Interview Question of the Week #056 – How to fix Installation Failure – Rule “Setup account privileges” Failed in SQL Server

Question: How do I fix SQL Server Setup’s failed “Setup account privileges” rule? Read the failed rule and Setup log to identify the missing Windows user right, then correct the effective policy for the authorized setup account.

A gate needs several keys, but a required position in the key tray is empty

During an interview at a large organization, a DBA reported an installation failure. It gave us a practical problem to put in front of the candidate, who solved it. The useful part was not memorizing an error; it was following the evidence.

Original SQL Server setup Global Rules list shows Setup account privileges Failed

Clicking Failed showed this rule result:

Original rule result describes missing backup audit or debug rights

Find the missing right in the log

The original SystemConfigurationCheck_Report.htm named HasSecurityBackupAndDebugPrivilegesCheck. The corresponding Detail.txt entry said the process had SeSecurity and SeBackup, but did not have SeDebug.

Original SQL Server 2014 configuration report identifies HasSecurityBackupAndDebugPrivilegesCheck

  • SeBackupPrivilege: Back up files and directories.
  • SeDebugPrivilege: Debug programs.
  • SeSecurityPrivilege: Manage auditing and security log.

In this case, the missing right was Debug programs. The original wording about the “second one” was easy to misunderstand; the log is the authority.

Inspect the effective Windows policy

Open Local Security Policy with secpol.msc, then Local Policies, User Rights Assignment. The original screenshot shows an empty Debug programs assignment:

Original Local Security Policy shows Debug programs with an empty security setting

I had removed the default Administrators assignment during hardening on that test machine. Restoring the intended account policy and restarting the machine allowed Setup to proceed. On a managed server, coordinate with the policy owner: a domain policy can override local edits.

Run Setup elevated with an authorized account. After a rights change, refresh the account’s logon token as required and rerun the checks. Do not broadly grant Debug programs to ordinary users, bypass the failed check or assume database sysadmin membership fixes a Windows process privilege.

These four screenshots document the historical SQL Server 2014 incident. A current Setup version may label screens differently, so read its current report and Detail.txt instead of assuming the same missing right.

Published by Pinal Dave on SQLAuthority. More of my work at pinaldave.com.


Discover more from SQL Authority with Pinal Dave

Subscribe to get the latest posts sent to your email.

MySQL, SQL Error Messages
Previous Post
Interview Question of the Week #055 – How to Convert ASCII to DECIMAL or DECIMAL to ASCII?
Next Post
Interview Question of the Week #057 – What is GO Statement in SQL SERVER?

Related Posts

20 Comments. Leave new

  • Hi I’m not sure whether I’m posting in the right platform but I’m trying to calculate hours worked between 8 – 16:30 excluding weekends, after-hours, holidays, and lunch time. Was able to find help except for excluding lunch hours. How do I exclude lunch hours in my calculation.

    Reply
  • When the steps above do not work what do you do?

    Reply
  • On Windows Server 2012, I am not able to add or remove any group or user for the Debug Programs Policy. The two buttons are greyed out.

    Reply
    • @Raj – that happens when they are controlled via group policy. You should contact you domain admin to make that changes.

      Reply
  • Jim. if you are unable to Add the Permission, Skip the check by running setup from the command line as so :-

    Setup.exe /ACTION=Install /SkipRules=HasSecurityBackupAndDebugPrivilegesCheck

    Reply
  • How do you run the setup from the command line? My manage auditing and security log is greyed out. Please help out

    Reply
    • You can open command prompt, browse to folder which contains setup.exe and run below command

      Setup.exe /ACTION=Install /SkipRules=HasSecurityBackupAndDebugPrivilegesCheck

      I have not tested.

      Reply
  • Shaik Azaz Ahamed
    April 3, 2017 6:55 pm

    hi
    i am unable to install sql 2012 and the error is “setup account privileges failed” and when itried to skind the rules through that above given command its not installing properly in between the installation getting error,please tell me any other alternative solution that i can install .

    Reply
  • Shaik Azaz Ahamed
    April 3, 2017 7:09 pm

    Pinal Dave Please give me your email id that i can forward the error screen shot which i got after running that command”Setup.exe /ACTION=Install /SkipRules=HasSecurityBackupAndDebugPrivilegesCheck”

    Reply
  • If it can help someone :
    I had to go out of the AD to be able to install sqlserver without debug rights.
    After that you can reintegrate the AD.

    Reply
  • Why doesn’t the article complete the details? *HOW* do I continue to fix the problem???

    Reply
  • Worked for me:

    press Win + R to open cmd.

    browse to the folder of the SQL instalation, in my case “C:\SQL2019\ExpressAdv_ENU” with this command:
    cd C:\SQL2019\ExpressAdv_ENU

    A new line will be created waiting for the command:
    Setup.exe /ACTION=Install /SkipRules=HasSecurityBackupAndDebugPrivilegesCheck

    Press enter, enjoy.

    Reply
  • This has been very useful! Thank you!

    Reply

Leave a Reply

Your email address will not be published. Required fields are marked *

Fill out this field
Fill out this field
Please enter a valid email address.