Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions private/functions/Get-DecryptedObject.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,12 @@ function Get-DecryptedObject {
This is necessary because SQL Server does not allow retrieval of plaintext passwords for security reasons.
By leveraging the service master key and the encryption mechanism used by SQL Server, this function can extract the actual passwords for credentials and linked servers.

Two connections to the instance are needed and both are established from the machine running the command:
- The dedicated admin connection (DAC) passed in as SqlInstance, needed to read master.sys.syslnklgns and sys.sysobjvalues. Callers open it with Connect-DbaInstance -DedicatedAdminConnection, which uses ADMIN:localhost for a local instance and a remote DAC otherwise. Only the remote case needs remote admin connections enabled and the DAC port reachable.
- Access to the Windows host, needed to unprotect the service master key with the entropy stored in the registry. Invoke-Command2 uses PowerShell remoting for a remote host and runs the script block locally otherwise.

Up to dbatools 2.7 this function opened a local DAC itself from inside the PowerShell remoting session, which did not need remote admin connections. That was removed in #10174 so that one DAC can be opened early and shared across all commands that need it, because SQL Server only allows one DAC per instance.

This function is used by the following public functions:
- Copy-DbaCredential
- Copy-DbaDbMail
Expand Down
16 changes: 12 additions & 4 deletions public/Copy-DbaCredential.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -8,15 +8,23 @@ function Copy-DbaCredential {

This is essential for server migrations, disaster recovery setup, or environment synchronization where you need to move service accounts, proxy credentials, or linked server authentication without having to reset passwords or contact application teams for credentials.

The function requires sysadmin privileges on both servers, Windows administrator access, and DAC enabled on the source instance. It supports filtering by credential name or identity and can handle cryptographic provider credentials used for Extensible Key Management (EKM).
It supports filtering by credential name or identity and can handle cryptographic provider credentials used for Extensible Key Management (EKM).

Decrypting the stored passwords requires sysadmin privileges on both servers, DAC access to the source instance and Windows administrator access to the source host. On SQL Server Express, the DAC is not available unless the instance is started with trace flag 7806.

The command opens or reuses the dedicated admin connection (DAC) from the machine it runs on. When that machine is different from the source host, enable remote admin connections on the source instance (Set-DbaSpConfigure -SqlInstance <source instance> -Name RemoteDacConnectionsEnabled -Value 1) and make the DAC TCP listener reachable from that machine. SQL Server listens for the DAC on TCP port 1434 when that port is available; otherwise it assigns a port during startup. Check the SQL Server error log for the active DAC port.

The service master key is read and unprotected on the source Windows host. When the source host is remote, this uses PowerShell remoting. When the command runs directly on the source host, everything runs locally, so remote admin connections and PowerShell remoting are not required.

Use -ExcludePassword to skip password decryption entirely; no DAC is opened and the Windows host is not accessed then.

Credit: Based on password decryption techniques by Antti Rantasaari (NetSPI, 2014)
https://blog.netspi.com/decrypting-mssql-database-link-server-passwords/

.PARAMETER Source
Source SQL Server. You must have sysadmin access and server version must be SQL Server version 2005 or higher.

You must be able to open a dedicated admin connection (DAC) to the source SQL Server.
Unless -ExcludePassword is used, you must be able to open a dedicated admin connection (DAC) to the source SQL Server from the machine you run this command on.

.PARAMETER SourceSqlCredential
Login to the target instance using alternative credentials. Accepts PowerShell credentials (Get-Credential).
Expand Down Expand Up @@ -61,6 +69,7 @@ function Copy-DbaCredential {
.PARAMETER ExcludePassword
Copies credential definitions without the actual password values.
Use this in security-conscious environments where password decryption is restricted or when passwords should be manually reset after migration.
Also use it when the dedicated admin connection or PowerShell remoting described above is not available, because the copy then needs neither.

.PARAMETER Force
Overwrites existing credentials on the destination server by dropping and recreating them with the source values.
Expand All @@ -87,9 +96,8 @@ function Copy-DbaCredential {

Requires:
- PowerShell Version 3.0
- Administrator access on Windows
- sysadmin access on SQL Server.
- DAC access enabled for local (default)
- unless -ExcludePassword is used: DAC access to the source instance, and Windows administrator access on the source host

.OUTPUTS
PSCustomObject (MigrationObject type)
Expand Down
11 changes: 10 additions & 1 deletion public/Copy-DbaDbMail.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,14 @@ function Copy-DbaDbMail {

The function preserves all SMTP authentication details including encrypted passwords, handles name conflicts with optional force replacement, and can enable Database Mail on the destination if it's enabled on the source. You can migrate specific component types or the entire configuration in one operation.

Decrypting the stored passwords requires DAC access to the source instance and Windows administrator access to the source host. On SQL Server Express, the DAC is not available unless the instance is started with trace flag 7806.

