SQL Server: before and after hardening

Server 17.0.5005.3 Enterprise Developer Edition (64-bit) · collected 2026-10-01T18:04:15Z (before) and 2026-10-01T18:04:34Z (after)

Summary

SeverityBeforeAfter
High70
Medium60
Low10
Checks not evaluated00
CheckTitleBeforeAfter
MS-01sa login enabled or not renamed2 finding(s)pass
MS-02SQL logins without password policy2 finding(s)pass
MS-03xp_cmdshell enabledpasspass
MS-04Risky surface options enabled1 finding(s)pass
MS-05Encrypted connections not forced1 finding(s)pass
MS-06User database without TDE1 finding(s)pass
MS-07Audit does not cover key events1 finding(s)pass
MS-08Unexpected sysadmin members2 finding(s)pass
MS-09guest user can connect1 finding(s)pass
MS-10Application login over-privileged1 finding(s)pass
MS-11TRUSTWORTHY database1 finding(s)pass
MS-12Cross-database ownership chaining1 finding(s)pass

Findings before hardening

CheckSeverityStatusObjectDetail
MS-01HighFindingsaThe built-in sa login is enabled.
MS-01HighFindingsaThe built-in sa login keeps its well-known name.
MS-02MediumFindingsaCHECK_EXPIRATION off on a sysadmin login.
MS-02MediumFindingclinic_appCHECK_POLICY off.
MS-04MediumFindingremote accessRemote access (procedure calls from other servers) is enabled.
MS-05HighFindingserverEncryption is not forced: a connection made with Encrypt=no was not encrypted; 0 of 1 sessions open at collection were unencrypted.
MS-06MediumFindingclinicTDE is not enabled.
MS-07HighFindingserverNo server audit is running.
MS-08HighFindingBUILTIN\AdministratorsMember of sysadmin but not in the allowed list.
MS-08HighFindingNT AUTHORITY\NETWORK SERVICEMember of sysadmin but not in the allowed list.
MS-09MediumFindingclinicThe guest user has CONNECT.
MS-10MediumFindingclinic_appMember of fixed database role db_owner.
MS-11HighFindingclinicTRUSTWORTHY is on.
MS-12LowFindingserverCross-database ownership chaining is on for the whole instance.

Findings after hardening

CheckSeverityStatusObjectDetail