Solved

sysadmin role risks

Posted on 2014-04-16
1
569 Views
Last Modified: 2014-04-16
can anyone give a management freindly summary of what a user can do with sysadmin priveleges on a SQL server? (aside from access all data). I am trying to identify the risks and put forward a case for revoking such access as there seems a significant number of users with this role permission. So a good list of potential problems that a malciois user with these permissions could cause would be most welcome.
0
Comment
Question by:pma111
1 Comment
 
LVL 52

Accepted Solution

by:
Carl Tawn earned 500 total points
ID: 40003514
Anyone with sysadmin rights can do anything they want, they have full unrestricted administrative rights over the SQL server. It would be a very bad idea to give that level of permissions to anybody who didn't need it.

Non-exhaustive list:

Create/alter/drop any security object (users, roles, etc)
Create/alter/drop any database, database object, agent job
Create/alter/drop security certificates, encryption keys
Backup/restore/overwrite any database
Modify any server settings
Setup/remove mirroring, replication, log shipping

The list goes on.....
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Why is this different from all of the other step by step guides?  Because I make a living as a DBA and not as a writer and I lived through this experience. Defining the name: When I talk to people they say different names on this subject stuff l…
How to leverage one TLS certificate to encrypt Microsoft SQL traffic and Remote Desktop Services, versus creating multiple tickets for the same server.
Via a live example, show how to shrink a transaction log file down to a reasonable size.
Viewers will learn how to use the INSERT statement to insert data into their tables. It will also introduce the NULL statement, to show them what happens when no value is giving for any given column.

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question