Note You must give the ASPNET user account only minimal permissions to run. This limits the potential damage that may result to an ASP.NET application that is compromised by a malicious attacker.
back to the top
- On the taskbar, click start.
- Point to Programs and then point to
Microsoft SQL Server.
- Double-click Enterprise Manager.
- Expand Microsoft SQL Servers and then expand the SQL Server group that contains your server.
- Expand your server branch and then expand
- Right-click Logins and then select
New Login to open the SQL Server Login Properties-New Login dialog box.
- Click the General tab. In the name field, enter the name of the ASP.NET user.
By default, this is a local account with the name ASPNET.
- Click the Database Access tab.
- Under Specify Which Databases Can Be Accessed By This Login, select the databases that are used by the ASP.NET application.
You generally do not have to permit access to the Model database, the Master database, the Msdb database, or the Tempdb database.
- For each database that the account requires access to, verify that the Public role in the Permit In Database Role list is selected.
- Click OK to return to Enterprise Manager.
- Expand the Databases branch, and then expand the branch for the database that your ASP.NET application requires access to. Click to select Users.
- In the right pane, right-click the ASPNET user account and then click Properties.
Database User Properties dialog box appears.
- Click Permissions.
A new dialog box appears. This dialog box shows the permissions for the ASPNET user account for all objects in the database. Scroll through the list and then select the check boxes that are associated with the tables and the views that the application requires access to. For tables and views that the application must read, but not write to, select only the SELECT column. For tables and views that must be updated, select the SELECT, the
UPDATE, the INSERT, and the
DELETE check boxes as appropriate.
- After you grant all the required permissions, click
OK two times to return to Enterprise Manager.
- Close Enterprise Manager.
Article ID: 815154 - Last Review: May 21, 2009 - Revision: 1