SQL Server Forums
Profile | Register | Active Topics | Members | Search | Forum FAQ
 
Register Now and get your question answered!
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 SQL Server 2005 Forums
 SQL Server Administration (2005)
 BUILTIN\Administrators
 New Topic  Reply to Topic
 Printer Friendly
Author Previous Topic Topic Next Topic  

tbrothers
Yak Posting Veteran

USA
79 Posts

Posted - 06/22/2012 :  17:08:19  Show Profile  Visit tbrothers's Homepage  Reply with Quote
Hello - We're running SQL 2005 Ent. We use mixed mode authentication. When SQL was installed it automatically created the SQL login BUILTIN\Administrators and added it to the sysadmin role.

Assuming we have assigned any other privileges or used this login for anything ... is there any reason I should not delete it?

I ask because we're going through an audit and they specifically stated the following:

Please confirm that the BUILTIN\Administrators login has been removed and replaced with a Windows group specifically created for database administrators.

Thanks,
Terry

jackv
Flowing Fount of Yak Knowledge

United Kingdom
1773 Posts

Posted - 06/23/2012 :  04:38:34  Show Profile  Visit jackv's Homepage  Reply with Quote
Removing the BUILTIN/Administrators group to prevent local server administrators from accessing SQL Serve is a good idea.
Ensure you've tested all apps first - and other processes such as backups, in a lower environment.
In SQL Server 2008 BUILTIN\Administrators is not automatically added

Jack Vamvas
--------------------
http://www.sqlserver-dba.com
Go to Top of Page

gregory_pfeifer
Starting Member

USA
1 Posts

Posted - 06/23/2012 :  14:30:30  Show Profile  Reply with Quote
You may also want to check with your Active Directory group prior to removal, we began removing the account on 50 legacy servers to find out they had added admin accounts for Citrix, LANDesk, Symantec, Qualys to this group to limit there work not realizing that it really is a SQL Server group account.

GMan
Go to Top of Page

jeffw8713
Aged Yak Warrior

USA
696 Posts

Posted - 06/24/2012 :  10:37:09  Show Profile  Reply with Quote
Before removing the group - just remove the sysadmin rights. Make sure you have setup another account with sysadmin rights before doing this, because if you are getting sysadmin rights through that group and either remove the group or syadmin rights you could lock yourself out of the system.

After a few weeks/months without sysadmin rights - you can then remove the group.
Go to Top of Page
  Previous Topic Topic Next Topic  
 New Topic  Reply to Topic
 Printer Friendly
Jump To:
SQL Server Forums © 2000-2009 SQLTeam Publishing, LLC Go To Top Of Page
This page was generated in 0.05 seconds. Powered By: Snitz Forums 2000