STIGQter STIGQter: STIG Summary: Microsoft SQL Server 2022 Instance Security Technical Implementation Guide Version: 1 Release: 4 Benchmark Date: 01 Apr 2026:

Use of credentials and proxies must be restricted to necessary cases only.

DISA Rule

SV-271342r1108642_rule

Vulnerability Number

V-271342

Group Title

SRG-APP-000342-DB-000302

Rule Version

SQLI-22-010500

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Remove any SQL Agent Proxy accounts and credentials that are not authorized.

DROP CREDENTIAL <Credential Name>
GO

USE [msdb]
EXEC sp_delete_proxy @proxy_name = '<Proxy Name>'
GO

Check Contents

Review the server documentation to obtain a listing of accounts used for executing external processes. Execute the following to obtain a listing of accounts currently configured for use by external processes.

SELECT C.name AS credential_name, C.credential_identity
FROM sys.credentials C
GO

SELECT P.name AS proxy_name, C.name AS credential_name, C.credential_identity
FROM sys.credentials C
JOIN msdb.dbo.sysproxies P ON C.credential_id = P.credential_id
WHERE P.enabled = 1
GO

If any Credentials or SQL Agent Proxy accounts are returned that are not documented and authorized, this is a finding.

Vulnerability Number

V-271342

Documentable

False

Rule Version

SQLI-22-010500

Severity Override Guidance

Review the server documentation to obtain a listing of accounts used for executing external processes. Execute the following to obtain a listing of accounts currently configured for use by external processes.

SELECT C.name AS credential_name, C.credential_identity
FROM sys.credentials C
GO

SELECT P.name AS proxy_name, C.name AS credential_name, C.credential_identity
FROM sys.credentials C
JOIN msdb.dbo.sysproxies P ON C.credential_id = P.credential_id
WHERE P.enabled = 1
GO

If any Credentials or SQL Agent Proxy accounts are returned that are not documented and authorized, this is a finding.

Check Content Reference

M

Target Key

5677