Windows authentication is more robust than the mechanism provided by SQL Server authentication and should be used if at all possible. If SQL Server authentication is necessary, configure GPO to limit SQL Server account settings. ref. http://www.cisecurity.org/tools2/sqlserver/CIS_SQL2005_Benchmark_v1.0.pdf, pg 9. We are testing the server is using Windows authentication mode.