Enterprise Vault™ Using SQL Database Roles in Enterprise Vault, Compliance Accelerator, and Discovery Accelerator

Last Published:
Product(s): Enterprise Vault (14.1, 14.0, 12.5, 12.4, 12.3, 12.2, 12.1, 12.0)
  1. About this guide
    1.  
      Introducing this guide
  2. Using Enterprise Vault database roles
    1.  
      About Enterprise Vault database roles
    2. Configuring the Vault Service account for normal operations
      1.  
        Preparing to configure the Vault Service account
      2.  
        Configuring the Vault Service account's SQL login
      3.  
        Changing ownership of Enterprise Vault databases
      4.  
        Assigning the Vault Service account to EVRuntimeRole
      5.  
        Mapping the Vault Service account to the msdb system database
      6.  
        Creating EVMonitoringOperator in the msdb system database and assigning Vault Service account
      7.  
        Restarting Enterprise Vault services
    3.  
      Configuring the Vault Service account for operations that require elevated privileges
  3. Using Compliance Accelerator and Discovery Accelerator roles
    1.  
      About Compliance Accelerator and Discovery Accelerator database roles
    2. Configuring the Vault Service account for normal operations
      1.  
        Preparing to configure the Vault Service account
      2.  
        Configuring the Vault Service account's SQL login
      3.  
        Changing ownership of Compliance Accelerator and Discovery Accelerator databases
      4.  
        Assigning the Vault Service account to EVRuntimeRole
      5.  
        Mapping the Vault Service account to the msdb system database
      6.  
        Creating EVScheduledSearchOperator in the msdb system database and assigning the Vault Service account
      7.  
        Creating EVAnalyticsOperator in the msdb system database and assigning the Vault Service account
      8.  
        Restarting Compliance Accelerator and Discovery Accelerator services
    3.  
      Configuring the Vault Service account for operations that require elevated privileges

Configuring the Vault Service account's SQL login

Use this procedure to take away the elevated SQL privileges that are assigned to the Vault Service account in a normal installations of Compliance Accelerator and Discovery Accelerator, and then assign only the reduced privileges that are required for normal daily operations.

To configure the Vault Service account's SQL login

  1. Connect to the SQL server using SQL Server Management Studio.
  2. In Object Explorer, under Security > Logins, double-click the Vault Service account.
  3. In the Login Properties dialog box, select the Server Roles page.
  4. Under Server roles, clear the dbcreator and sysadmin options, then click OK.
  5. In Object Explorer, right-click the top-level server instance, and click Properties.
  6. In the Server Properties dialog box, select the Permissions page.
  7. Under Logins or roles, select the Vault Service account.
  8. On the Explicit tab, select the Grant option for Create any database, View server state, and View any Definition, and then click OK.