Failure to install Database Enginee Service for SQL Server Standard 2012 on Windows 10

Mabel Te 21 Reputation points
2020-09-01T08:42:54.067+00:00

I have problem in getting Database Engine Services installed for SQL Standard 2012 on Window 10. Have google and tried many ways, but encounter many different error.
I am writing this post after 2 weeks of research.... appreciate all help

  1. Complete uninstall and fresh install again (that means remove program from Control Panel, delete regedit related to SQL Server 2012, delete all Microsoft SQL folder)
  2. Install SQL Standard 2012 SP1, SP2, SP3, SP4, setting server configuration for SQL Server Database Engine to NT Service\System
  3. Install 2018 to ensure a instance can be created. But when I installed 2012, encounter error "The service did not respond to the start or control request in a timely fashion" (I then tried to add DWORD - ServicesPipeTimeout to set as 180000
  4. Install SQL 2012 Cumulative Update 3 and .Net 3.5 SP1
  5. Install via command Setup.exe /ConfigurationFile= ConfigurationFile.ini

I just did another fresh install again (uninstall and install with regedit clear and SQL folder deleted) to prepare for any help. Following is what I have installed

  • Under Apps & features, I have the following SQL version installed
  • Microsoft SQL Server 2008 R2 (64 bit)
  • Microsoft SQL Server 2012 (64 bits) with SP 1 to 4 installed
  • .Net version 3.5 with SP1
  • Windows Update has all the latest update i.e. "Check for update" has no outstanding program

Please advise. Thanks

Windows for business Windows Client for IT Pros Devices and deployment Set up, install, or upgrade
SQL Server Other
{count} votes

Accepted answer
  1. Erland Sommarskog 121.4K Reputation points MVP Volunteer Moderator
    2020-09-04T09:48:42.38+00:00

    I'm leaning towards that Avecto Defendpoint Service (which is what appears to have produced that event log message) decided that it was not approriate to start SQL Server 2012. Maybe it needs to be white-listed?

    I think you need to talk with your internal IT folks at NCS to get this sorted out.

    1 person found this answer helpful.
    0 comments No comments

13 additional answers

Sort by: Most helpful
  1. Mabel Te 21 Reputation points
    2020-09-03T13:53:35.377+00:00

    Hi All, I have start all over again.
    Upon installed SQL 2008, MSSQLSERVER instance is created
    Next, I installed SQL Standard 2012 and it fails again "Could not find the Database Engine startup handle"

    Overall summary:
    Final result: Failed: see details below
    Exit code (Decimal): -2061893608
    Start time: 2020-09-03 21:31:20
    End time: 2020-09-03 21:48:54
    Requested action: Install

    Setup completed with required actions for features.
    Troubleshooting information for those features:
    Next step for SQLEngine: Use the following information to resolve the error, uninstall this feature, and then run the setup process again.

    Machine Properties:
    Machine name: NCS-270720DN02
    Machine processor count: 8
    OS version: Future Windows Version
    OS service pack:
    OS region: United States
    OS language: English (United States)
    OS architecture: x64
    Process architecture: 64 Bit
    OS clustered: No

    Product features discovered:
    Product Instance Instance ID Feature Language Edition Version Clustered
    SQL Server 2008 R2 MSSQLSERVER MSSQL10_50.MSSQLSERVER Database Engine Services 1033 Standard Edition 10.50.1600.1 No
    SQL Server 2008 R2 Client Tools Connectivity 1033 10.50.1600.1 No

    Package properties:
    Description: Microsoft SQL Server 2012
    ProductName: SQL Server 2012
    Type: RTM
    Version: 11
    SPLevel: 0
    Installation location: e:\x64\setup\
    Installation edition: Standard

    Product Update Status:
    User selected not to include product updates.

