STIGQter STIGQter: STIG Summary:

Microsoft SQL Server 2022 Instance Security Technical Implementation Guide

Version: 1

Release: 4 Benchmark Date: 01 Apr 2026

CheckedNameTitle
SV-271263r1108405_ruleSQL Server must limit the number of concurrent sessions to an organization-defined number per user for all accounts and/or account types.
SV-271264r1111061_ruleSQL Server must be configured to use the most-secure authentication method available.
SV-271265r1108933_ruleSQL Server must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals.
SV-271266r1137654_ruleSQL Server must enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.
SV-271267r1108417_ruleSQL Server must protect against a user falsely repudiating by ensuring only clearly unique Active Directory user accounts can connect to the instance.
SV-271268r1136917_ruleSQL Server must protect against a user falsely repudiating by ensuring the NT AUTHORITY SYSTEM account is not used for administration.
SV-271269r1108423_ruleSQL Server must protect against a user falsely repudiating by ensuring all accounts are individual, unique, and not shared.
SV-271270r1108426_ruleSQL Server must be configured to generate audit records for DOD-defined auditable events within all DBMS/database components.
SV-271271r1108429_ruleSQL Server must allow only the information system security manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited.
SV-271272r1109110_ruleSQL Server must generate audit records when attempts to access privileges, categorized information, and security objects occur.
SV-271273r1109234_ruleSQL Server must initiate session auditing upon startup.
SV-271280r1108456_ruleSQL Server must include additional, more detailed, organization-defined information in the audit records for audit events identified by type, location, or subject.
SV-271282r1109273_ruleThe audit information produced by SQL Server must be protected from unauthorized access, modification, and deletion.
SV-271283r1108465_ruleSQL Server must protect its audit configuration from authorized and unauthorized access and modification.
SV-271284r1109111_ruleSQL Server must limit privileges to change software modules, to include stored procedures, functions and triggers, and links to software external to SQL Server.
SV-271285r1109236_ruleSQL Server must limit privileges to change software modules and links to software external to SQL Server.
SV-271286r1108474_ruleSQL Server software installation account must be restricted to authorized users.
SV-271287r1108843_ruleDatabase software, including DBMS configuration files, must be stored in dedicated directories, separate from the host OS and other applications.
SV-271290r1109112_ruleDefault demonstration and sample databases, database objects, and applications must be removed.
SV-271291r1108899_ruleUnused database components, DBMS software, and database objects must be removed.
SV-271292r1111143_ruleThe SQL Server Replication Xps feature must be disabled unless specifically required and approved.
SV-271293r1111138_ruleThe SQL Server External Scripts Enabled feature must be disabled, unless specifically required and approved.
SV-271295r1111135_ruleThe remote Data Archive feature must be disabled unless specifically required and approved.
SV-271296r1111132_ruleThe "Allow Polybase Export" feature must be disabled, unless specifically required and approved.
SV-271297r1111129_ruleThe "Hadoop Connectivity" feature must be disabled unless specifically required and approved.
SV-271298r1111126_ruleThe "Remote Access" feature must be disabled unless specifically required and approved.
SV-271299r1108513_ruleAccess to linked servers must be disabled or restricted, unless specifically required and approved.
SV-271300r1109264_ruleAccess to nonstandard, extended stored procedures must be disabled or restricted, unless specifically required and approved.
SV-271301r1109114_ruleAccess to common language runtime (CLR) code must be disabled or restricted unless specifically required and approved.
SV-271302r1109113_ruleAccess to xp_cmdshell must be disabled unless specifically required and approved.
SV-271303r1109116_ruleSQL Server must be configured to prohibit or restrict the use of organization-defined ports, as defined in the Ports, Protocols, and Services Management (PPSM) Category Assurance List (CAL) and vulnerability assessments.
SV-271304r1109265_ruleSQL Server must be configured to prohibit or restrict the use of organization-defined protocols as defined in the Ports, Protocols, and Services Management (PPSM) Category Assurance List (CAL) and vulnerability assessments.
SV-271305r1109239_ruleSQL Server must uniquely identify and authenticate users (or processes acting on behalf of organizational users).
SV-271306r1109119_ruleContained databases must use Windows principals.
SV-271307r1109241_ruleIf DBMS authentication using passwords is employed, SQL Server must enforce the DOD standards for password complexity and lifetime.
SV-271309r1109243_ruleIf passwords are used for authentication, SQL Server must transmit only encrypted representations of passwords.
SV-271310r1111062_ruleConfidentiality of information during transmission must be controlled through the use of an approved TLS version.
SV-271313r1111146_ruleWhen using command-line tools such as SQLCMD in a mixed-mode authentication environment, users must use a logon method that does not expose the password.
