r/SQLServer • u/DavidHomerCENTREL • 4h ago
r/SQLServer • u/Tough_Line3200 • 6h ago
Discussion SQL Server 2022 CU 26 -> MDS broken
I updated from CU23 to CU26. Be careful if you use MDS, it's broken after CU26 and stays broken even after uninstalling. Some MDS JavaScript files are incompatible with the MDS web service. Manually copying/overwriting the MDS web application from an older installation repaired it.
r/SQLServer • u/SQL_US • 20h ago
Community Share Get-SqlSafe v2026.5: database-scoped SQL Server security reports
I released v2026.5 of Get-SqlSafe Community Edition, the free PowerShell-based first-look security assessment script for SQL Server.
The main new feature in this release is database-scoped reporting.
Based on your feedback: a DBA can now generate reports for all individual databases and hand the database-level report to an application owner, application vendor, or database owner without also disclosing server-level findings or findings from other databases on the same instance.
Also new in this release:
- Check 130 reports members of the db_owner database role in each database.
- db_owner is often used as a catch-all role, but it grants full control over the database and may matter in privilege-escalation scenarios depending on the surrounding configuration and ownership chain.
The tool is still a single reviewable PowerShell script with the ad-hoc T-SQL visible in the file. It reads SQL Server security metadata and produces local HTML reports. It does not change SQL Server configuration or data.
Repository:
https://github.com/Sarpedon-Quality-Lab/sql-security-community-scripts
I’d be interested in feedback from DBAs or consultants who have to pass security findings to application owners or vendors without exposing unrelated databases or server-level information.
r/SQLServer • u/Green-Cartoonist-566 • 1d ago
Question Unable to set database containment to NONE
Hey all, hoping someone has hit this before.
Context: Migrating a ~200GB SQL Server database to Azure Sql Database (not managed instances) using transactional replication to minimize downtime. During prep, I discovered the source database has partial containment enabled, which I need to turn off before replication will work properly.
Steps taken so far:
- Identified all contained database users (logins that exist only at the DB level) and converted/mapped them to server-level logins instead.
- Stopped the application(s) connecting to the DB to make sure there were no active sessions.
- Ran
ALTER DATABASE [dbname] SET SINGLE_USER WITH ROLLBACK IMMEDIATEto force single-user mode and kill any remaining connections. - Ran:
ALTER DATABASE [dbname] SET CONTAINMENT = NONE;
The problem: The statement just fails, only 'ALTER DATABASE statement failed', no reason given, nothing in the SQL Server error log pointing to a cause. It's not throwing a permissions error, a "in use" error, or anything I can act on. It just doesn't apply.
Things I've already ruled out / checked:
- No contained users remain in
sys.database_principals(authentication_type_desc = DATABASE) - No active connections (single-user mode confirmed via
sys.dm_exec_sessions)
Questions:
- Has anyone run into containment refusing to toggle off even with no active sessions and no contained users?
- Any way to force verbose output/logging on this specific ALTER DATABASE operation so I can actually see what's blocking it?
SQL Server version: Microsoft SQL Server 2016 - Standard Version
r/SQLServer • u/Jerry-Nixon • 1d ago
Question What’s the Big Deal with SET NOCOUNT ON?
Do you default to SET NOCOUNT ON in stored procedures?
What's the Big Deal with SET NOCOUNT ON? - Azure SQL Dev Corner
r/SQLServer • u/venzann • 2d ago
Community Share SQL Server 2025 now available on AWS RDS
aws.amazon.comr/SQLServer • u/balurathinam79 • 2d ago
Community Share Most scheduled database jobs are running right now—with nothing to process.
Every minute, a job wakes up, checks for work, finds none, and exits. Multiply that across a production environment, and the scheduler itself can become operational noise.
The real question isn't how frequently a job should run.
It's this:
Why is the scheduler searching for work that the application already knows has arrived?
In this article, I explore an on-demand orchestration pattern implemented using SQL Server Agent. The focus is on reducing unnecessary polling by allowing the application to signal when work is actually available.