    User Input Settings:
    ACTION: Install
    ADDCURRENTUSERASSQLADMIN: false
    AGTSVCACCOUNT: NT AUTHORITY\SYSTEM
    AGTSVCPASSWORD: *****
    AGTSVCSTARTUPTYPE: Manual
    ASBACKUPDIR: Backup
    ASCOLLATION: Latin1_General_CI_AS
    ASCONFIGDIR: Config
    ASDATADIR: Data
    ASLOGDIR: Log
    ASPROVIDERMSOLAP: 1
    ASSERVERMODE: MULTIDIMENSIONAL
    ASSVCACCOUNT: <empty>
    ASSVCPASSWORD: <empty>
    ASSVCSTARTUPTYPE: Automatic
    ASSYSADMINACCOUNTS: <empty>
    ASTEMPDIR: Temp
    BROWSERSVCSTARTUPTYPE: Automatic
    CLTCTLRNAME: <empty>
    CLTRESULTDIR: <empty>
    CLTSTARTUPTYPE: 0
    CLTSVCACCOUNT: <empty>
    CLTSVCPASSWORD: <empty>
    CLTWORKINGDIR: <empty>
    COMMFABRICENCRYPTION: 0
    COMMFABRICNETWORKLEVEL: 0
    COMMFABRICPORT: 0
    CONFIGURATIONFILE: C:\Program Files\Microsoft SQL Server\110\Setup Bootstrap\Log\20200903_212833\ConfigurationFile.ini
    CTLRSTARTUPTYPE: 0
    CTLRSVCACCOUNT: <empty>
    CTLRSVCPASSWORD: <empty>
    CTLRUSERS: <empty>
    ENABLERANU: false
    ENU: true
    ERRORREPORTING: false
    FEATURES: SQLENGINE, CONN, SNAC_SDK
    FILESTREAMLEVEL: 0
    FILESTREAMSHARENAME: <empty>
    FTSVCACCOUNT: <empty>
    FTSVCPASSWORD: <empty>
    HELP: false
    INDICATEPROGRESS: false
    INSTALLSHAREDDIR: C:\Program Files\Microsoft SQL Server\
    INSTALLSHAREDWOWDIR: C:\Program Files (x86)\Microsoft SQL Server\
    INSTALLSQLDATADIR: <empty>
    INSTANCEDIR: C:\Program Files\Microsoft SQL Server\
    INSTANCEID: MSSQL2012
    INSTANCENAME: MSSQL2012
    ISSVCACCOUNT: NT AUTHORITY\Network Service
    ISSVCPASSWORD: <empty>
    ISSVCSTARTUPTYPE: Automatic
    MATRIXCMBRICKCOMMPORT: 0
    MATRIXCMSERVERNAME: <empty>
    MATRIXNAME: <empty>
    NPENABLED: 0
    PID: *****
    QUIET: false
    QUIETSIMPLE: false
    ROLE: <empty>
    RSINSTALLMODE: DefaultNativeMode
    RSSHPINSTALLMODE: DefaultSharePointMode
    RSSVCACCOUNT: <empty>
    RSSVCPASSWORD: <empty>
    RSSVCSTARTUPTYPE: Automatic
    SAPWD: <empty>
    SECURITYMODE: <empty>
    SQLBACKUPDIR: <empty>
    SQLCOLLATION: SQL_Latin1_General_CP1_CI_AS
    SQLSVCACCOUNT: NT AUTHORITY\SYSTEM
    SQLSVCPASSWORD: *****
    SQLSVCSTARTUPTYPE: Automatic
    SQLSYSADMINACCOUNTS: NCS\P0102881
    SQLTEMPDBDIR: <empty>
    SQLTEMPDBLOGDIR: <empty>
    SQLUSERDBDIR: <empty>
    SQLUSERDBLOGDIR: <empty>
    SQMREPORTING: false
    TCPENABLED: 1
    UIMODE: Normal
    UpdateEnabled: false
    UpdateSource: MU
    X86: false

    Configuration file: C:\Program Files\Microsoft SQL Server\110\Setup Bootstrap\Log\20200903_212833\ConfigurationFile.ini

