BUILTIN\Administrators help

From: CMLC (anonymous_at_discussions.microsoft.com)
Date: 09/24/04


Date: Fri, 24 Sep 2004 04:05:43 -0700

My suggestion:
1.Remove the login BUILTIN\Administrators from SQL Server.
2.Assign a specified account or NT Group (ex: DBAAdmins)
dba rights on the SQL Server.

Attentions:
-All the connections to SQL Server should be mapped to a
specified account with login rights.
-The services should start using an account other than
Local System Account, because this account is mapped to
the login BUILTIN\Administrators.

This will make your SQL Server more secure, in my
opinion :)
See topics in BOL about "Removing BUILIN\Administrators"
Hope this helps

Regards,
CMLC

>-----Original Message-----
>In an environment using mixed mode, and domain admins
have
>local administrator rights on servers, and it's a domain
>admin that administers all the SQL, can we put any
>restrictions on the BUILTIN\Administrators. What are the
>best restrictions, or what would you recommend?
>Thanks for help,
>Josie
>.
>



Relevant Pages

  • Re: MSSQL$SBSMONITORING Login to Disabled Account?
    ... SQL Server installed, I can't have the tools you were using, can I? ... I still don't know what that process is doing trying to login to the ... Administrator account and I don't understand why this login attempt is ...
    (microsoft.public.windows.server.sbs)
  • Re: xp_cmdshell issue, local system
    ... So initially I tried to change the login using EM, ... account to the localsystem for SQL Server and the same for agent which worked ... Now when I go and try the same for the agent startup account it ...
    (microsoft.public.sqlserver.security)
  • Re: Problems changing the password for the service account in SQL
    ... It is because there is BULTIN\Administrstors Login that alllow access to ... You have a domaim account group that SQL Server ... this domain account in SQL Server ...
    (microsoft.public.sqlserver.security)
  • Re: Builtin Administrators Group and SQL Agent Jobs
    ... >gave that login full access to all SQL DB's. ... >group and rights to all the SQL Server databases. ... >Administrator Server role explicitly. ... >account that is a member of the DBA group and this group ...
    (microsoft.public.sqlserver.security)
  • Re: Conflicting AD groups
    ... This means that the sum of rights granted to all groups (with rights to SQL Server) for a particular login are applied. ...
    (microsoft.public.sqlserver.security)