Why to Use SQL Server Configuration Manager Over Services applet (services.msc)? – Interview Question of the Week #112

Interview question: Why should you change a SQL Server service account with SQL Server Configuration Manager rather than the Windows Services applet (services.msc)?

Answer: SQL Server Configuration Manager changes more than the Windows service logon field. It coordinates SQL Server-specific permissions and protection for the Database Engine service master key. Microsoft advises using it for account and password changes.

A fitted maintenance cradle supports a mechanism and its lock while a generic spanner rests nearby

Interviewers ask this because both tools appear to offer the same account box. If all you remember is the click path, the question seems unfair. The useful answer is what SQL Server needs around that box.

  • Permissions: Configuration Manager updates the settings and Windows permissions that the SQL Server service needs, including registry access. A generic service-account edit does not perform all of that SQL Server configuration.
  • Protected keys: It updates the Windows local security store used to protect the Database Engine’s service master key when the account changes.
  • Password changes: A password changed through Configuration Manager takes effect immediately without restarting the SQL Server service. A change through services.msc requires a service restart.
  • Account changes: Plan for a service restart and verify startup with the new account. The tool can prompt for that restart; changing the account is different from changing only its password.

My earlier answer also described adding the new account to a local SQL Server group. That was too broad as a modern rule. For many current components, permissions are assigned to a per-service SID, which does not change when the logon account changes. Some components and clustered setups still have their own group or permission requirements. Check the component and installation instead of assuming one group-membership step fits every server.

This is why I use Configuration Manager for SQL Server and SQL Server Agent account maintenance, then confirm the service state and review the error log after the change.

Published by Pinal Dave on SQLAuthority. More of my work at pinaldave.com.


Discover more from SQL Authority with Pinal Dave

Subscribe to get the latest posts sent to your email.

SQL Server, SQL Server Configuration, SQL Server Services
Previous Post
How to do Pagination in SQL Server? – Interview Question of the Week #111
Next Post
How to Get Status of Running Backup and Restore in SQL Server? – Interview Question of the Week #113

Related Posts

5 Comments. Leave new

  • Elijah Gagne
    March 5, 2017 8:26 pm

    If you’re using a cluster, I think SSCM will also make the update on all cluster nodes, whereas services.msc will only make the update locally.

    Reply
  • Getting below error

    —————————
    SQL Server Configuration Manager
    —————————
    Cannot connect to WMI provider. You do not have permission or the server is unreachable. Note that you can only manage SQL Server 2005 and later servers with SQL Server Configuration Manager.
    Invalid class [0x80041010]
    —————————
    OK

    What should I do?

    Reply
    • Thanks for your time peter, I would write a blog on the steps we followed to fix your issue.

      Reply
  • James Keirstead
    February 5, 2021 8:11 pm

    Is there a PowerShell equivalent of using Configuration Manger (yet)? We have an instance (I inherited this config) that cycles the services weekly. I would like to implement a better hands-free solution than the current “NET START – – NET STOP” solution.

    Reply

Leave a Reply

Your email address will not be published. Required fields are marked *

Fill out this field
Fill out this field
Please enter a valid email address.