Warning! Audit Deprecated
Information
Level 1, Not Scorable
Make a domain service account a member of only non-privileged groups.
SQL Server service accounts do not typically require elevated domain privileges. Ensuring that SQL Server service account and the SQL Agent
account run under the lowest privileges necessary lowers the risk to the network if these accounts are compromised.
ref. https://benchmarks.cisecurity.org/tools2/sqlserver/CIS_Microsoft_SQL_Server_2005_Benchmark_v2.0.0.pdf, pg 20.
NOTE: Update {SQL_SERVICE_ACCT} with the appropriate value for the local environment