Use of credentials and proxies must be restricted to necessary cases only.
An XCCDF Rule
Description
In certain situations, to provide required functionality, a DBMS needs to execute internal logic (stored procedures, functions, triggers, etc.) and/or external code modules with elevated privileges. However, if the privileges required for execution are at a higher level than the privileges assigned to organizational users invoking the functionality applications/programs, those users are indirectly provided with greater privileges than assigned by organizations. Privilege elevation must be utilized only where necessary and protected from misuse.
- ID
- SV-213980r961359_rule
- Version
- SQL6-D0-010500
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Remove any SQL Agent Proxy accounts and credentials that are not authorized.
DROP CREDENTIAL <Credential Name>
GO
USE [msdb]