1.2.3 Local Administrators group membership

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Level 1, Not Scorable
Any local or domain account used by SQL server services must not be a member of the local Administrators group.
Ensuring that SQL server related services are not member of the local Administrators group will reduce an attacker's ability to compromise
other local assets, accounts, services, or information on the server.
ref. https://benchmarks.cisecurity.org/tools2/sqlserver/CIS_Microsoft_SQL_Server_2005_Benchmark_v2.0.0.pdf, pg 19.
Change {SQL_SERVER_ACCT} to your organization's appropriate SQL Server account.