Skip to content

Use of credentials and proxies must be restricted to necessary cases only.

An XCCDF Rule

Description

In certain situations, to provide required functionality, a DBMS needs to execute internal logic (stored procedures, functions, triggers, etc.) and/or external code modules with elevated privileges. However, if the privileges required for execution are at a higher level than the privileges assigned to organizational users invoking the functionality applications/programs, those users are indirectly provided with greater privileges than assigned by organizations. Privilege elevation must be utilized only where necessary and protected from misuse.

ID
SV-213980r961359_rule
Version
SQL6-D0-010500
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Remove any SQL Agent Proxy accounts and credentials that are not authorized. 
 
DROP CREDENTIAL <Credential Name> 
GO 
 
USE [msdb]