THE SQL Server Blog Spot on the Web

Welcome to - The SQL Server blog spot on the web Sign in | |
in Search

Argenis Fernandez

Think Your Windows Administrators Don’t Have Access to SQL Server 2008 by Default? Think Again.

Published Sunday, July 10, 2011 7:56 PM by Argenis

Comment Notification

If you would like to receive an email when updates are made to this post, please register here

Subscribe to this post's comments using RSS



Robert L Davis said:

Interesting. I never considered trying something like this.

July 10, 2011 10:15 PM

Paul Timmerman said:

Well that's not scary at all, LOL!

July 10, 2011 10:20 PM

Mark Shay said:

You can also schedule an AT Job to open a command prompt.. Basically, the same thing to get NT Authority/SYSTEM session going.

July 10, 2011 10:31 PM

Robert Miller said:

Some mad hacker skills there.  

Seriously, like Robert Davis, I never thought of this approach.

July 10, 2011 11:01 PM

Meher said:

Nice demo Argenis.


July 11, 2011 9:07 AM

Brent Ozar said:

Wow.  Nice find, man.

July 11, 2011 9:10 AM

K. Brian Kelley said:

Another thing is if you look at the SQL Server VSS Writer service, the service account is System. In SQL Server 2000 System was required because of Full Text. In 2005/2008 it's required not only for updates, but also for this service.

The one disadvantage of using AT is you can't get an interactive session in newer versions of the OS. This is to prevent the case where you schedule a job using AT to start explorer and then intentionally kill explorer. And you can prevent the AT issue by setting the service account that is used for these jobs. This should be a best practice because it's also a security exploit on Windows systems where you've been stripped of admin rights.

July 11, 2011 9:31 AM

Jim Murphy said:

Nice job!  Nice combined use of tools and 'features'.

July 11, 2011 9:54 AM

Chris Wood said:


The KB article says that this account is used for Microsoft Update. I have had problems with others using Microsoft Update on SQL Server so that would be a good reason not to give it sysadmin authority. Do we know what authority the SQL VSS Writer service needs because I would want to remove sysadmin role from it?



July 11, 2011 11:50 AM

Amit Banerjee said:

If you are using VSS backups for your SQL Server instance, then remove the Local System account from the sysadmin list will cause these backups to fail.


Additionally, because of the types of operations that the writer must perform, we recommend that you do not remove the NT AUTHORITY\SYSTEM login from the sysadmin server role.

July 11, 2011 12:10 PM

Chris Wood said:


If you are only using the Maintenance Plan Backup DB thru an SQL agent job then you do not need this service right? We also use Red Gate SQLBackup so I know that this uses the Writer service but what elso would use it?


July 11, 2011 1:51 PM

Argenis said:


For regular native backups or Red Gate backups you do not need the VSS Writer service. You would need it if you used DPM, for example.


July 11, 2011 2:10 PM

Chris Wood said:


If that's the case then we can certaily try to remove syadmin authority.



July 11, 2011 3:30 PM

Leo Miller said:

Thinking it through you will see he doesn't even need to add himself as a Sysadmin. Under the NT Authotity account he is already a sysadmin, and effectivly transparent to most monitoring.

Our system monitors Sysadmins added or removed, but we wouldn't see the first logon.

July 11, 2011 5:36 PM

Argenis said:


If you're only monitoring 'sa' logins, then yes, you will miss the login by 'NT AUTHORITY\SYSTEM'. In my opinion any system that is properly audited should monitor all logins (failed and successful) - this is especially true of member of the sysadmin server role.

July 11, 2011 6:15 PM

GrumpyOldDBA said:

ah well this account NT AUTHORITY\SYSTEM  does not need sysadmin rights to run, even on a cluster. I change this to public only, add as a user to master database and grant datareader. I forget exactly what it needs to call, think it might be checking version info.

Sorry but a DBA should understand security on his or her system fully with regard to what logins are created by default on install - it could be that I spent many years working in a SOX environment - that tends to sharpen your outlook ( paranoia ) on things.

I see to remember ms kbs covering this - something like "impeding admins ona  cluster" or something.

Good post though - I wonder how many DBAs suddenly had a panic attack?

July 13, 2011 9:56 AM

Dale Hirt said:

I had heard of the running SQL Server in single-user mode hack, but this one is truly a wonder of simplicity and a gaping hole.

Thanks for the great article on it.