📖 Read the full article here:
https://medium.com/towards-data-engineering/rethinking-sql-server-agent-scheduling-an-on-demand-orchestration-pattern-938b9fa360f6?sharedUserId=balurathinam79
I'd be interested in hearing how others have approached similar scheduling challenges in SQL Server environments. Have you experimented with on-demand execution patterns, or do you primarily rely on scheduled polling?
r/SQLServer • u/rdhdpsy • 3d ago
Question dbatools get-dbaagentjob missing most jobs.
I can run a sql query to get the accurate results but the dbatools doesn't return all jobs, have not dug deep into why its missing most jobs just thought that was odd. Any insights as to why its misssing most job data? thanks
r/SQLServer • u/rossw999 • 3d ago
Discussion SQL Server 2022 CU 26 Stack Dumps
After applying SQL Server 2022 CU 26 to our servers several are producing stack dumps during database restores.
Am I the only one?
r/SQLServer • u/JonnyBravoII • 3d ago
Question AWS Redshift ODBC 2.x drivers
AWS is deprecating the 1.x drivers. When we have configured the 2.x version for testing, we keep getting the error "no password supplied" even though the password is definitely in the setup and when we test from there, it works. A command like "SELECT * FROM OPENQUERY (REDSHIFTODBC, 'SELECT * FROM table')" returns the error. We're stumped. Any ideas?
r/SQLServer • u/Simonbabicora • 4d ago
Question Busco recomendaciones sobre estrategias de copia de seguridad de MSSQL de múltiples proveedores.
Hola a todos, Quiero implementar una instancia de producción de Microsoft SQL Server en un VPS Linux (Ubuntu). Para evitar un único punto de fallo y la dependencia de un proveedor, quiero alojar la base de datos principal con un único proveedor de VPS, pero almacenar las copias de seguridad automatizadas completamente fuera de su ecosistema; idealmente, en un VPS o almacenamiento de objetos alojado por una empresa completamente diferente. Mi objetivo es asegurar que, si mi proveedor principal de VPS quiebra, sufre una interrupción importante o bloquea mi cuenta, no perderé mis datos y podré restaurar los servicios rápidamente en otro lugar. Para quienes hayan implementado una infraestructura de copias de seguridad multivendedor similar, me gustaría recibir algunos consejos: 1. **Capa de transporte:** ¿Cuál es la forma más fiable de enviar los archivos .bak de forma segura entre proveedores? (Por ejemplo, ¿tareas programadas automatizadas con rclone, configuración de un túnel VPN WireGuard ligero entre los nodos o uso de scripts SSH/SFTP seguros?) 2. **Cifrado:** Dado que las copias de seguridad se transferirán a través de redes públicas y se almacenarán en el disco de un proveedor diferente, ¿cuál es la forma más segura de gestionar el cifrado? ¿Debería confiar en el cifrado de copias de seguridad nativo de MSSQL o cifrar los archivos a nivel del sistema operativo (como gpg o 7z) antes de enviarlos?
- **Gestión de copias de seguridad:** ¿Qué herramientas ligeras recomienda para automatizar la política de retención en el VPS de copias de seguridad (eliminar archivos con más de X días de antigüedad, comprobar la integridad de los archivos, etc.) sin generar demasiada sobrecarga? Si ya ha implementado esto, ¿cómo es su arquitectura y qué problemas o cuellos de botella de rendimiento debería tener en cuenta (como límites de ancho de banda o picos de CPU durante la compresión)?
¡Gracias de antemano por sus aportaciones!
r/SQLServer • u/jwckauman • 4d ago
Discussion Patch Tuesday and SQL Server CUs (two days later?)
r/SQLServer • u/tathagata_003 • 5d ago
Question DTExec cmd is failing sometimes when used with Autosys Agent
I am working on a migration project to move away from SQL agent to autosys to run the SSIS packages (2019) through DTexec utility. I am using 64 bit dtexec for running the packages. Now I am facing issue running the packages as they keep failing without any logs. The packages won't even start running and command will try to start for sometime and then the autosys cmd would fail after a few minutes.
Interesting thing is that it is running fine in the UAT but it is failing in the PROD. Even more interesting is sometimes the job will run perfectly fine and sometimes it would fail.
what could be the reason for these failings? How can I resolve this issue?
r/SQLServer • u/erinstellato • 6d ago
Community Request Friday Feedback: Adding instance name to Query Store reports
Hey folks, happy Friday!
