About credentials used with SQL Server Intelligent Policy
SQL Server instances or replicas must be registered with Windows credentials that have the proper permissions to perform backup and restore operations. Intelligent Policy supports Windows authentication and Windows Active Directory authentication. It does not support Mixed Mode or SQL Server authentication. Credentials are not supported at the database level.
Table: Options to register credentials
Option to register credentials | Environment or configuration | Notes |
|---|---|---|
|
Use these specific credentials |
| (Recommended) Veritas recommends that you use this option to register credentials. See Requirements when you use specific credentials for registration. |
Use credentials that are defined locally on the client |
| The NetBackup services run as a privileged SQL Server user on the client. See Requirements when you use locally defined credentials for registration. |
Add to group and register using group credentials | You want to be able to do one or more of the following:
| The group can be configured so instances or replicas in the group all use a specific set of credentials. Or, instances or replicas in the group can use separate, locally defined credentials. See Registering instances or availability replicas with an instance group. |
Command line |
|
The following requirements apply when you use the option for registration:
The user must have the SQL Server "sysadmin" role.
The user must be a member of the Windows Administrators group.
The logon account for the NetBackup Client Service and the NetBackup Legacy Network Service can be either the SQL System administrator or Local System. The services do not have to use the same logon account.
See Configuring the NetBackup services for SQL Server backups and restores.
The logon account for the NetBackup Client Service and the NetBackup Legacy Network Service must have the privileges to and .
When you use the option for registration, NetBackup uses the credentials for the user that installed NetBackup. The following requirements apply with this option:
The user must have the SQL Server "sysadmin" role.
The user must be a member of the Windows Administrators group.
The logon account for the NetBackup Client Service and the NetBackup Legacy Network Service can be either the SQL System administrator or Local System. The services must use the same logon account.
See Configuring the NetBackup services for SQL Server backups and restores.
To register an instance or replica from the command line, the following configuration is required:
The NetBackup administrator must authorize the nbsqladm command for a specific DBA or user on a specific host.
On the NetBackup master server, use nbsqladm to authorize the user:
nbsqladm [-S master_server] -add_dba host_name user_name
If you have multiple NICs, authorize the DBA using the private interface name of the SQL Server host. For a SQL Server cluster, authorize the DBA for each node in the cluster. (Do not authorize a DBA using the virtual name of the SQL Server cluster.) For the -host name provide one of the node names in the SQL Server cluster. For a SQL Server cluster with multiple NICs, authorize the DBA using the private interface name for each of the nodes in the SQL Server cluster.
Once a DBA is authorized to use the nbsqladm command, the DBA can register instances with the local credentials (-local_credentials) or other specific credentials (-user name -domain name).
For complete details on the nbsqladm command, see the NetBackup Commands Reference Guide.
When NetBackup discovers a SQL Server cluster, it adds a single entry in the Applications utility. This instance represents all nodes in the cluster. The host name is the virtual name of the SQL Server cluster. When you register this instance NetBackup validates the credentials on the active node. The credentials must be valid for all nodes in the cluster.
When NetBackup discovers a SQL Server host that uses multiple NICs, it adds an entry using the NetBackup client name in the Applications utility. If you installed the NetBackup client using the public interface name, you must configure the NetBackup client name as the private interface name. Then register the instance with its private interface name. For a SQL Server cluster that uses multiple NICs, add and register the instance with the private virtual name of the SQL Server cluster.
See Configuring the NetBackup client with the private interface name.
After you add credentials, NetBackup validates the credentials, marks the instances as registered, and adds the instances to the NetBackup database. NetBackup requests detailed information about the instances or replicas from the NetBackup client and displays it in the or nodes.
For a SQL Server cluster or if an availability group instance is part of SQL Server cluster, NetBackup validates the credentials on the active node. The credentials must be valid for all nodes in the cluster. For a SQL Server availability group, replicas are registered and validated individually.
If you choose to save the credentials despite a validation failure, the instances or replicas are still marked as registered. NetBackup cannot successfully protect an instance or an availability group without valid credentials.
See Troubleshooting credential validation in the Applications utility.