SV-271358r1137659_rule
V-271358
SRG-APP-000431-DB-000388
SQLI-22-012400
CAT II
10
Configure SQL Server services to have a documented, dedicated account.
For nondomain servers, consider using virtual service accounts (VSAs).
For more information, refer to: https://learn.microsoft.com/en-us/sql/database-engine/configure-windows/configure-windows-service-accounts-and-permissions?
For standalone domain-joined servers, consider using managed service accounts.
For more information, refer to: https://learn.microsoft.com/en-us/sql/database-engine/configure-windows/configure-windows-service-accounts-and-permissions?
For clustered instances, consider using group managed service accounts.
For more information, refer to: https://learn.microsoft.com/en-us/sql/database-engine/configure-windows/configure-windows-service-accounts-and-permissions?
or
https://learn.microsoft.com/en-us/archive/blogs/markweberblog/group-managed-service-accounts-gmsa-and-sql-server-2016
Review the server documentation to obtain a listing of required service accounts. Review the accounts configured for all SQL Server services installed on the server.
Run the following query in SSMS:
SELECT servicename,service_account FROM sys.dm_server_services
Review the returned results. If any services are configured with the same service account or with an account that is not documented and authorized, this is a finding.
V-271358
False
SQLI-22-012400
Review the server documentation to obtain a listing of required service accounts. Review the accounts configured for all SQL Server services installed on the server.
Run the following query in SSMS:
SELECT servicename,service_account FROM sys.dm_server_services
Review the returned results. If any services are configured with the same service account or with an account that is not documented and authorized, this is a finding.
M
5677