Citrix Daas SDK

Get-AcctDBSchema

Gets SQL scripts to create or maintain the database schema for the Citrix ADIdentity Service.

Syntax

Get-AcctDBSchema
   [-DatabaseName <String>]
   [-ServiceGroupName <String>]
   [-ScriptType <ScriptTypes>]
   [-LocalDatabase]
   [-Sid <String>]
   [-DatabaseRights <String>]
   [-AzureDatabase]
   [<CitrixCommonParameters>]
   [<CommonParameters>]
<!--NeedCopy-->

Description

Gets SQL scripts that can be used to create a new ADIdentity Service database schema, add a new ADIdentity Service to an existing site, remove an ADIdentity Service from a site, or create a database server logon for an ADIdentity Service.

If no Sid parameter is provided, the scripts obtained relate to the currently selected ADIdentity Service instance, otherwise the scripts relate to ADIdentity Service instance running on the machine identified by the Sid provided. When obtaining the Evict script (See ScriptType), a Sid parameter must be supplied.

The current service instance is that on the local machine, or that explicitly specified by the last usage of the -AdminAddress parameter to an ADIdentity SDK cmdlet.

The service instance used to obtain the scripts does not need to be a member of a site or have had its database connection configured.

The database scripts only support Microsoft SQL Server, or SQL Server Express, and require Windows integrated authentication to be used. They can be run using SQL Server’s SQLCMD utility, or by copying the script into an SQL Server Management Studio (SSMS) query window and executing the query. If using SSMS, the query must be executed in ‘SQLCMD mode’.

The ScriptType parameter determines which script is obtained. If ScriptType is not specified, or is FullDatabase or Database, the script contains:

  • Creation of service schema
  • Creation of database server logon
  • Creation of database user
  • Addition of database user to ADIdentity Service roles

If ScriptType is Instance, the returned script contains:

  • Creation of database server logon
  • Creation of database user
  • Addition of database user to ADIdentity Service roles

If ScriptType is Evict, the returned script contains:

  • Removal of ADIdentity Service instance from database
  • Removal of database user

If ScriptType is Login, the returned script contains:

  • Creation of database server logon only

If the service uses two data stores they can exist in the same database. You do not need to configure a database before using this command.

Examples

EXAMPLE 1

Gets a script to create the full database schema for the Citrix ADIdentity Service and copies it to a file called “C:\ADIdentitySchema.sql”

This script can be used to create the service schema in a database with name “MySiteDB”, which must already exist, and must not already contain a ADIdentity service schema.

Get-AcctDBSchema -DatabaseName MySiteDB -ServiceGroupName  MyServiceGroup > C:\ADIdentitySchema.sql
<!--NeedCopy-->

EXAMPLE 2

Gets a script to create the appropriate database server logon for the ADIdentity service. This can be used when configuring a mirror server for use.

Get-AcctDBSchema -DatabaseName MySiteDB -ScriptType Login > C:\ADIdentityLogins.sql
<!--NeedCopy-->

Parameters

-DatabaseName

Specifies the name of the database into which the new ADIdentity service schema is to be placed, or in which it already exists. The database itself is not created by any of the script types; it must already exist before the scripts are run.

Type: String
Position: Named
Default value: None
Required: False
Accept pipeline input: False
Accept wildcard characters: False

-ServiceGroupName

The name of the service group to be used when creating the Citrix ADIdentity Service database schema. The service group is the collection of all ADIdentity Services that share the same database and are considered equal (i.e. any service in the same service group can be used interchangeably).

Type: String
Position: Named
Default value: None
Required: False
Accept pipeline input: False
Accept wildcard characters: True

-ScriptType

Specifies the type of database script returned. Available script types are:

  • FullDatabase

    Creates a database schema for the Citrix ADIdentity Service in a database instance that does not already contain one. This is used when creating a new site. DatabaseName and ServiceGroupName are required parameters for this script type.

  • Database

    Performs the same function as “FullDatabase”.

  • Instance

    Adds a ADIdentity Service instance to a database and so to the associated site. Appropriate database server logons and users are created to allow the service instance access to the required service schemas.

  • Evict

    Removes a ADIdentity Service instance from the database and so from the site. All reference to the service instance is removed from the database. DatabaseName and Sid are required parameters for this script type.

  • Login

    Adds a logon for the ADIdentity Service instance to a database server. This is specifically for use when configuring SQL Server mirroring where the mirror server must have appropriate logons created for all service instances in the site.

Type: ScriptTypes
Position: Named
Default value: None
Required: False
Accept pipeline input: False
Accept wildcard characters: False

-LocalDatabase

Specifies whether the database script is to be used in a database instance run on the same controller as other services in the service group. Including this parameter ensures the script creates only the required permissions for local services to access the database schema for ADIdentity services. If this parameter is specified inappropriately, the service instance will not be able to connect to the database.

Type: SwitchParameter
Position: Named
Default value: None
Required: False
Accept pipeline input: False
Accept wildcard characters: False

-Sid

Specifies the SID of the controller on which the ADIdentity Service instance to remove from the database is running (only valid for a script type of Evict).

Type: String
Position: Named
Default value: None
Required: False
Accept pipeline input: True (ByValue)
Accept wildcard characters: False

-DatabaseRights

Specifies the rights to run the database script under. Available rights are:

  • Mixed

    Creates a database schema which uses all rights.

  • SysAdmin:

    Creates a database schema which does the minimum with the SysAdmin (sa) rights.

  • DbOwner:

    Creates a database schema which only needs Database Owner (dbo) rights. This script expects to be used after the SysAdmin script has been run.

Type: String
Position: Named
Default value: Mixed
Required: False
Accept pipeline input: False
Accept wildcard characters: False

-AzureDatabase

Specifies that the generated schema must be compatible with Azure SQL limits, including not generating code for logins.

Type: SwitchParameter
Position: Named
Default value: None
Required: False
Accept pipeline input: False
Accept wildcard characters: False

CitrixCommonParameters

This cmdlet supports the common Citrix parameters: -AdminAddress, -AdminClientIP, -BearerToken, -TraceParent, -TraceState and -VirtualSiteId. For more information, see about_CitrixCommonParameters.

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

Inputs

None

You cannot pipe input into this cmdlet.

Outputs

String

A string containing the required SQL script for application to a database.

Notes

If the command fails, the following errors can be returned.

Error Codes


GetSchemasFailed

The database schema could not be found.

ActiveDirectoryAccountResolutionFailed

The specified Active Directory account or Group could not be found.

DatabaseError

An error occurred in the service while attempting a database operation.

DatabaseNotConfigured

The operation could not be completed because the database for the service is not configured.

DataStoreException

An error occurred in the service while attempting a database operation - communication with the database failed for various reasons.

PermissionDenied

You do not have permission to execute this command.

AuthorizationError

There was a problem communicating with the Citrix Delegated Administration Service.

CommunicationError

There was a problem communicating with the remote service.

ExceptionThrown

An unexpected error occurred. For more details, see the Windows event logs on the controller or the Citrix Virtual Apps and Desktops logs.

Get-AcctDBSchema