Andreas Wolter 2/6/2025

The challenges for least privilege: When sysadmin is still required in Microsoft SQL Server

Read Original

This technical article examines the difficulties in adhering to the Principle of Least Privilege (PoLP) within Microsoft SQL Server. It details specific areas, such as certain DBCC commands, SQL Agent, and Replication, where the sysadmin server role is still required, bypassing granular permission controls. The author, drawing from experience on the SQL Server security team, discusses improvements in SQL Server 2022 and looks ahead to SQL Server 2025, arguing that the CONTROL SERVER permission is not a sufficient security improvement.

The challenges for least privilege: When sysadmin is still required in Microsoft SQL Server

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week