PREEMPTIVE_OS_LOOKUPACCOUNTSID

(Republishing, or using this info in a commercial product/website, is prohibited without permission. All other uses are permitted. If in doubt, please ask.)

(Back to main page…)

Description:

This wait type is when a thread is calling the Windows LookupAccountSid function.

(Books Online description: N/A)

Questions/comments on this wait type? Click here to send Paul an email, especially if you have any information to add to this topic.

Added in SQL Server version:

2008

Removed in SQL Server version:

N/A

Extended Events wait_type value:

The map_key value in sys.dm_xe_map_values is 381 in 2008 and 2008 R2, 429 in 2012, and 445 in 2014 RTM. After 2014 RTM, you must check the DMV to get the latest value as some map_key values have changed in later builds.

Other information:

If you see long waits for this wait type, have your infrastructure team investigate performance issues with servers that provide security authentication and authorization, such as Active Directory Controllers and Domain Controllers.

In one reported case where this wait type was the top one, code was repeatedly calling the SUSER_SNAME() function for a specified SID, which caused a domain controller on the opposite side of the Atlantic Ocean to be queried. So while it’s more common that a local DC or ADC has an issue, it could also be a long round-trip time for the security information.

Note that when a thread calls out to Windows, the thread changes from non-preemptive (SQL Server controls the thread) to preemptive (Windows controls the thread) mode. The thread’s state will be listed as RUNNING, as SQL Server doesn’t know what Windows is doing with the thread.

Known occurrences in SQL Server (list number matches call stack list):

  1. Looking up an account SID (in this case, when building the login token for a new client connection)

And other similar call stacks.

Abbreviated call stacks (list number matches known occurrences list):

  1. SOS_Task::PopWait+b1
    SOS_ExternalAutoWait::~SOS_ExternalAutoWait+7c
    NTGroupInfo::`vector deleting destructor’+70b
    CSECWinLoginTokenBuilder::BuildLoginToken+3fb
    CSECWinLoginTokenBuilder::CallBuildLoginToken+6e
    CSECLoginTokenBuilder::CreateAndAuthorizeLoginToken+484
    FindLogin+3f6
    login+829
    process_login_finish+16e
    process_commands+456
    TDSSNIClient::AddSSPIProviderHandler+474
    TDSSNIClient::AddProviderHandler+38
    SNIProcessAddProviderOnWorker+122
    SOS_Task::Param::Execute+21e
    SOS_Scheduler::RunTask+ab