SV-271314r1109121_ruleSQL Server must use NIST FIPS 140-2 or 140-3 validated cryptographic operations for encryption, hashing, and signing.
SV-271322r1108582_ruleThe Master Key must be backed up and stored in a secure location that is not on the SQL Server.
SV-271323r1108585_ruleThe Service Master Key must be backed up and stored in a secure location that is not on the SQL Server.
SV-271324r1192911_ruleSQL Server must protect the confidentiality and integrity of all information at rest.
SV-271327r1137657_ruleSQL Server must prevent unauthorized and unintended information transfer via Instant File Initialization (IFI).
SV-271328r1137657_ruleSQL Server must prevent unauthorized and unintended information transfer via shared system resources.
SV-271329r1137658_ruleAccess to database files must be limited to relevant processes and to authorized, administrative users.
SV-271331r1108609_ruleSQL Server and associated applications must reserve the use of dynamic code execution for situations that require it.
SV-271332r1108612_ruleSQL Server and associated applications, when making use of dynamic code execution, must scan input data for invalid values that may indicate a code injection attack.
SV-271334r1109125_ruleSQL Server must reveal detailed error messages only to documented and approved individuals or roles.
SV-271341r1111081_ruleSQL Server must prevent nonprivileged users from executing privileged functions, to include disabling, circumventing, or altering implemented security safeguards/countermeasures.
SV-271342r1108642_ruleUse of credentials and proxies must be restricted to necessary cases only.
SV-271343r1108645_ruleSQL Server must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
SV-271344r1111082_ruleSQL Server must provide a warning to appropriate support staff when allocated audit record storage volume reaches 75 percent of maximum audit record storage capacity.
SV-271345r1109254_ruleSQL Server must provide an immediate real-time alert to appropriate support staff of all audit log failures.
SV-271346r1109256_ruleSQL Server must record time stamps in audit records and application data that can be mapped to Coordinated Universal Time (UTC), formerly Greenwich Mean Time (GMT).
SV-271349r1108938_ruleWindows must enforce access restrictions associated with changes to the configuration of the SQL Server instance.
SV-271350r1111084_ruleSQL Server must enforce access restrictions associated with changes to the configuration of the instance.
SV-271351r1167494_ruleSQL Server must produce audit records when attempts to modify SQL Server configuration and privileges occur within the database(s).
SV-271358r1137659_ruleSQL Server services must be configured to run under unique dedicated user accounts.
SV-271359r1137659_ruleSQL Server must maintain a separate execution domain for each executing process.
SV-271362r1108702_ruleWhen invalid inputs are received, the SQL Server must behave in a predictable and documented manner that reflects organizational and system objectives.
SV-271364r1137667_ruleSecurity-relevant software updates to SQL Server must be installed within the time period directed by an authoritative source (e.g., IAVM, CTOs, DTMs, and STIGs).
SV-271365r1138543_ruleMicrosoft SQL Server products must be a version supported by the vendor.
SV-271370r1111091_ruleSQL Server must generate audit records when successful and unsuccessful attempts to modify or delete security objects occur.
SV-271375r1111093_ruleSQL Server must generate audit records when successful and unsuccessful logons or connection attempts occur.
SV-271381r1111095_ruleSQL Server must generate audit records for all direct access to the database(s).
SV-271385r1108771_ruleThe system SQL Server must off-load audit data to a separate log management facility; this must be continuous and in near real time for systems with a network connection to the storage facility and weekly or more often for stand-alone systems.
SV-271387r1111140_ruleThe SQL Server Browser service must be disabled unless specifically required and approved.
SV-271388r1111098_ruleSQL Server must configure SQL Server Usage and Error Reporting Auditing.
SV-271389r1109133_ruleSQL Server must configure Customer Feedback and Error Reporting.
SV-271400r1167497_ruleSQL Server must, for password-based authentication, require immediate selection of a new password upon account recovery.
SV-274444r1137654_ruleThe SQL Server default account [sa] must be disabled.
SV-274445r1111103_ruleThe SQL Server default account [sa] must have its name changed.
SV-274446r1111106_ruleExecution of startup stored procedures must be restricted to necessary cases only.
SV-274447r1111109_ruleThe SQL Server Mirroring endpoint must use AES encryption.
SV-274448r1111112_ruleThe SQL Server Service Broker endpoint must use AES encryption.
SV-274449r1111115_ruleSQL Server execute permissions to access the registry must be revoked unless specifically required and approved.
SV-274450r1111117_ruleFilestream must be disabled unless specifically required and approved.
SV-274451r1111120_ruleThe Ole Automation Procedures feature must be disabled unless specifically required and approved.
SV-274452r1111123_ruleThe SQL Server User Options feature must be disabled unless specifically required and approved.