Export (0) Print
Expand All
Expand Minimize

sp_validatelogins (Transact-SQL)


Applies To: SQL Server 2014, SQL Server 2016 Preview

Reports information about Windows users and groups that are mapped to SQL Server principals but no longer exist in the Windows environment.

Applies to: SQL Server (SQL Server 2008 through current version).

Topic link icon Transact-SQL Syntax Conventions


0 (success) or 1 (failure)

Column name

Data type




Windows security identifier (SID) of the Windows user or group.

NT Login 


Name of the Windows user or group.

If the orphaned server-level principal owns a database user, the database user must be removed before the orphaned server principal can be removed. To remove a database user, use DROP USER. If the server-level principal owns securables in the database, ownership of the securables must be transferred or they must be dropped. To transfer ownership of database securables, use ALTER AUTHORIZATION.

To remove mappings to Windows users and groups that no longer exist, use DROP LOGIN.

Requires membership in the sysadmin or securityadmin fixed server role.

The following example displays the Windows users and groups that no longer exist but are still granted access to an instance of SQL Server.

EXEC sp_validatelogins;
Was this page helpful?
(1500 characters remaining)
Thank you for your feedback

Community Additions

© 2015 Microsoft