server doesn't allow a login authenticated by a group as database owner, so the dbo-variant of creating the SDE schema doesn't work with groups.
So, if you want to give SDE admin rights (create/update SDE schema) to a group of people, you need DB authentication. Also, if you want to have a group of people to be able to create datasets in a common schema, you also need to use DB authentication.
Accounts that edit and read data can be authenticated by AD group logins.
Any comments?
Martin