The groups and accounts that BizTalk Server uses have the minimum user rights they need to perform most tasks. Therefore, there are some tasks where you may need more user rights than the ones BizTalk Server automatically has granted the group to which you belong. The following table describes the Minimum Security User Rights you need to perform tasks in BizTalk Server.
|
Task
|
Groups or Roles
|
|---|
|
Setup
|
|
|
Installation
|
|
|
Configuration
|
-
BizTalk Server Administrators
-
Local Administrators
-
sysadmin SQL Server Role
-
SSO Administrators
-
OLAP Administrator
|
|
Join a BizTalk Server group
|
-
Local Administrators
-
BizTalk Server Administrators
|
|
BizTalk Administration
|
|
|
Create a MessageBox database
|
-
BizTalk Server Administrators
-
sysadmin SQL Server Role
|
|
Create or delete a BizTalk host
|
-
BizTalk Server Administrators
-
db_ddladmin SQL Server Database role on the BizTalk MessageBox databases
|
|
Change the Host Tracking property for a host
|
-
BizTalk Server Administrators
-
db_securityadmin SQL Server Database role on the BAM Primary Import database, BizTalk MessageBox databases, and the BizTalk Tracking database
|
|
Create (install), delete, or change the credentials for a host instance
|
-
BizTalk Server Administrators
-
Local Administrators
-
securityadmin SQL Server Role on the server(s) where the following databases are:
-
BizTalk MessageBox databases, BizTalk Management database, Rule Engine database, BizTalk Tracking database, BAM Primary Import database
-
db_securityadmin SQL Server Database role on the following databases:
-
BizTalk MessageBox databases, BizTalk Management database, Rule Engine database, BizTalk Tracking database, BAM Primary Import database
|
|
Start or stop a host instance
|
-
BizTalk Server Administrators
|
|
Add or remove Server
|
-
BizTalk Server Administrators
-
Local Administrators on the computer you are adding or removing.
|
|
Add or remove a receive handler
|
-
BizTalk Server Administrators
-
SSO Affiliate administrators
|
|
Start or stop applications, orchestrations, send ports, and send port groups
|
|
|
Enable or disable receive locations
|
|
|
Search for artifacts
|
|
|
Add an adapter
|
-
BizTalk Server Administrators
-
SSO Affiliate administrators
|
|
Backup databases
|
-
BTS_BACKUP_USERS role for the databases
-
sysadmin SQL Server role on the SQL Server hosting BizTalk Management database.
Note
You must configure the SQL Server Agent service to run under a domain account or a local account with a mapped user on each instance of SQL Server.
|
|
Configure BizTalk Groups with a certificate
|
-
BizTalk Server Administrators
|
|
All other tasks (including WMI)
|
-
BizTalk Server Administrators
|
|
Operations and Health and Activity Tracking (HAT)
|
|
|
View Group Hub page, perform queries, save and load queries
|
|
|
View query results
|
|
|
General configuration and tracking configuration
|
-
BizTalk Server Administrators (read and write)
-
BizTalk Server Operators (read)
|
|
Browse a health monitoring cube
|
-
BizTalk Server Administrators
|
|
View message properties
|
-
BizTalk Server Administrators
|
|
Save message bodies
|
-
BizTalk Server Administrators
|
|
Use Find Message query
|
-
BizTalk Server Administrators
|
|
Use Query Build
|
-
BizTalk Server Administrators
|
|
Use the orchestration debugger
|
-
BizTalk Server Administrators
|
|
View message flow, message events in HAT
|
|
|
Suspend, terminate, or resume instances
|
|
|
Archiving or purging messages from the Tracking database
|
-
db_owner role on the BizTalk Tracking database
|
|
All other tasks
|
-
BizTalk Server Administrators
|
|
Tracking Profile Editor
|
|
|
Read or write to the BizTalk Management database
|
-
BizTalk Server Administrators
|
|
Event Bus Monitoring MMC
|
|
|
All tasks
|
-
BizTalk Server Administrators
|
|
BizTalk Web Services Publishing Wizard
|
|
|
All tasks
|
|
|
Human Workflow Services
|
|
|
Start/stop Web service using the Human Workflow Services (HWS) Administration console
|
|
|
Activity Model Designer API
|
-
HWS_AM_DESIGNER SQL Server Database role in the BizTalk Management and HWS Administration databases
|
|
All other tasks
|
-
BizTalk Server Administrators
|
|
Business Activity Monitoring
|
|
|
Run BM.exe
|
-
db_owner SQL Server Database role in the BAM Primary Import, BAM Star Schema, and BAM Archive databases
|
|
Run BM.exe, if there is an Analysis Services database
|
-
db_owner SQL Server Database role in the BAM Primary Import, BAM Star Schema, and BAM Archive databases
-
OLAP Administrators in the BAM Analysis Services database
|
|
Create account for BAM View
|
-
db_owner SQL Server Database role in the BAM Primary Import database
-
OLAP Administrators in the BAM Analysis Services database
|
|
Business Activity Services
|
|
|
Perform publishing operations that do not modify BizTalk Server settings
|
|
|
Perform management operations that make changes in BizTalk Server, such as deploying partners and creating and activating agreements
|
|
|
Perform operations that directly affect the operations of BizTalk Server, such as creating a BizTalk Server registration and synchronizing and repairing databases with the Trading Partner Management database
|
-
BizTalk BAS Administrators
|
|
Rule Engine (publishing rules)
|
|
|
Deploy/undeploy policies, manipulate security-related artifacts
|
-
RE_ADMIN_USERS SQL Server Database role in the Rule engine database
|