> For the complete documentation index, see [llms.txt](https://docs.devolutions.net/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.devolutions.net/rdm/de/knowledge-base/how-to-articles/configure-sql-server-for-protected-users-with-integrated-security.md).

# SQL Server für geschützte Benutzer mit integrierter Sicherheit konfigurieren

Hier sind die Schritte zur Konfiguration Ihres SQL Servers, damit Ihre ***Protected Users*** sich mit der Authentifizierungsmethode Integrated Security mit der Datenbank verbinden können.

Laut Microsoft blockiert ***Protected Users*** die Verwendung von [NTLM-Hashes](https://docs.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/protected-users-security-group#domain-controller-protections-for-protected-users) Es ist jedoch möglich, SQL Server so zu konfigurieren, dass er auch [Kerberos für Integrated Security](https://docs.microsoft.com/en-us/sql/database-engine/configure-windows/register-a-service-principal-name-for-kerberos-connections) verwendet. Die gute Nachricht ist, dass dies von Remote Desktop Manager standardmäßig unterstützt wird.

Damit SQL Server die Kerberos-Authentifizierung unterstützt, müssen SPNs erstellt werden. Standardmäßig läuft der Dienst unter Konten, denen die erforderlichen Berechtigungen fehlen. Wir vermuten, dass Sie beim Start von SQL Server die folgenden Meldungen erhalten (die Protokolle können Sie in SSMS unter ***Management SQL Server Logs*** einsehen).

![](https://cdnweb.devolutions.net/docs/docs_en_kb_KB4657.png)

Sie müssen den SQL Server-Dienst so konfigurieren, dass er unter ***Network Service*** läuft, da dieses Konto über die [notwendigen Berechtigungen](https://docs.microsoft.com/en-us/sql/database-engine/configure-windows/register-a-service-principal-name-for-kerberos-connections?view=sql-server-ver15#Permissions) verfügt. Laut [diesem Artikel](https://dba.stackexchange.com/questions/180064/what-should-my-spn-entries-look-like-for-each-sql-instance/180147#180147) ist es auch möglich, die Berechtigungen zum Erstellen von SPNs einem Dienstkonto zu erteilen. Sie müssen außerdem das Konto im SQL Server-Konfigurationsmanager ändern.

<figure><img src="https://cdnweb.devolutions.net/docs/docs_en_kb_KB4659.png" alt=""><figcaption></figcaption></figure>

<figure><img src="https://cdnweb.devolutions.net/docs/docs_en_kb_KB4658.png" alt=""><figcaption></figcaption></figure>

Auf unserem Server meldete SQL Server jedoch weiterhin, dass die SPNs nicht registriert werden konnten. Wir haben [Microsoft Kerberos Configuration Manager for SQL Server](https://www.microsoft.com/en-ca/download/details.aspx?id=39046) verwendet, um die SPNs zu korrigieren. Er zeigt klickbare Schaltflächen in den Aktionsspalten.

<figure><img src="https://cdnweb.devolutions.net/docs/docs_en_kb_KB4660.png" alt=""><figcaption></figcaption></figure>

Nach dem Neustart des SQL Server-Dienstes sollten Sie in den Protokollen „The SQL Server Network Interface library successfully registered the Service Principal Name (SPN) \[ **MSSQLSvc/vdownsrv-sql3.downhill.loc:1433** ] for the SQL Server service.“ sehen.

Zu diesem Zeitpunkt sollte die Verbindung in Remote Desktop Manager wieder funktionieren.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.devolutions.net/rdm/de/knowledge-base/how-to-articles/configure-sql-server-for-protected-users-with-integrated-security.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