    Detailed results:
    Feature: Client Tools Connectivity
    Status: Passed

    Feature: Database Engine Services
    Status: Failed: see logs for details
    Reason for failure: An error occurred during the setup process of the feature.
    Next Step: Use the following information to resolve the error, uninstall this feature, and then run the setup process again.
    Component name: SQL Server Database Engine Services Instance Features
    Component error code: 0x851A0018
    Error description: Could not find the Database Engine startup handle.
    Error help link: http://go.microsoft.com/fwlink?LinkId=20476&ProdName=Microsoft+SQL+Server&EvtSrc=setup.rll&EvtID=50000&ProdVer=11.0.2100.60&EvtType=0xD15B4EB2%400x4BDAF9BA%401306%4024&EvtType=0xD15B4EB2%400x4BDAF9BA%401306%4024

    Feature: SQL Browser
    Status: Passed

    Feature: SQL Writer
    Status: Passed

    Feature: SQL Client Connectivity
    Status: Passed

    Feature: SQL Client Connectivity SDK
    Status: Passed

    Rules with failures:

    Global rules:

    Scenario specific rules:

    Rules report file: C:\Program Files\Microsoft SQL Server\110\Setup Bootstrap\Log\20200903_212833\SystemConfigurationCheck_Report.htm


  2. Mabel Te 21 Reputation points
    2020-09-03T14:01:11.007+00:00

    There is no file in the directory: C:\Program Files\Microsoft SQL Server\MSSQL11.MSSQL2012\MSSQL\Log

    However there is ERRORLOG under the directory: C:\Program Files\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Log

    2020-09-03 21:25:18.55 Server Microsoft SQL Server 2008 R2 (RTM) - 10.50.1600.1 (X64)
    Apr 2 2010 15:48:46
    Copyright (c) Microsoft Corporation
    Standard Edition (64-bit) on Windows NT 6.2 <X64> (Build 9200: )