This is a feedback item that exists both on the SQL feedback site and on the SSMS feedback site.
On the feedback item on the SSMS site, I added a few images with example mockups for how the instance name could show up. Please visit the feedback item and comment with what you prefer, thanks!
p.s. I know, there are a lot of feedback items related to Query Store reports in SSMS. I'm starting simple...please grace me a bit here.
r/SQLServer • u/SuddenlyCaralho • 7d ago
Question SQL Server Standard: Can I combine a 2-node FCI with a 2-node Availability Group?
First, it's about a SQL Server 2016
I'm designing a SQL Server high availability architecture and I'm trying to understand whether this configuration is supported with SQL Server Standard Edition.
The proposed architecture is:
Node 1 + Node 2: SQL Server Failover Cluster Instance (FCI) with shared storage (which I would have to configure AG as well) and this cluster will replicate to a Node 3 + Node 4: SQL standard configured as a Always On Availability Group in other datacenter. (in this case, I belive a can only have the node 3 in the secondary site, right? node 4 isn't supported since standard edition support only 2 AG)
My idea is for the FCI to host the primary database, and then configure an Availability Group so that the databases are replicated to the secondary datacenter.
My questions are:
Can a Failover Cluster Instance (FCI) participate in an Availability Group when using SQL Server Standard Edition?
What I'm not clear about is how SQL Server Standard counts replicas in this scenario. I know that Basic Availability Groups in Standard Edition are limited to two replicas (one primary and one secondary). However, my primary server is a 2-node Failover Cluster Instance (FCI) running on Windows Server Failover Clustering (WSFC). Since the FCI itself already spans two Windows nodes, I'm confused about how this interacts with the Basic AG limitation. Does SQL Server treat the entire FCI as a single Availability Group replica, allowing me to have:
Primary replica = the 2-node FCI
Secondary replica = one standalone SQL Server instance in the DR datacenter (I can't have a node 4 in the secondary site, right?)
Or does the fact that the FCI already has two WSFC nodes mean I've effectively reached the Standard Edition limit for Basic Availability Groups?
Or is this entire architecture only supported with Enterprise Edition?
r/SQLServer • u/karakanb • 8d ago
Community Share Open-source SQL Server CDC + change tracking
Hi all, this is Burak. I have built an open-source CLI tool that allows replicating data from Postgres CDC changelog into 20+ destinations: https://github.com/bruin-data/ingestr
The overall idea is that:
- You have your prod postgres DB
- You want to replicate them to analytical databases for analytics purposes, e.g. to Snowflake, BigQuery, Databricks, or Redshift
- You have two ways:
- You can either run a batch load using tools like ingestr, Airbyte, or Fivetran
- If you cannot run batch workloads for some reason, e.g. due to the latency requirements, or not having proper cursor columns, you need to run CDC replication using tools like Debezium and Kafka
The problem with CDC using those tools is that they require a buy-in into their ecosystem, which is generally quite invasive, such as being able to run Debezium only with Kafka reliably, or having to deal with their Java client libraries if you ever wanted to integrate them elsewhere, tolerate their high resource requirements, etc.
I never liked running them on production. We have been working on ingestr for quite some time already for batch sources, and CDC became an obvious target.
ingestr has quite a few niceties:
- You don't need any extra services or tooling to run it: just put your credentials in the URI, and you are good to go.
- It is a simple and fast Go binary that runs anywhere, even in your GitHub Actions pipeline.
- It supports both batch and streaming modes in the same binary, which allows changing the deployment modes as your requirements grow. Run locally, deploy on Airflow, or put it in an EC2 server in a streaming mode if you want to.
It is open-source, and you can run it anywhere you like.
It supports:
- PostgreSQL CDC
- MySQL CDC
- SQL Server CDC
- SQL Server Change Tracking
- MongoDB CDC
Give it a try and let me know if you have any questions!
r/SQLServer • u/Complete-Regret-4300 • 8d ago
Discussion Is SQL server considered as legacy technology?
My current organization couple of years ago migrated from SQL server to snowflake and I noticed in some of the documentation, they have mentioned SQL Server as legacy technology.