The command opens or reuses the dedicated admin connection (DAC) from the machine it runs on. When that machine is different from the source host, enable remote admin connections on the source instance (Set-DbaSpConfigure -SqlInstance <source instance> -Name RemoteDacConnectionsEnabled -Value 1) and make the DAC TCP listener reachable from that machine. SQL Server listens for the DAC on TCP port 1434 when that port is available; otherwise it assigns a port during startup. Check the SQL Server error log for the active DAC port.

The service master key is read and unprotected on the source Windows host. When the source host is remote, this uses PowerShell remoting. When the command runs directly on the source host, everything runs locally, so remote admin connections and PowerShell remoting are not required.

Use -ExcludePassword to skip password decryption entirely; no DAC is opened and the Windows host is not accessed then.

.PARAMETER Source
Specifies the source SQL Server instance containing the Database Mail configuration to copy. The function reads all mail profiles, accounts, mail servers, and configuration values from this instance.
You must have sysadmin privileges to access the MSDB database where Database Mail settings are stored.
Expand Down Expand Up @@ -44,6 +52,7 @@ function Copy-DbaDbMail {
.PARAMETER ExcludePassword
Copies credential definitions without the actual password values.
Use this in security-conscious environments where password decryption is restricted or when passwords should be manually reset after migration.
Also use it when the dedicated admin connection or PowerShell remoting described above is not available, because the copy then needs neither.

.PARAMETER WhatIf
If this switch is enabled, no actions are performed but informational messages will be displayed that explain what would happen if the command were to run.
Expand All @@ -68,7 +77,7 @@ function Copy-DbaDbMail {
Copyright: (c) 2018 by dbatools, licensed under MIT
License: MIT https://opensource.org/licenses/MIT

Requires: sysadmin access on SQL Servers
Requires: sysadmin access on SQL Servers, and unless -ExcludePassword is used DAC access to the source instance plus Windows administrator access on the source host

.OUTPUTS
PSCustomObject (MigrationObject)
Expand Down
15 changes: 12 additions & 3 deletions public/Copy-DbaLinkedServer.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -10,10 +10,18 @@ function Copy-DbaLinkedServer {

When upgrading from older versions to SQL Server 2025+, MSOLEDBSQL is changed to MSOLEDBSQL19 and provider string for encrypt and trustservercertificate settings is added if not already included to ensure compatibility with the breaking changes in the new driver.

Decrypting the stored passwords requires DAC access to the source instance and Windows administrator access to the source host. On SQL Server Express, the DAC is not available unless the instance is started with trace flag 7806.

The command opens or reuses the dedicated admin connection (DAC) from the machine it runs on. When that machine is different from the source host, enable remote admin connections on the source instance (Set-DbaSpConfigure -SqlInstance <source instance> -Name RemoteDacConnectionsEnabled -Value 1) and make the DAC TCP listener reachable from that machine. SQL Server listens for the DAC on TCP port 1434 when that port is available; otherwise it assigns a port during startup. Check the SQL Server error log for the active DAC port.

The service master key is read and unprotected on the source Windows host. When the source host is remote, this uses PowerShell remoting. When the command runs directly on the source host, everything runs locally, so remote admin connections and PowerShell remoting are not required.

Use -ExcludePassword to skip password decryption entirely; no DAC is opened and the Windows host is not accessed then.

Credit: Password decryption techniques provided by Antti Rantasaari (NetSPI, 2014) - https://blog.netspi.com/decrypting-mssql-database-link-server-passwords/

.PARAMETER Source
Source SQL Server (2005 and above). You must have sysadmin access to both SQL Server and Windows.
Source SQL Server (2005 and above). You must have sysadmin access. Unless -ExcludePassword is used, Windows administrator access on the source host is also required to decrypt the stored passwords.

.PARAMETER SourceSqlCredential
Login to the target instance using alternative credentials. Accepts PowerShell credentials (Get-Credential).
Expand All @@ -23,7 +31,7 @@ function Copy-DbaLinkedServer {
For MFA support, please use Connect-DbaInstance.

.PARAMETER Destination
Destination SQL Server (2005 and above). You must have sysadmin access to both SQL Server and Windows.
Destination SQL Server (2005 and above). You must have sysadmin access; Windows administrator access is not needed on the destination.

.PARAMETER DestinationSqlCredential
Login to the target instance using alternative credentials. Accepts PowerShell credentials (Get-Credential).
Expand Down Expand Up @@ -55,6 +63,7 @@ function Copy-DbaLinkedServer {
.PARAMETER ExcludePassword
Copies linked server definitions without migrating stored passwords or sensitive authentication data.
Use this in security-conscious environments where password decryption is restricted or when passwords should be manually reset after migration.
Also use it when the dedicated admin connection or PowerShell remoting described above is not available, because the copy then needs neither.
Linked servers will be created but authentication credentials will need to be reconfigured.