    2020-09-03 21:25:18.55 Server (c) Microsoft Corporation.
    2020-09-03 21:25:18.55 Server All rights reserved.
    2020-09-03 21:25:18.55 Server Server process ID is 3928.
    2020-09-03 21:25:18.55 Server System Manufacturer: 'HP', System Model: 'HP ProBook 430 G5'.
    2020-09-03 21:25:18.55 Server Authentication mode is WINDOWS-ONLY.
    2020-09-03 21:25:18.55 Server Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Log\ERRORLOG'.
    2020-09-03 21:25:18.55 Server This instance of SQL Server last reported using a process ID of 4204 at 9/3/2020 9:24:33 PM (local) 9/3/2020 1:24:33 PM (UTC). This is an informational message only; no user action is required.
    2020-09-03 21:25:18.55 Server Registry startup parameters:
    -d C:\Program Files\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\DATA\master.mdf
    -e C:\Program Files\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Log\ERRORLOG
    -l C:\Program Files\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\DATA\mastlog.ldf
    2020-09-03 21:25:18.56 Server SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
    2020-09-03 21:25:18.56 Server Detected 8 CPUs. This is an informational message; no user action is required.
    2020-09-03 21:25:18.77 Server Using dynamic lock allocation. Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node. This is an informational message only. No user action is required.
    2020-09-03 21:25:18.82 Server Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
    2020-09-03 21:25:18.87 spid6s Starting up database 'master'.
    2020-09-03 21:25:18.89 spid6s Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
    2020-09-03 21:25:18.91 spid6s FILESTREAM: effective level = 0, configured level = 0, file system access share name = 'MSSQLSERVER'.
    2020-09-03 21:25:18.94 spid6s SQL Trace ID 1 was started by login "sa".
    2020-09-03 21:25:18.94 spid6s Starting up database 'mssqlsystemresource'.
    2020-09-03 21:25:18.95 spid6s The resource database build version is 10.50.1600. This is an informational message only. No user action is required.
    2020-09-03 21:25:18.97 spid10s Starting up database 'model'.
    2020-09-03 21:25:18.97 spid6s Server name is 'NCS-270720DN02'. This is an informational message only. No user action is required.
    2020-09-03 21:25:18.97 spid6s Informational: No full-text supported languages found.
    2020-09-03 21:25:18.97 spid6s Starting up database 'msdb'.
    2020-09-03 21:25:18.99 spid10s Clearing tempdb database.
    2020-09-03 21:25:19.02 spid10s Starting up database 'tempdb'.
    2020-09-03 21:25:19.02 Server A self-generated certificate was successfully loaded for encryption.
    2020-09-03 21:25:19.03 Server Server is listening on [ 'any' <ipv6> 1433].
    2020-09-03 21:25:19.03 Server Server is listening on [ 'any' <ipv4> 1433].
    2020-09-03 21:25:19.03 Server Server local connection provider is ready to accept connection on [ \.\pipe\SQLLocal\MSSQLSERVER ].
    2020-09-03 21:25:19.03 Server Server local connection provider is ready to accept connection on [ \.\pipe\sql\query ].
    2020-09-03 21:25:19.03 Server Server is listening on [ ::1 <ipv6> 1434].
    2020-09-03 21:25:19.03 Server Server is listening on [ 127.0.0.1 <ipv4> 1434].
    2020-09-03 21:25:19.03 Server Dedicated admin connection support was established for listening locally on port 1434.
    2020-09-03 21:25:19.03 Server The SQL Server Network Interface library could not register the Service Principal Name (SPN) for the SQL Server service. Error: 0x54b, state: 3. Failure to register an SPN may cause integrated authentication to fall back to NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies.
    2020-09-03 21:25:19.03 Server SQL Server is now ready for client connections. This is an informational message; no user action is required.
    2020-09-03 21:25:19.04 spid13s The Service Broker protocol transport is disabled or not configured.
    2020-09-03 21:25:19.04 spid13s The Database Mirroring protocol transport is disabled or not configured.
    2020-09-03 21:25:19.05 spid13s Service Broker manager has started.
    2020-09-03 21:25:19.05 spid6s Recovery is complete. This is an informational message only. No user action is required.
    2020-09-03 21:26:29.62 spid1s A significant part of sql server process memory has been paged out. This may result in a performance degradation. Duration: 0 seconds. Working set (KB): 63420, committed (KB): 128216, memory utilization: 49%.
    2020-09-03 21:32:01.99 spid1s A significant part of sql server process memory has been paged out. This may result in a performance degradation. Duration: 332 seconds. Working set (KB): 63368, committed (KB): 128144, memory utilization: 49%.
    2020-09-03 21:36:33.60 spid1s A significant part of sql server process memory has been paged out. This may result in a performance degradation. Duration: 603 seconds. Working set (KB): 63396, committed (KB): 128144, memory utilization: 49%.
    2020-09-03 21:41:59.66 spid1s A significant part of sql server process memory has been paged out. This may result in a performance degradation. Duration: 930 seconds. Working set (KB): 63520, committed (KB): 128144, memory utilization: 49%.
    2020-09-03 21:46:31.11 spid1s A significant part of sql server process memory has been paged out. This may result in a performance degradation. Duration: 1201 seconds. Working set (KB): 63232, committed (KB): 128144, memory utilization: 49%.
    2020-09-03 21:51:57.39 spid1s A significant part of sql server process memory has been paged out. This may result in a performance degradation. Duration: 1527 seconds. Working set (KB): 63596, committed (KB): 128144, memory utilization: 49%.
    2020-09-03 21:57:29.39 spid1s A significant part of sql server process memory has been paged out. This may result in a performance degradation. Duration: 1859 seconds. Working set (KB): 63624, committed (KB): 128144, memory utilization: 49%.

