1.2.2 SQL Server Agent Service Account

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Level 1, Not Scorable
If replication, DTS, or other inter-server communication is required, the SQL Server Agent account must be a domain account. Ensure the
domain account used for the SQL Server Agent Service is least-privilege.
If the SQL Server Agent Service is compromised, the attacker's ability to pivot to other systems is reduced if the compromised service is
operating under the context of a least privileged principal.
ref. https://benchmarks.cisecurity.org/tools2/sqlserver/CIS_Microsoft_SQL_Server_2005_Benchmark_v2.0.0.pdf, pg 18.
NOTE: Update {SQL_SERVER_AGENT} with the appropriate value for the local environment