Configure COM Security

FineBuild can configure COM security to allow access to Integration Services from remote machines.

The COM Security processing in FineBuild is based on the details in

Security Compliance

COM Security configuration helps to secure SSIS access rights. If you setup Security Compliance then COM Security configuration will always be implemented.

FineBuild COM Security configuration

Automated silent COM Security Configuration relates to Process Id 5AA and is controlled by the parameters below:

Parameter Build SQL2005 SQL2008 SQL2008 R2 SQL2012 SQL2014
SetupDCOM FULL Yes Yes Yes Yes Yes
SetupDCOM CLIENT Yes Yes Yes Yes Yes

In order to maintain compatibility with older versions of SQL FineBuild, the parameter ConfigDCOM can also be used.

This process can only be automated for Windows 2008 and above. If you are using Windows 2003 or XP, you must complete the Manual COM Security configuration process below.

Manual COM Security configuration

The following steps show what you would have to do for manual COM Security Configuration. FineBuild does all of this work for you automatically for Windows 2008 and above.

1) Navigate via Settings -> Control Panel -> Administrative Tools to start the Component Services MMC snap-in. Within this panel, navigate to Component Services -> Computers -> My Computer -> DCOM Config, then scroll to the following, right-click and select Properties.

SQL2005 SQL2008 SQL2008R2 SQL2012 SQL2014
MsDtsServer MsDtsServer100 MsDtsServer100 MsDtsServer110 MsDtsServer120

2) Select the Security tab, and within Launch and Activation Permissions, click Edit.
3) The Launch Permission window is displayed. Click on Add.
4) Use the process Find Group on Server with the Group Name Distributed COM Users to configure COM Security.

5) Grant all permissions to the Distributed COM Users group.
6) Click OK until the Properties window is closed, then close the Component Services window.