    0 comments No comments

  3. Mabel Te 21 Reputation points
    2020-09-03T15:36:08.337+00:00

    Hi Shashank,
    There is no application logs in the Event Viewer
    The followings are the 2 System Logs from Event Viewer

    • System
      • Provider
      [ Name] Service Control Manager
      [ Guid] {555908d1-a6d7-4695-8e1e-26931d2012f4}
      [ EventSourceName] Service Control Manager
      • EventID 7009
      [ Qualifiers] 49152 Version 0 Level 2 Task 0 Opcode 0 Keywords 0x8080000000000000
      • TimeCreated
      [ SystemTime] 2020-09-03T15:19:50.006357600Z EventRecordID 27937 Correlation
      • Execution
      [ ProcessID] 964
      [ ThreadID] 9788 Channel System Computer NCS-270720DN02.ncs.corp.int-ads Security
    • EventData param1 180000
      param2 SQL Server (MSSQL2012)
      4D005300530051004C0024004D005300530051004C0032003000310032000000

    Binary data:

    In Words

    0000: 0053004D 00510053 0024004C 0053004D
    0010: 00510053 0032004C 00310030 00000032

    In Bytes

    0000: 4D 00 53 00 53 00 51 00 M.S.S.Q.
    0008: 4C 00 24 00 4D 00 53 00 L.$.M.S.
    0010: 53 00 51 00 4C 00 32 00 S.Q.L.2.
    0018: 30 00 31 00 32 00 00 00 0.1.2...


    • System
      • Provider
      [ Name] Service Control Manager
      [ Guid] {555908d1-a6d7-4695-8e1e-26931d2012f4}
      [ EventSourceName] Service Control Manager
      • EventID 7000
      [ Qualifiers] 49152 Version 0 Level 2 Task 0 Opcode 0 Keywords 0x8080000000000000
      • TimeCreated
      [ SystemTime] 2020-09-03T15:19:50.006357600Z EventRecordID 27938 Correlation
      • Execution
      [ ProcessID] 964
      [ ThreadID] 9788 Channel System Computer NCS-270720DN02.ncs.corp.int-ads Security
    • EventData param1 SQL Server (MSSQL2012)
      param2 %%1053
      4D005300530051004C0024004D005300530051004C0032003000310032000000

    Binary data:

    In Words

    0000: 0053004D 00510053 0024004C 0053004D
    0010: 00510053 0032004C 00310030 00000032

    In Bytes

    0000: 4D 00 53 00 53 00 51 00 M.S.S.Q.
    0008: 4C 00 24 00 4D 00 53 00 L.$.M.S.
    0010: 53 00 51 00 4C 00 32 00 S.Q.L.2.
    0018: 30 00 31 00 32 00 00 00 0.1.2...


  4. Mabel Te 21 Reputation points
    2020-09-04T00:41:10.957+00:00

    There is no output and I still cannot find anything under the log directory: C:\Program Files\Microsoft SQL Server\MSSQL11.MSSQL2012\MSSQL\Log

    This time when I go Event Viewer, I see a application log

    Log Name: Application
    Source: Avecto Defendpoint Service
    Date: 9/4/2020 8:35:15 AM
    Event ID: 101
    Task Category: None
    Level: Information
    Keywords: Classic
    User: NCS\P0102881
    Computer: NCS-270720DN02.ncs.corp.int-ads
    Description:
    Process started from shell menu with admin rights added to token.