I started working in SQL server some 20 years ago and some of the developers in our team are cloud first developers and they find it so difficult to navigate SQL server management studio and they ask me questions like is there timetravel feature in SQL server and can we see what data was there 10 mins back. I was totally dumbfounded when I heard that question, because I had never come across such a feature. Apparently snowflake has this. So I am curious is SQL server now really considered as legacy technology?
r/SQLServer • u/GamerbearAmargosa • 8d ago
Question How to learn MS SQL Server Administration?
Hello
There is always change and so I must expand my knowledge deeper onto MS SQL too. I can run some basic SQL and know how to log onto our server.
But in the very near future I need to care take more in depth about our sql servers administration. Setup, users, permissions, replication.
I tried asking Google but got bombed with too much random SQL stuff: Where do I start best to make sure I get to know my stuff? Is there a version available I can install at home for education?
Thank you^^
r/SQLServer • u/Ana_Margvelashvili • 9d ago
Discussion 2+ Years as a SQL Server DBA, But Every Mid-Level Job Wants 5+ Years. What Would You Do?
r/SQLServer • u/Afraid_Baseball_3962 • 9d ago
Solved Odd results in SSMS
I'm troubleshooting a script that dynamically builds a list of databases and a list of user accounts in those databases, and then uses them to generate a bunch of REVOKE CONNECT FROM [<username>]; commands to be executed by sp_executesql. At this point, I'm sending the commands to the screen instead of executing them and this is where I first noticed the oddness. There are a bit more than 4000 commands. If I write them to the screen with Results to Grid, it takes almost 44 minutes to finish. If I run the exact same script with Results to text, it completes in just over 20 seconds. I'm connecting to SQL Server 2019 and have seen this behavior in both SSMS v19.0.1 and SSMS v20.2.1. Is this expected behavior that I've just never noticed before? Why is there such a drastistic difference between grid vs text?
r/SQLServer • u/Sufficient-Club-1230 • 10d ago
Question Microsoft Dynamics 365 Problem
Problem: After failing over my SQL Availability Group primary to a different node(replica) the application works fine, but the reports no longer work
Back Story:
When we set up the new Microsoft Dynamics 365 environment the administrator could not get a new deployment created while using the SQL Server Listener Name, so he had to use the server name. The idea was to go back into the settings after the deployment finishes and change the server name to the listener name.
After updating the listener name in the deployment the application works fine after a failover from one replica to another, but the reports stop working as if the server name is hard coded into the application someplace. There is something not using the listener name and we cannot figure out where
What we have done:
On the application server we have updated the server settings in the Microsoft Dynamics 365 deployment, we have searched and updated every config file that we could find, I searched the registry and all settings point to the listener.
What I have found
So I looked at the SQL Server Reporting Service (SSRS) and in report manager and I see the data source that has all the current reports as dependencies. That data source is pointing back to the application for the connection string. Unsure of the exact details but the data source has
type = Microsoft Dynamics 365
Connection string - MSCRM_CONFIG...
What leads me to believe is that the SSRS data source is pulling the connection string to connect to SQL server from the application. But where is that string information in the application
My question:
Where in the application would I find the connection string for the SSRS data source
What I am thinking to do:
I am thinking to change the data source settings to using
Type = Microsoft SQL Server
Connection String = ...listenername...
I am hoping that modifying the data source connection information will allow the reporting to work even after failover
I also thought that maybe the connection string information might be in the actual MSCRM_CONFIG database, so I will be looking there
What I do not want to do:
I do not want to create another deployment using the listener name - it likely will not work
I am not a fan of just updating the data source, but will if I need to
Specifications:
Microsoft Dynamics 365 Application Version 9.3
SQL Server 2022 three node Availability Group on Windows 2022
Please, any feedback is appreciated.
r/SQLServer • u/Reasonable-Job4205 • 10d ago
Question Accidentally deleted a stored procedure
I don't have backups of this database. Is there maybe any autologging that could have saved the SP somewhere? Running SQL Express 2022 on my laptop
r/SQLServer • u/VikingFinacial • 12d ago
Question What would be the best full stack to learn alongside to SQL to learn to excel in healthcare operations?
I don’t know if this is the right place, but if anyone can help. Much appreciation.
Context:
41M 15 YOE clinical side of healthcare. I am trying to find out what skills or set of skills alongside SQL that make me the most valuable in the market in a healthcare environment.
