Best Practice - Builtin\Administrators SQL account - I'm confused

smaas_at_newsgroups.nospam
Date: 11/13/04


Date: Fri, 12 Nov 2004 15:44:01 -0800

I couldn't find anything about Builtin\Administrators in the Microsoft Best
Practices checklist, but MBSA reports that it is part of the sysadmin role
and apparently should not be. I started to research this and see that a lot
of people are going so far as to remove the account altogether from SQL
Server with varying results in an effort to prevent system administrators
from gaining the same access as the DBA. I am confused about the differing
opinions and am wondering if there is some definitive guide to handling this
account to meet Sarbanes-Oxley objectives.

In our particular environment, there are only 4 people in our IT staff and
we intend for two of them, the DBA and the senior sys admin, to have access -
the senior sys admin in more of a back-up context for the DBA but also as
overall responsibility for the server. We would like to exclude the other
two staff. The senior sys admin's plan is reserve knowledge of the System
Administrator account login only to himself but to put the other staff in an
NT group with at least some administrative rights (so that they can
troubleshoot systems from a support perspective - beyond that, I don't know
the details of his plan).

To accomplish this, will it be enough to remove the Builtin\Administrators
account from the sysadmins role or is there some reason to remove the account
completely?



Relevant Pages

  • What happened to me when Whitey Bulger took off
    ... In 1994 a local Woburn Mass. ... Whitey Bulger left town as Steve Flemmi was arrested. ... as reported by hospital staff. ... my account to bounce checks, and never did anything to the teller nor ...
    (alt.true-crime)
  • Re: Administrators security training
    ... topic will make your staff aware who should be communicated and how ... the importance of good and timely documentation. ... General responsibilities as an admin (privileged access, become familiar with security controls, stronger requirements for account passwords and expirations, point out application weaknesses and suggest ways to mitigate) ... How to perform entitlement reviews(identify users and "need to know", periodic review of users, minimize number of admin users, etc) ...
    (Security-Basics)
  • Re: Russ Grover & Dave Nickason - RPC over HTTP and Outlook Cont
    ... i can now use any staff members username/password? ... need the passwords for logon to their workstations Outlook clients. ... have access to OWA - it's an account property. ... not his user account (assuming User CALs). ...
    (microsoft.public.windows.server.sbs)
  • Incorrect Automated Message
    ... Hi I have an outlook express account that is used by couple of staff. ... display name when name is set as "SiteCustomer Help"? ...
    (microsoft.public.exchange.misc)
  • Automated Email error
    ... Hi I have an outlook express account that is used by couple of staff. ... display name when name is set as "SiteCustomer Help"? ...
    (microsoft.public.outlook.general)