.PARAMETER WhatIf
Expand Down Expand Up @@ -94,7 +103,7 @@ function Copy-DbaLinkedServer {
Copyright: (c) 2018 by dbatools, licensed under MIT
License: MIT https://opensource.org/licenses/MIT

Requires: sysadmin access on SQL Servers
Requires: sysadmin access on SQL Servers, and unless -ExcludePassword is used DAC access to the source instance plus Windows administrator access on the source host
Limitations: This just copies the SQL portion. It does not copy files (i.e. a local SQLite database, or Microsoft Access DB), nor does it configure ODBC entries.

.LINK
Expand Down
15 changes: 13 additions & 2 deletions public/Export-DbaCredential.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -6,9 +6,15 @@ function Export-DbaCredential {
.DESCRIPTION
Exports SQL Server credentials to T-SQL files containing CREATE CREDENTIAL statements that can recreate the credentials on another instance. By default, this includes decrypted passwords, making it perfect for migration scenarios where you need to move credentials between servers.

The function generates executable T-SQL scripts that DBAs can run to recreate credentials during migrations, disaster recovery, or when setting up new environments. When passwords are included, the function requires sysadmin privileges and remote Windows registry access to decrypt the stored secrets.
The function generates executable T-SQL scripts that DBAs can run to recreate credentials during migrations, disaster recovery, or when setting up new environments.

Use the ExcludePassword parameter to export credential definitions without sensitive data for documentation or security-conscious scenarios.
Decrypting the stored passwords requires sysadmin privileges, DAC access to the instance and Windows administrator access to its host. On SQL Server Express, the DAC is not available unless the instance is started with trace flag 7806.

The command opens or reuses the dedicated admin connection (DAC) from the machine it runs on. When that machine is different from the host of the instance, enable remote admin connections on the instance (Set-DbaSpConfigure -SqlInstance <instance> -Name RemoteDacConnectionsEnabled -Value 1) and make the DAC TCP listener reachable from that machine. SQL Server listens for the DAC on TCP port 1434 when that port is available; otherwise it assigns a port during startup. Check the SQL Server error log for the active DAC port.

The service master key is read and unprotected on the Windows host of the instance. When that host is remote, this uses PowerShell remoting. When the command runs directly on the host, everything runs locally, so remote admin connections and PowerShell remoting are not required.

Use the ExcludePassword parameter to export credential definitions without sensitive data for documentation or security-conscious scenarios; no DAC is opened and the Windows host is not accessed then.

.PARAMETER SqlInstance
The target SQL Server instance or instances.
Expand Down Expand Up @@ -40,6 +46,7 @@ function Export-DbaCredential {
.PARAMETER ExcludePassword
Exports credential definitions without the actual password values, replacing them with placeholder text.
Use this for documentation purposes or when you need credential structure without sensitive data for security reviews.
Also use it when the dedicated admin connection or PowerShell remoting described above is not available, because the export then needs neither.

.PARAMETER Append
Adds the exported credential scripts to an existing file instead of overwriting it.
Expand All @@ -62,6 +69,10 @@ function Export-DbaCredential {
Copyright: (c) 2018 by dbatools, licensed under MIT
License: MIT https://opensource.org/licenses/MIT

Requires:
- sysadmin access on SQL Server
- unless -ExcludePassword is used: DAC access to the instance, and Windows administrator access on its host

.LINK
https://dbatools.io/Export-DbaCredential

Expand Down
5 changes: 5 additions & 0 deletions public/Export-DbaInstance.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -47,6 +47,10 @@ function Export-DbaInstance {
1. Default behavior creates new timestamped folders for historical archiving
2. Using -Force overwrites files in the same location, ideal for scheduled exports that feed into version control systems

Exporting credentials and linked servers includes their stored passwords. Decrypting those requires a dedicated admin connection (DAC) to the instance and Windows administrator access to its host; when this command runs on a different machine than the instance, that means remote admin connections enabled on the instance, its DAC TCP port reachable, and PowerShell remoting to its host. As SQL Server only allows one DAC per instance, this command opens a single one and hands it to both export operations instead of letting each open its own. See Export-DbaCredential and Export-DbaLinkedServer for the details and prerequisites.

Use -ExcludePassword, or exclude both Credentials and LinkedServers, if no DAC should be opened at all.

For more granular control, please use one of the -Exclude parameters and use the other functions available within the dbatools module.

.PARAMETER SqlInstance
Expand Down Expand Up @@ -110,6 +114,7 @@ function Export-DbaInstance {
.PARAMETER ExcludePassword
Omits passwords from exported scripts for logins, credentials, and linked servers, replacing them with placeholder text.
Essential for security compliance when export scripts will be stored in version control or shared with other team members.
Also use it when the dedicated admin connection or PowerShell remoting described above is not available, because the export then needs neither.

.PARAMETER ScriptingOption
Provides a Microsoft.SqlServer.Management.Smo.ScriptingOptions object to customize script generation behavior.
Expand Down
Loading