You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SQL Server无法创建新数据库:域登录变更引发权限问题

Fixing "create database permission denied in database 'master'" for New Domain Accounts

Hey there, let's work through this permission issue you're hitting. Since you're using a brand new domain account after re-joining the company, your old permissions don't carry over to this new identity—here's exactly what you need to do to get back to creating databases:

Step 1: Log in with a Privileged Account

First, you need to access SSMS using an account that has sysadmin-level permissions (like the sa account, or a domain account that was already granted server admin rights before). Without this, you won't be able to modify permissions for your new account.

Step 2: Create/Find Your New Domain Login

  • In SSMS, expand your server → Security → Logins.
  • If your new domain account isn't already listed, right-click "Logins" and select "New Login".
  • On the "General" tab, click "Search", enter your new domain username (format: YourDomain\YourNewUsername), verify the account is correct, and click "OK".

Step 3: Grant the dbcreator Server Role

  • Switch to the Server Roles tab in the login properties window.
  • Check the box next to dbcreator—this role explicitly grants permission to create, alter, and drop databases, which is exactly what you need to fix the error.
  • (Optional: If you need additional server-level permissions, you can check other roles here, but dbcreator is sufficient for your current issue.)
  • Click "OK" to save the changes.

Step 4: Test the Permissions

  • Close your current SSMS session and log back in using your new domain account.
  • Try creating a new database again—you shouldn't see the "permission denied" error anymore.

Why Your Previous Attempts Didn't Work

Quick note on what went wrong earlier:

  • The sa account already has full sysadmin permissions (which includes all dbcreator rights), so adding dbcreator to it didn't help your new account.
  • The BuiltInUsers local group doesn't automatically include your new domain account, so modifying that group's permissions didn't apply to you. The fix needs to target your specific new domain login directly.

If you don't have access to a privileged account to make these changes, reach out to your IT team or the server administrator—they'll be able to grant the necessary permissions for your new domain user.

内容的提问来源于stack exchange,提问作者Mark Tait

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 10:37:38