Skip to main content

List Windows Groups With Access to SQL Servers

A manager posed the question “Can we list all the Windows groups that have access to all of our database servers?”  The answer is “Yes.” 

It is very easy to do with a short PowerShell script via SMO.

The results are written to a CSV file.

   1:  ## List Windows Groups on a server ##
   2:  ## ./get-WinGrps.ps1
   3:  $start = get-date
   4:  write-host "Start: "  $start
   6:  [reflection.assembly]::LoadWithPartialName("Microsoft.SqlServer.Smo") | out-null
   8:  $FilePath = "C:\Output"
   9:  $OutFile = Join-Path -path $FilePath -childPath ("WindowsGroupsOnServers_" + (get-date).toString('yyyyMMdd_hhmmtt') + ".csv")
  11:  # Version inventory
  12:  @(foreach ($svr in get-content "C:\Input\TestServers.txt")
  13:  {
  15:      $s = New-Object "Microsoft.SqlServer.Management.Smo.Server" $svr
  16:      $s.Logins | ? {$_.LoginType -eq "WindowsGroup"} | select Parent, Name, LoginType
  18:  })  | export-csv -noType $OutFile
  20:  $end = get-date    
  21:  write-host "End: "  $end


Popular posts from this blog

Modifying Endpoint URLs on Availability Group Replicas

I recently had to modify the Endpoint URLs on our SQL Server Availability Group replicas.  The reason for this blog post is that I could not answer the following questions: Do I need to suspend data movement prior to making this change?  Would this change require a restart of the database instance? I spent enough time searching on my own to no avail that I tossed the question to the #sqlhelp hashtag on Twitter and Slack but didn't get an answer prior to executing the change request. After reading the relevant documentation, I think it's probably a good idea to suspend data movement for this change. The T-SQL is straightforward.  USE MASTER GO ALTER AVAILABILITY GROUP [AG1]  MODIFY REPLICA ON 'SQL2012-1' WITH (ENDPOINT_URL = 'TCP://'); ALTER AVAILABILITY GROUP [AG1]  MODIFY REPLICA ON 'SQL2012-2' WITH (ENDPOINT_URL = 'TCP://'); ALTER AVAILABILITY GROUP [AG2]  MODIFY REPLICA ON 'SQL2012-1...

Set Azure App Service Platform Configuration to 64 bit.

If you need to update several Azure App Services' Configuration to change the Platform setting from 32 bit to 64 bit under Configuration | General settings, this script will save you about six clicks per service and you won't forget to press the SAVE button. Ask me I know. 🙄 Login-AzureRmAccount Set-AzureRmContext  -SubscriptionName  "Your Subscription" $ResourceGroupName  =  'RG1' ,  'RG2', 'RG3' foreach  ( $g   in   $ResourceGroupName ) {       # Set PROD slot to use 64 bit Platform Setting      Get-AzureRmWebApp  -ResourceGroupName  $g  | Select Name |  %  {  Set-AzureRmWebApp  -ResourceGroupName  $g  -Name  $_ .Name  -Use32BitWorkerProcess  $false  }       # Set staging slot to use 64 bit Platform setting ...