使用 SQL 委派的管理员权限安装 Azure AD ConnectInstall Azure AD Connect using SQL delegated administrator permissions

在最新的 Azure AD Connect 版本之前,不支持在部署需要 SQL 的配置时使用管理委派。Prior to the latest Azure AD Connect build, administrative delegation, when deploying configurations that required SQL, was not supported. 若要安装 Azure AD Connect,用户需具有 SQL Server 的服务器管理员 (SA) 权限。Users who wanted to install Azure AD Connect needed to have server administrator (SA) permissions on the SQL server.

现在,在使用 Azure AD Connect 最新版本的情况下,可以由 SQL 管理员在带外进行数据库预配,然后由具有数据库所有者权限的 Azure AD Connect 管理员完成安装。With the latest release of Azure AD Connect, provisioning the database can now be performed out of band by the SQL administrator and then installed by the Azure AD Connect administrator with database owner rights.

准备阶段Before you begin

在使用此功能之前需认识到,存在多个移动部件,每一个可能涉及到组织中的不同管理员。To use this feature, you need to realize that there are several moving parts and each one may involve a different administrator in your organization. 下表汇总了各个角色及其在使用此功能部署 Azure AD Connect 的过程中的相应任务。The following table summarizes the individual roles and their respective duties in deploying Azure AD Connect with this feature.

角色Role 说明Description
域或林 AD 管理员Domain or Forest AD administrator 创建域级服务帐户,供 Azure AD Connect 用于运行同步服务。Creates the domain level service account that is used by Azure AD Connect to run the sync service. 有关服务帐户的详细信息,请参阅帐户和权限For more information on service accounts, see Accounts and permissions.
SQL 管理员SQL administrator 创建 ADSync 数据库,授予登录 + dbo 访问权限给 Azure AD Connect 管理员以及域/林管理员创建的服务帐户。Creates the ADSync database and grants login + dbo access to the Azure AD Connect administrator and the service account created by the domain/forest admin.
Azure AD Connect 管理员Azure AD Connect administrator 安装 Azure AD Connect 并在自定义安装过程中指定服务帐户。Installs Azure AD Connect and specifies the service account during custom installation.

使用 SQL 委派的权限安装 Azure AD Connect 的步骤Steps for installing Azure AD Connect using SQL delegated permissions

若要使用数据库所有者权限预配带外数据库并安装 Azure AD Connect,请使用以下步骤。To provision the database out of band and install Azure AD Connect with database owner permissions, use the following steps.

Note

强烈建议在创建数据库时选择 Latin1_General_CI_AS 排序规则,虽然这不是必需的。Although it is not required, it is highly recommended that the Latin1_General_CI_AS collation is selected when creating the database.

  1. 让 SQL 管理员使用不区分大小写的排序规则序列 (Latin1_General_CI_AS) 创建 ADSync 数据库。Have the SQL Administrator create the ADSync database with a case insensitive collation sequence (Latin1_General_CI_AS). 数据库必须命名为 ADSyncThe database must be named ADSync. 安装 Azure AD Connect 时,会将恢复模型、兼容性级别和包含类型更新为正确的值。The recovery model, compatibility level, and containment type are updated to the correct values when Azure AD Connect is installed. 但是,必须由 SQL 管理员来正确设置排序规则序列,否则 Azure AD Connect 会阻止该安装。However the collation sequence must be set correctly by the SQL administrator otherwise Azure AD Connect will block the installation. 若要进行恢复,SA 必须删除并重新创建数据库。To recover the SA must delete and recreate the database.

    Collation

  2. 向 Azure AD Connect 管理员和域服务帐户授予以下权限:Grant the Azure AD Connect administrator and the domain service account the following permissions:

    • SQL 登录名SQL Login
    • 数据库所有者 (dbo) 权限。database owner(dbo) rights.

    权限

    Note

    Azure AD Connect 不支持使用嵌套成员身份登录。Azure AD Connect does not support logins with a nested membership. 这意味着你的 Azure AD Connect 管理员帐户和域服务帐户必须关联到一个被授予了 dbo 权限的登录名。This means your Azure AD Connect administrator account and domain service account must be linked to a login that is granted dbo rights. 它不能仅仅是被分配给某个登录名(具有 dbo 权限)的组的成员。It cannot simply be the member of a group that is assigned to a login with dbo rights.

  3. 向 Azure AD Connect 管理员发送一封电子邮件,指出在安装 Azure AD Connect 时应使用的 SQL Server 和实例。Send an email to the Azure AD Connect administrator indicating the SQL server and instance name that should be used when installing Azure AD Connect.

其他信息Additional information

预配数据库以后,Azure AD Connect 管理员可以在方便的情况下安装并配置本地同步。Once the database is provisioned, the Azure AD Connect administrator can install and configure on-premises synchronization at their convenience.

如果 SQL 管理员从以前的 Azure AD Connect 备份还原了 ADSync 数据库,你需要使用现有的数据库安装新的 Azure AD Connect 服务器。In case the SQL Administrator has restored ADSync database from a previous Azure AD Connect backup, you will need to install the new Azure AD Connect server by using an existing database. 若要详细了解如何通过现有数据库来安装 Azure AD Connect,请参阅使用现有 ADSync 数据库安装 Azure AD ConnectFor more information on installing Azure AD Connect with an existing database, see Install Azure AD Connect using an existing ADSync database.

后续步骤Next steps