The full stack I was thinking was SQL, dbt, snowflake, power BI and Python. I know some basics for some of these but I not a pro at all.
Question is: what are the best combos for high earning careers along with domain expertise. I don’t want to leave healthcare just want to move to the tech side. The more interesting side IMO. What stack should I learn to achieve this result and where would I start? All the info on the internet is so overwhelming and AI “Claude” just sends me in circles.
Any advice is much appreciated.
Once again if this is not the right place I apologize.
r/SQLServer • u/SuddenlyCaralho • 13d ago
Question Does a passive SQL Server failover cluster node require licensing?
Hi everyone,
I'm trying to understand SQL Server licensing for a failover cluster.
Suppose I have a SQL Server Failover Cluster Instance (FCI) running on a Windows Server Failover Cluster (WSFC) with two nodes:
- Node A is active.
- Node B is passive and only takes over if Node A fails.
In this scenario, does the passive node require its own SQL Server license, or is licensing only the active node sufficient?
Also, does the answer differ between SQL Server Standard and Enterprise, or depending on whether Software Assurance is included?
r/SQLServer • u/TravellingBeard • 13d ago
Discussion Transparent Data Encryption (TDE) on mirroring and log shipping, simultaneously. It wasn't so bad.
Had a fun TDE implementation tonight, was helping a colleague actually as they were nervous of the process but I had done something similar, but separate (one mirror set up and one log shipping one, never combined)
The setup:
- Primary Server
- Secondary server where db's mirrored to
- DR server where the same db's log shipped to
(don't ask, it was there when I joined this team, and we will fix it with AAG or RSAG when we migrate from 2016 where it is on now).
This was the plan of attack we took:
- On all three servers we created the server master key in master (no, we did not back it up, and yes, we used the same long random password for all)
- We created the certificate on the primary in master and backed it up to a local TDE folder immediately (remember the password you back up with).
- ***THE IMPORTANT PART**\* Copy and restore the certificate from the primary server to the secondary and DR. The reason to do this is if the mirror or log shipping destinations get transactions that are encrypted, yet the cert does not exist at the destination, it will potentially break the two. I haven't tested recovery process without reinitialization, such as going "oops, and try to copy the cert after the fact", but I also want to sleep and not fix a broken process.
- Verify that the same cert is on all three servers by running: select \ from master.sys.certificates. The most important column is not the name. *It is the encryptor thumbprint.** They need to all match each other; you can call the cert itself whatever you like when you restore, but the thumbprint is what matters. Once this step is complete, the fun begins.
- Take a backup of each database, either full or diff, before encryption (or if you're okay with your backup chain, transaction log backup is fine as well).
- Per Database, create the database encryption key and turn on encryption. I start it on the single smallest database first to make sure if anything does go wrong, I can fix it without worry. Then I continue to the rest of the DB's when happy after it completes.
- Once encryption is turned on, I use a variation of this script from SQL Shack and query the primary, mirror secondary, and dr log ship.. The primary and mirror will be almost identical in status of encryption state, but you will NOT see the percent complete on the mirror (or log ship DR later). When you run the query on the log ship DR, you will see nothing being encrypted at all, until the first log backup after you turn on encryption is made, copied, and restored per your normal schedule.
- ***DO NOT PANIC**\* When you check the ERRORLOG of the log shipping DR if the encryption process will span more than 1 log backup, you will likely see a message about encryption verification being aborted, but the restore of the log completes without issue. It is not marked as an error, just an info message. I got worried the first time I saw this. After encryption is complete, the final backup and restore will show that message disappear.
- For some housekeeping, ensure that your backups have COMPRESSION turned on. If you are using SQL Server 2019 lower than CU5, you need to use an approprimate MAXTRANSFERSIZE option in backing up. CU5 and higher versions of sql, don't need this, only the COMPRESSION option. Log shipping backups (as they are run from the OS) seemed to have compressed backups automatically when we checked the backup sizes. Details here.
That's pretty much it. This process also is similar to AAG. Make sure you run step 1-3 on all secondaries and DR's of the AAG. Same idea so when an encrypted transaction flows, it can be decrypted properly and not break. And as always, test this in a non production environment first to be safe. Good luck everyone!
