To pursue best practice for SQL Service accounts, I’m working through changing the SQL service account to be AD accounts for our existing SQL servers. The first one I did was fine because it was a fresh install. But for existing servers, making the change, I’m not sure about the “rights” required. The how-to states:
The SQL Server setup program will grant the necessary rights on the machine to that account during installation.
But if I’m not doing a fresh install, I guess I don’t know what the necessary rights are. I know I will:
- Apply Perform Volume Maintenance Tasks Right
- Apply Lock pages in memory right
- Disable interactive login for the AD service account
- Add AD service account to local Administrators group
Is there anything more needed to be done to successfully transfer the SQL Service account from NT SERVICEMSSQLSERVER?