Skip to main content

Choosing Database Credentials and Authentication for ScrewDrivers v7

ScrewDrivers Pro and Enterprise store configuration in a Microsoft SQL Server database, and every component that touches it needs credentials. This guide helps you pick the right authentication mode during installation and change credentials later without reinstalling.

The three authentication modes​

ScrewDrivers v7 supports three ways to authenticate to SQL Server:

  • Windows Authentication — the logged-on user's Windows credentials secure the connection. This works for interactive tools like ScrewDrivers Administration, where a real user is present.
  • SQL Authentication — a SQL Server login (separate from anyone's Windows credentials) secures the connection. This is the most common choice.
  • Static Windows Authentication — a fixed set of Windows credentials, separate from the logged-on user's, secures the connection. Use this when your security policy requires Windows accounts but the component runs unattended.

Unattended services can't use plain Windows Authentication — there's no logged-on user. The ScrewDrivers Print Server, for example, runs in the background and needs database access when print job reporting is configured, so it authenticates with SQL Authentication or Static Windows Authentication.

What the installers ask for​

Every v7 installer is database-aware: when a component or selected feature requires database access, the installer prompts for credentials. Two things keep those prompts low-drama:

  1. The high-permission work is separated out. Creating, initializing, and updating the database happens only in the ScrewDrivers Database installer, which you run once per environment. The main ScrewDriversProOrEnterprise installer needs only basic read and write access to the Tricerat database — day-to-day installs never need elevated database rights. See What Changed in ScrewDrivers v7 for the background.
  2. Least privilege is practical. If your DBA wants the runtime account trimmed down, grant execution rights with the db_executor role instead of broader permissions.

Changing credentials after installation​

You don't reinstall to change the database server, database name, account, or password — use the ScrewDrivers Database Connection tool (installed alongside any component that accesses the database). It maintains the "Tricerat Simplify" DSN and the registry locations that back it, including the encrypted password value that can't be edited any other way. Changing SQL Access Data After Your Install walks through the tool and how to roll a change across many servers.

Never edit the connection registry values directly — the password is encrypted binary data, and the tool keeps the paired locations in sync.