Link to home
Start Free TrialLog in
Avatar of Pau Lo
Pau Lo

asked on

DBA accounts best practice

Is there any major security benefit/other benefit in setting up DBA's with a separate AD account for day to day activities and then an elevated account for when they do their DBA work? I can understand the logic when it comes to tasks such as browsing the Internet as if you got some nasty malware as a domain admin for example it could cause carnage, but if a standard user account is added SYSADMIN privileges to live DB servers is that really a dangerous thing or should they have a second account for doing their DBA duties. Do you use multiple accounts in your role as a DBA?
ASKER CERTIFIED SOLUTION
Avatar of btan
btan

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Yes, don't do it.

You cannot tier isolate it
You should apply PSO with stronger password to elevated accounts
You might leak the hash which can then be offline cracked or checked on hashkiller
Should not be able to do admin from a user session without explicitly elevating
Elevated accounts should have more rigorous auditing
etc.