    Command Line: sqlservr -s SQL2012
    Process Id: 16984
    Parent Process Id: 12892
    Workstyle: Lob Medium Flexibility
    Application Group: (Recommended) Restricted Functions (On-Demand)
    Reason: <None>
    File Name: c:\program files\microsoft sql server\mssql11.mssql2012\mssql\binn\sqlservr.exe
    Hash: 89022F5B02DE51BFF5FEDBA4184501B4A21F23EC
    Certificate: Microsoft Corporation
    Description: SQL Server Windows NT - 64 Bit
    Application Type: exe
    Product Name: Microsoft SQL Server
    Product Code: <None>
    Upgrade Code: <None>
    Product Version: 11.0.2100.60
    File Version: 2011.0110.2100.060 ((SQL11_RTM).120210-1917 )
    Application Group Description: OS functions that could be used maliciously so are controlled when executing On-Demand
    Workstyle Description: Line of Business (LoB) Workstyle that applies to users who need some flexibility
    Token Assignment Id: e932d729-42ef-4ec7-af6e-b73051e6f172
    Token Assignment Is Shell: true
    Token Id: f30a3824-27af-4d69-9125-c78e44764ac1
    Message Id: be92c58a-dc1c-482b-9ded-c02b95273f54
    Token: Add Admin Rights
    Token Description: <None>
    Message Name: Allow Message (Yes / No & Authentication)
    Message Description: Simple confirmation before elevating privileges with Authentication
    Unique Process ID: 4481d802-e3fd-42b2-af2e-cb3f8feae99f
    Workstyle ID: da40f6e8-5f51-4f79-8db4-6084f30f6936
    Application Group ID: 55d10fa7-0955-4950-8ae0-1e9a084117be
    User SID: S-1-5-21-128803295-326981143-357459296-298394
    User Name: P0102881
    User Domain SID: S-1-5-21-128803295-326981143-357459296
    User Domain Name: NCS
    User Domain Name NetBIOS: NCS
    Host SID: <None>
    Host Name: NCS-270720DN02
    Host Name NetBIOS: NCS-270720DN02
    Host Domain SID: S-1-5-21-128803295-326981143-357459296
    Host Domain Name: ncs.corp.int-ads
    Host Domain Name NetBIOS: NCS
    Event ID: F5E8C5FD-EC97-469A-A32E-1A4286FC18BE
    Process Start Time: 132436533153292032
    Process End Time: 0
    Event Time: 132436533153292032
    Authorizing User SID: <None>
    Authorizing User Name: <None>
    Authorizing User Domain SID: <None>
    Authorizing User Domain Name: <None>
    Authorizing User Domain Name NetBios: <None>
    Client IPV4: <None>
    Client Name: <None>
    UAC Triggered: false
    File Owner SID: S-1-5-18
    File Owner Name: SYSTEM
    File Owner Domain SID: S-1-5
    File Owner Domain Name: NT AUTHORITY
    File Owner Domain Name NetBIOS: NT AUTHORITY
    Parent Process Unique ID: 64059b36-4ba6-4f84-b7bb-941cda277757
    Parent Process File Name: c:\windows\system32\cmd.exe
    COM CLSID: <None>
    COM AppID: <None>
    COM Display Name: <None>
    Source URL: <None>
    Authorization Challenge: <None>
    Windows Store App Name: <None>
    Windows Store App Publisher: <None>
    Windows Store App Version: <None>
    Drive Type: Fixed Disk
    Challenge Response Status: <None>
    PowerShell Command: <None>
    Application Workstyle Description: Windows Command Processor
    Application Workstyle Id: ceccc155-3499-4343-b59a-f9865b67383b
    Message Type: Prompt
    IE Zone Tag: <None>
    MD5: 3AE13C9869B7CE1135BCF21C0AAA68ED
    Host Local SID: S-1-5-21-3906383662-37666300-1607268661
    Trusted Application Name: <None>
    Trusted Application Version: <None>
    Uninstall Action: <None>
    Rule Script File Name: <None>
    Rule Script Name: <None>
    Rule Script Version: <None>
    Rule Script Publisher: <None>
    Rule Script Rule Affected: false
    Rule Script Result: <None>
    Rule Script Output: <None>
    Rule Script Status: <None>

