SQL Server 2016 SSRS邮件订阅仅域管理员可用,其他用户报错求助
问题描述
- 环境:SQL Server 2016
- 现象:域管理员账号可正常创建SSRS邮件订阅,但其他已配置以下权限的用户创建时失败:
- SSRS安全设置中配置为System Administrator、System User
- 加入SQL Server本地管理员组
- 报错信息:
Failure sending mail: An internal error occurred on the report server. See the error log for more details.Mail will not be resent.
- 日志关键错误:
library!ReportServer_0-1!4390!08/22/2023-00:02:32:: i INFO: Call to GetPermissionsAction(/REPORT1/OTP). User: ACC\LIUT.
library!ReportServer_0-1!4390!08/22/2023-00:02:32:: e ERROR: Throwing Microsoft.ReportingServices.Diagnostics.Utilities.WindowsAuthz5ApiException: , Microsoft.ReportingServices.Diagnostics.Utilities.WindowsAuthz5ApiException: Windows returned a ERROR_ACCESS_DENIED error when Reporting Services attempted to call the Windows Authz APIs. If this issue persists the Reporting Services account may not possess permission to perform authentication checks. Check the Windows Authz documentation for more information and details on diagnosing issues. Authz method: AuthzInitializeContextFromSid, Error code: 5, UserName: ACC\LIUT.;
解决步骤
1. 配置SSRS服务账号的系统权限
- 打开
services.msc,找到SQL Server Reporting Services服务,记录其运行账号 - 打开
secpol.msc(本地安全策略),依次进入本地策略 > 用户权限分配:- 找到作为操作系统的一部分权限,将SSRS服务账号添加至列表
- 验证SSRS服务账号对以下资源的权限:
- SSRS安装目录(默认
C:\Program Files\Microsoft SQL Server\MSRS13.MSSQLSERVER\Reporting Services):授予读取、写入权限 - ReportServer和ReportServerTempDB数据库:确保账号拥有
db_owner或足够的数据库操作权限
- SSRS安装目录(默认
2. 确保服务账号可解析用户SID
- 若为域环境,联系域管理员确认SSRS服务账号具备读取域控制器AD用户属性的权限(需能解析目标用户的SID信息)
- 若为本地用户,确保服务账号对本地用户数据库(
C:\Windows\System32\config\SAM等)拥有读取权限
3. 刷新SSRS服务配置
- 打开Reporting Services配置管理器,进入服务账号选项卡,重新输入服务账号密码并点击应用
- 重启SQL Server Reporting Services服务,使权限变更生效
4. 验证报表级订阅权限
- 登录SSRS门户,找到目标报表
/REPORT1/OTP,点击管理 > 安全 - 确认目标用户(ACC\LIUT)的权限列表中包含管理订阅项,若缺失则添加该权限
内容的提问来源于stack exchange,提问作者Ohannis Dikramanjian