July 18, 2011 4:22 PM

Aaron Sentell said:

At least they can't use this to hack in using a GUI like SSMS ... or can they? Not that I feel any better either way.

July 20, 2011 4:43 PM

Jorge Segarra said:

Again, awesome find. Good news for security folks though, looks like this loophole might be "closed" in Denali as NT\System is no longer sysadmin by default:

"BUILTIN\administrators and Local System (NT AUTHORITY\SYSTEM) are not automatically provisioned in the sysadmin fixed server role."

July 23, 2011 8:05 PM

Jason S said:

This isn't a security hole or loophole by any means. If you are a local admin on a system, all bets are off to begin with. Local admins by definition can do anything they want. If someone isn't trusted, then they shouldn't be a local admin. If an untrusted user is on a system as local admin, you've got big trouble whether they try to log into SQL Server or not.

Also, the task scheduler was completely redesigned in Vista/2008 so the AT trick (mentioned way above) hasn't worked in a while.

October 14, 2011 3:47 PM

Argenis Fernandez said:

  If you recall one of my previous blog posts, titled Think Your Windows Administrators Don’t Have

January 12, 2012 6:34 PM

Sudhanshu said:

Excelelnt one, this saves my time...


March 21, 2012 3:40 AM

Neil Simmons said:

Actually as long as you use the -i switch in psexec then you can just as easily run the SSMS from here.

August 13, 2012 9:14 AM

Nik Edmiidz said:

Got the following error:

C:\Windows\system32>sqlcmd -S MAGMA\R2

HResult 0xFFFFFFFF, Level 16, State 1

SQL Server Network Interfaces: Error Locating Server/Instance Specified [xFFFFFF


Sqlcmd: Error: Microsoft SQL Server Native Client 10.0 : A network-related or in

stance-specific error has occurred while establishing a connection to SQL Server

. Server is not found or not accessible. Check if instance name is correct and i

f SQL Server is configured to allow remote connections. For more information see

SQL Server Books Online..

Sqlcmd: Error: Microsoft SQL Server Native Client 10.0 : Login timeout expired.


September 7, 2012 12:07 PM

Argenis said:

@Neil: indeed you can - the cmd window shows a what I would have needed several SSMS screenshots to demonstrate.

September 7, 2012 12:18 PM

Argenis said:

@Nik: MAGMA\R2 is the name of the SQL Server instance that I used in this example. You'll have to replace it with the name of the instance you're trying to connect to.

September 7, 2012 12:19 PM

PJ said:


November 15, 2012 10:00 AM

Ankur Arora said:

This article is indeed very interesting and knowledgable. Thanks a lot Argenis


November 22, 2012 3:17 PM

Josh M. said:

Great workaround!

January 18, 2013 10:57 AM

DL said:

Great tool!  Thanks!

February 12, 2013 12:08 PM

Es said:

Amazing. Thanks!

May 30, 2013 10:15 PM

David said:

I frickin' love you!

October 31, 2013 11:15 PM

ars said:

Worked !


June 30, 2014 3:15 AM

Julio said:

Worked, and saves me from disaster.

Thanks a lot.

November 26, 2014 7:27 PM

Zubair Ahmed said:

Excellent KB; thanks Argenis.

March 10, 2015 4:48 AM

Jack said:

On my server NT AUTHORITY\SYSTEM  does not have sysadmin rights, public only. Any advice how can I login as sa?

March 18, 2015 1:22 PM

Argenis said:

March 18, 2015 1:27 PM

Jack said:

@Argenis, thank you very much! It works now :)

March 19, 2015 9:35 AM

Pavel Lemnitskiy said:

Great workaround, thanks!


April 24, 2015 10:07 PM

khalil said:

Nice Articles, still works on old boxes.


August 6, 2015 4:49 AM

fyrefox said:

Thank you for this how-to ! Worked for me!

December 18, 2015 7:28 AM

ermoas said:

great post! very useful information. thanks for sharing

March 7, 2016 2:01 AM

RJ said:

When I tried to run the SQLCMD, i hit with pipe error.

But when I tried to run the SQL management ssme.exe with the same , it worked.

PsExec -s -i "C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\Ssms.exe"

April 27, 2016 7:59 PM

Vincent said:

RJ Thanks!!!!!!!!!!!! All other solution sdid not work for me!!!!!

May 11, 2016 11:13 AM

Seán said:

Massive thanks for this.