    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Avecto Defendpoint Service" />
    <EventID Qualifiers="0">101</EventID>
    <Level>0</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2020-09-04T00:35:15.713851700Z" />
    <EventRecordID>295341</EventRecordID>
    <Channel>Application</Channel>
    <Computer>NCS-270720DN02.ncs.corp.int-ads</Computer>
    <Security UserID="S-1-5-21-128803295-326981143-357459296-298394" />
    </System>
    <EventData>
    <Data>sqlservr -s SQL2012</Data>
    <Data>16984</Data>
    <Data>12892</Data>
    <Data>Lob Medium Flexibility</Data>
    <Data>(Recommended) Restricted Functions (On-Demand)</Data>
    <Data><None></Data>
    <Data><None></Data>
    <Data>c:\program files\microsoft sql server\mssql11.mssql2012\mssql\binn\sqlservr.exe</Data>
    <Data>89022F5B02DE51BFF5FEDBA4184501B4A21F23EC</Data>
    <Data>Microsoft Corporation</Data>
    <Data>SQL Server Windows NT - 64 Bit</Data>
    <Data>exe</Data>
    <Data>Microsoft SQL Server</Data>
    <Data><None></Data>
    <Data><None></Data>
    <Data>11.0.2100.60</Data>
    <Data>2011.0110.2100.060 ((SQL11_RTM).120210-1917 )</Data>
    <Data>OS functions that could be used maliciously so are controlled when executing On-Demand</Data>
    <Data>Line of Business (LoB) Workstyle that applies to users who need some flexibility</Data>
    <Data>e932d729-42ef-4ec7-af6e-b73051e6f172</Data>
    <Data>true</Data>
    <Data>f30a3824-27af-4d69-9125-c78e44764ac1</Data>
    <Data>be92c58a-dc1c-482b-9ded-c02b95273f54</Data>
    <Data>Add Admin Rights</Data>
    <Data><None></Data>
    <Data>Allow Message (Yes / No & Authentication)</Data>
    <Data>Simple confirmation before elevating privileges with Authentication</Data>
    <Data>4481d802-e3fd-42b2-af2e-cb3f8feae99f</Data>
    <Data>da40f6e8-5f51-4f79-8db4-6084f30f6936</Data>
    <Data>55d10fa7-0955-4950-8ae0-1e9a084117be</Data>
    <Data>S-1-5-21-128803295-326981143-357459296-298394</Data>
    <Data>P0102881</Data>
    <Data>S-1-5-21-128803295-326981143-357459296</Data>
    <Data>NCS</Data>
    <Data>NCS</Data>
    <Data><None></Data>
    <Data>NCS-270720DN02</Data>
    <Data>NCS-270720DN02</Data>
    <Data>S-1-5-21-128803295-326981143-357459296</Data>
    <Data>ncs.corp.int-ads</Data>
    <Data>NCS</Data>
    <Data>F5E8C5FD-EC97-469A-A32E-1A4286FC18BE</Data>
    <Data>132436533153292032</Data>
    <Data>0</Data>
    <Data>132436533153292032</Data>
    <Data><None></Data>
    <Data><None></Data>
    <Data><None></Data>
    <Data><None></Data>
    <Data><None></Data>
    <Data><None></Data>
    <Data><None></Data>
    <Data>false</Data>
    <Data>S-1-5-18</Data>
    <Data>SYSTEM</Data>
    <Data>S-1-5</Data>
    <Data>NT AUTHORITY</Data>
    <Data>NT AUTHORITY</Data>
    <Data>64059b36-4ba6-4f84-b7bb-941cda277757</Data>
    <Data>c:\windows\system32\cmd.exe</Data>
    <Data><None></Data>
    <Data><None></Data>
    <Data><None></Data>
    <Data><None></Data>
    <Data><None></Data>
    <Data><None></Data>
    <Data><None></Data>
    <Data><None></Data>
    <Data><None></Data>
    <Data>Fixed Disk</Data>
    <Data><None></Data>
    <Data><None></Data>
    <Data>Windows Command Processor</Data>
    <Data>ceccc155-3499-4343-b59a-f9865b67383b</Data>
    <Data><None></Data>
    <Data><None></Data>
    <Data><None></Data>
    <Data><None></Data>
    <Data><None></Data>
    <Data>Prompt</Data>
    <Data><None></Data>
    <Data><None></Data>
    <Data>3AE13C9869B7CE1135BCF21C0AAA68ED</Data>
    <Data>S-1-5-21-3906383662-37666300-1607268661</Data>
    <Data><None></Data>
    <Data><None></Data>
    <Data><None></Data>
    <Data><None></Data>
    <Data><None></Data>
    <Data><None></Data>
    <Data><None></Data>
    <Data>false</Data>
    <Data><None></Data>
    <Data><None></Data>
    <Data><None></Data>
    </EventData>
    </Event>

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.