STIGQter STIGQter: STIG Summary: Microsoft SQL Server 2022 Instance Security Technical Implementation Guide Version: 1 Release: 4 Benchmark Date: 01 Apr 2026:

The SQL Server External Scripts Enabled feature must be disabled, unless specifically required and approved.

DISA Rule

SV-271293r1111138_rule

Vulnerability Number

V-271293

Group Title

SRG-APP-000141-DB-000092

Rule Version

SQLI-22-017700

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Disable use of or remove any external application executable object definitions that are not approved.

To disable the use of [External Scripts Enabled] option, from the query prompt:
EXEC SP_CONFIGURE 'External Scripts Enabled', 0;
RECONFIGURE WITH OVERRIDE;

Check Contents

To determine if [External Scripts Enabled] is enabled, execute the following command:
SELECT name, value, value_in_use
FROM sys.configurations
WHERE name = 'External Scripts Enabled'

If [value_in_use] is a [1], review the system documentation to determine whether the use of [External Scripts Enabled] is approved. If it is not approved, this is a finding.

Vulnerability Number

V-271293

Documentable

False

Rule Version

SQLI-22-017700

Severity Override Guidance

To determine if [External Scripts Enabled] is enabled, execute the following command:
SELECT name, value, value_in_use
FROM sys.configurations
WHERE name = 'External Scripts Enabled'

If [value_in_use] is a [1], review the system documentation to determine whether the use of [External Scripts Enabled] is approved. If it is not approved, this is a finding.

Check Content Reference

M

Target Key

5677