I had a legacy vendor-installed SQL 2008 R2 Express system that nobody had the password to. This worked a charm :-)

June 10, 2016 6:58 AM

rodabot said:

Perfect! thanks!

September 29, 2016 12:09 PM

Vlad said:

Argenis - great article, thanks a million.

January 27, 2017 9:15 AM

Michael said:

Sometimes get troubles with these assignments and projects. While Java is still a fair programming language as compared to other languages, it is still very complicated to make assignments and projects. Students often take Programming Assignment Help from the online writing services to help them out from this difficult situation.

January 14, 2019 10:09 PM

ammie said:

Being an academic writer from past 5 years providing assignment help writing services to college and university students also associated with Myassignmenthelp platform. I am dedicated in providing best online academic writing services to the college students at the affordable rates.

January 23, 2019 10:31 PM

<a href="">Tow Truck Service</a> said:

Pleasant to be going to your web journal yet again, it has been months for me. Well this article ive been sat tight for accordingly long. i need this article to complete my task inside of the staff, and it has same theme together with your article. Much appreciated, pleasant offer.<a href="">Tow Truck Service</a>

February 4, 2019 10:35 AM

buy travel gift voucher said:

Hi I am so charmed I found your online journal, I truly found you by error, while I was watching on google for something else, Anyways I am here now and could simply get a kick out of the chance to say thank for a huge post and an inside and out enlivening site. Kindly do keep up the considerable work.

February 5, 2019 11:06 PM

guelph real estate said:

I hate artifical stuffs so i always do organic gardening at home to get some natural foods~

March 6, 2019 8:39 AM

Johnson City TN Family Practice Clinics said:

Amazing site, Distinguished criticism that I can handle. Im advancing and may apply to my present place of employment as a pet sitter, which is extremely agreeable, yet I have to extra extend. Respects.[url=]Johnson City TN Family Practice Clinics[/url]

March 7, 2019 7:48 PM

Domenic Tylor said:

Students do not write a lengthy dissertation and he always needs a good writer help. Don’t worry, we provide online dissertation writers. We have more then 5000+ writers. We provide our service in Australia. Hire now at

March 13, 2019 10:32 PM

Jessica said:

Get assignment help in Australia in law subject at: and from Student Life saviour at:

March 14, 2019 3:46 AM

Max said:

This post is quite striking and helped me to gain deep understanding of some of my academic topics. I would recommend everyone to choose Assignment Help Australia. You can email us at cs@Myassignmenthelpau.Com or Phone Number: +61-2-8005-8227. For More Details Visit :-

March 19, 2019 12:51 AM

Nikki said:

Best team of masters and Ph.D. degree professionals that understand students requirement and finish all the task properly. Our team is working with a team of native writers from the USA, Ireland, Australia, Singapore, UK, New Zealand, etc. Professional College Assignments Help online is available at For more information:

March 27, 2019 4:37 AM

hary said:

Excellent and nice post. It will beneficial for everyone. Thanks for sharing such a wonderful post. Avail No 1 Essay writing services UK from certified PhD writers. It is extremely helpful for me. You can email us at or Phone Number - 020 8144 9988 .See more :

March 27, 2019 6:12 AM

rodent pest control said:

Youtupedia is a place full of free articles for your blog or website, and info to find places to get beautiful pictures on the web!

April 3, 2019 5:20 AM

Load Cell - Load Cell Systems said:

This substance is composed extremely well. Your utilization of organizing when mentioning your focuses makes your objective facts clear and straightforward. Much obliged to you.

April 4, 2019 12:35 AM

Marie John said:

Order your assignment with Need Assignment. We have expert team for best assignment help in all subjects.

April 5, 2019 4:41 AM

SAM said:

Thank you for bringing to a halt my long search topic. I really benefited from your content.  If you are experiencing trouble striking a balance between your busy academic life and handling your online classes, you can get help from a professional who will take online classes on your behave. It doesn’t matter the kind of help you need, whether it is passing your exam, finishing your assignments or even the entire classwork, you can get help here at  <a href=""> Online Class Help </a>.

March 9, 2020 12:01 AM

kevinwick11 said:

Assignment help Hong Kong reflects inexpensive academic writing for Hong Kong students to finish their assignment without any hindrance. Find experienced academic writer via assignment help and complete your work within deadlines.

April 5, 2020 10:28 PM

Paul said:

Printer devices are widely used to print, scan and fax documents. HP offering different types of printer like LaserJet, OfficeJet and envy printers. Sometimes user unable to print document due to some technical issues or any other reasons. You can avail HP Support Printer to eliminate technical errors from printer device.

