How to: Configure a Report Server for Remote Administration
In Reporting Services, you can configure report server instances locally or remotely. To configure a remote report server instance, you can use the Reporting Services Configuration tool or write custom code that uses the Reporting Services Windows Management Instrumentation (WMI) provider. The Reporting Services Configuration tool provides a graphical interface to the WMI provider so that you can configure a report server without having to write code. When you start the tool, you can specify a remote server to connect to.
Before you can use the tool to configure a remote report server, you must follow the instructions in this topic to enable ports in Windows Firewall, enable remote connections, and enable remote WMI requests.
Proper configuration helps you avoid the following error:
The machine could not be found.
"The RPC server is unavailable. (Exception from HRESULT: 0x800706BA)".
Prerequisites
To modify firewall settings, you must be logged on locally and you must be a member of the local Administrators group. You cannot modify the Windows firewall settings of a remote computer over a remote connection.
If you want to enable remote administration for a non-administrator user, you must grant the account Distributed Component Object Model (DCOM) Remote Activation permissions. Instructions for configuring the server for non-administrator access are provided in this topic.
Some organizations have group policies that prevent remote server administration for certain operating systems or users. Before you begin modifying firewall settings, check with your network administrator to verify whether there are restrictions on remote administration.
For more information, see Connecting Through Windows Firewall in the Platform SDK documentation on MSDN.
Tasks
Tasks that enable remote report server configuration include the following:
Enable ports in Windows Firewall to allow requests on ports used by the report server and by the SQL Server Database Engine instance.
Enable remote connections to the instance of the Database Engine instance that hosts the report server database. A remote connection is necessary for configuring the report server database connection and managing the encryption keys.
Enable remote WMI requests to pass through the Microsoft Windows firewall.
If you are configuring a remote report server for administration by a non-administrative user, you must set DCOM permissions to enable remote WMI access to a standard Windows user account. Because WMI uses DCOM as transport for remote calls, you must set the DCOM permissions so that users who are not logged on as the local administrator can configure the server.
If you are configuring a remote report server for administration by a non-administrative user, you must also set WMI permissions on the report server WMI namespace. By default, all members of the local Administrator group have access to the report server WMI namespace. If you want to grant access to non-administrators, you must set permissions.
Instructions on how to perform these tasks are provided in this topic.
To open ports in Windows Firewall
To configure remote connections to the report server database
Click Start, point to Programs, point to Microsoft SQL Server 2008, point to Configuration Tools, and click SQL Server Configuration Manager.
In the left pane, expand SQL Server Network Configuration, and then click Protocols for the instance of SQL Server.
In the details pane, enable the TCP/IP and Named Pipes protocols, and then restart the SQL Server service.
To enable remote administration in Windows Firewall
Log on as a local administrator to the computer for which you want to enable remote administration.
If the report server is running on Windows Vista, right-click Command Prompt and select Run as administrator. For other operating systems, open a command prompt window.
Run the following command:
netsh.exe firewall set service type=REMOTEADMIN mode=ENABLE scope=ALL
You can specify different options for Scope. For more information, see the Windows Firewall product documentation.
Verify that remote administration is enabled. You can run the following command to show the status:
netsh.exe firewall show state
Reboot the computer.
To set DCOM permissions to enable remote WMI access for non-administrators
On the Start menu, point to Administrative Tools, click Component Services.
For Windows Vista, on the Start menu, click All Programs, click Run, and then enter mmc comexp.msc.
Open the Component Services folder.
Open the Computers folder.
Select My Computer.
On the Action menu, and select Properties.
Click COM Security.
In Launch and Activation Permissions, click Edit Limits.
If you do not see your name in Launch Permission, click Add.
Type the name of your user account, and then click OK.
In Permissions for <User or Group>, in the Allow column, select Remote Launch and Remote Activation, and then click OK.
To set permissions on the report server WMI namespace for non-administrators
On the Start menu, point to Administrative Tools, click Computer Management.
Open the Services and Applications folder.
Right-click WMI Control, and select Properties.
Click Security.
Open the Root folder.
Open the Microsoft folder.
Open the SQLServer folder.
Open the ReportServer folder.
Open instance folder. If you installed the default instance, the folder is MSSQLSERVER.
Open the v10 folder.
Select the Admin folder, and then click Security.
Click Add, and then type the user account you will use to manage the server.
In the Allow column, select Enable Account, Remote Enable, and Read Security, and then click OK.