Re: SQL Server

From: Brett Karst (karst.brett@mayo.edu)
Date: 11/24/02


From:     Brett Karst <karst.brett@mayo.edu>
Date: Sun, 24 Nov 2002 12:09:39 -0800


Thanks for the articles. I agree with you that the situation under
which the sa account was being used was inappropriate. When I asked the
administrators to create separate accounts, they argued that:

1. The standard SQL Server audit logs only indicate when a user logged
on/off; not what they did. Utilizing the enhanced SQL Server auditing
("Profile"?) may require too many system resources, even if they were to
just log the details of the individual sa accounts because the logging
mechanism would have to verify whether each transaction was performed by
an sa-privileged account.

2. Server upgrades and other tasks require the user to log in as "sa",
so the account cannot be removed. This was the part that I was
wondering about, and if it were true. They are somewhat open to the
envelope method mentioned in the references you cited.

Thanks again for your help.

*** Sent via Developersdex http://www.developersdex.com ***
Don't just participate in USENET...get rewarded for it!



Relevant Pages

  • Re: Error 15401 using sp_grantlogin (not addressed by current KB articles)
    ... Restarting Windows 2000 resolved the problem for this particular account, ... confused when it sees a duplicate SID. ... > One way to get SQL Server to agree with the renamed NT ... > Preview (to ensure the script was created), ...
    (microsoft.public.sqlserver.security)
  • Re: SharePoint V3 Install Error
    ... But it our case it had to do with Group Policies that forbid the account of ... WSS FAQ:www.wssv3faq.com/wss.collutions.com ... Event Source: WindowsSharePointServices3Search ... whatever you are installing WSS as sufficient rights to the SQL Server ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: Job owned by a non-sysadmin fails to run
    ... I have a SQL Server 2000 SP4. ... As advised in many posts I created a Proxy SQL Server Agent account ... I made this account belong to the sysadmins ... I added the account sqlservice to Administrators as advised in the article ...
    (microsoft.public.sqlserver.security)
  • RE: Problems with WebParts
    ... to a database called aspnetdb. ... > The connection string specifies a local SQL Server Express instance using a ... > server account must have read and write access to the applications directory. ... > This is necessary because the web server account will automatically create ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Cannot connect to Query Analyzer
    ... For Query Analyzer, I tried replacing the file as you suggested but had the ... same results (Enterprise Manager starts up fine, ... I created an account on my laptop and changed SQL ... Try replacing the MMC app for SQL Server from the original ...
    (microsoft.public.sqlserver.connect)