STIGQter STIGQter: STIG Summary: Microsoft SQL Server 2022 Instance Security Technical Implementation Guide Version: 1 Release: 4 Benchmark Date: 01 Apr 2026:

The "Remote Access" feature must be disabled unless specifically required and approved.

DISA Rule

SV-271298r1111126_rule

Vulnerability Number

V-271298

Group Title

SRG-APP-000141-DB-000093

Rule Version

SQLI-22-017200

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Disable use of [Remote Access] if it is not authorized.

To disable the use of [Remote Access], from the query prompt:
EXEC SP_CONFIGURE 'remote access', 0;
RECONFIGURE WITH OVERRIDE;

Check Contents

To determine if [Remote Access] is enabled, execute the following command:
SELECT name, value, value_in_use
FROM sys.configurations
WHERE name = 'Remote Access'

If [value_in_use] is a [1], review the system documentation to determine whether the use of [Remote Access] is approved. If it is not approved, this is a finding.

Vulnerability Number

V-271298

Documentable

False

Rule Version

SQLI-22-017200

Severity Override Guidance

To determine if [Remote Access] is enabled, execute the following command:
SELECT name, value, value_in_use
FROM sys.configurations
WHERE name = 'Remote Access'

If [value_in_use] is a [1], review the system documentation to determine whether the use of [Remote Access] is approved. If it is not approved, this is a finding.

Check Content Reference

M

Target Key

5677