April 13, 2020 10:22 PM

lucy said:

Students also don’t have the academic writing expertise which is required to write a better <a href="">law assignment help australia</a> as these assignments follow a structure to convey the message better.

April 19, 2020 11:01 PM

lucy said:

In this structure, the first part is about the issue where students need to explain the issue to readers.

April 19, 2020 11:02 PM

do my assignment for me ireland said:

Our Experts make the best coursework' So, why will do my assignment for me Ireland?' We're pleased you asked. We have a splendid squad of helpers.

April 23, 2020 1:28 AM

assignment maker said:

In limited time we manage to gives you plagiarism free assignment at very nominal cost and that's why is super popular in between Singaporean students. Hire our assignment maker for assignment help services.

April 24, 2020 1:42 AM

SAM said:

Thank you for your outstanding article. I will be your regular visitor. Do you find business law assignments difficult to handle? Do you hate studying business law books? If the answer is yes to any of these questions, then you certainly need  <a href=""> Business Law Assignment Help </a>.

April 29, 2020 1:00 AM

william smith said:

You can get access to different holiday packages, refunds and different destinations to explore by dialing American Airlines Phone Number</a>. Whether it is a last minute obstacle or flight cancellation we can help you assist with every problems you face. So, fell free to call us anytime.

April 29, 2020 11:30 PM

william smith said:

Traveling with Southwest Airlines, your ultra-low-cost air carrier can be lower than it is right now. You must be wondering is that even possible! But with Southwest Airlines Phone Number it is possible. Our team can get you great deals and offers on your bookings to any destinations served by Southwest Airlines.

April 30, 2020 12:18 AM

william smith said:

Air China Official Site offers toll-free service and easily accessible from all around the world. You can call our experts anytime without worries of money deduction.

April 30, 2020 12:30 AM

william smith said:

Come of our Air Canada Airlines Official Site. Loaded with amazing features and functions, visiting our site has advantages and benefits that are unparalleled. Whether you are a economy, business or first class passenger with Air Canada Airlines, our well-tuned deals and packages make it sure that you travel with affordability.

April 30, 2020 12:32 AM

william smith said:

Please ensure that you’re entering the correct details about travelers. It’s recommended to double check everything you input online. It might cost you money in case if you want things corrected later. You will have the option to add baggage while booking online. Same can also be done by Delta Airlines Flights counter at the airport. To avoid any mistake or hassle, it’s recommended to book ticket with Delta Airlines Reservations.

April 30, 2020 2:49 AM

Forwards Homework help online said:

Learners Responsibilities Gives Excellent Forwards Homework help online. Forward is an agreement linking every agent and client. the forward assignment is the responsibility of a writer to give before the deadline.

May 4, 2020 12:42 AM

American Airlines Phone Number said:

No more waiting in long lines of check-in at the airport, just call at American Airlines Phone Number and complete the check-in process 24 hours before departure of the flight. For more info:

May 5, 2020 1:38 AM

Lufthansa Airlines Phone Number said:

There could be several portals through which you may book your tickets but if you are looking for a genuine and authentic platform for booking your tickets, then, you should call Lufthansa Airlines Phone Number. The group is a dedicated service provider that allows you to choose among several deals and offers available by the airline. For more info:.

May 5, 2020 5:35 AM

Allegiant Toll Free Number said:

Call our experts at Allegiant Toll Free Number for a hassle free experience with Allegiant Airlines. For more info:

May 7, 2020 12:39 AM

Emirates Airlines Manage Booking said:

With Emirates Airlines Manage Booking, you will get lots of benefits and flexibility to make a change in your flight easily and conveniently. For more info:

May 7, 2020 4:56 AM

Khalida said:

Windows 10 Activator  Crack Reddit happens to be suitable for your most useful overall performance of Computer.

May 7, 2020 1:58 PM


Hello there, great stuff you’ve shared here I will be checking regularly for more articles. But wait! When it becomes hard to manage your online assignment, availing Online Assignment Help is the best choice. Many students often fail to submit their assignment before deadlines and end up scoring low grades because they didn’t have enough time to write the assignment given on time and satisfactorily. Visit <a href=""> Assignment Help  </a>.  for assistance.

May 9, 2020 2:42 AM

Southwest Airlines Phone Number said:

I appericiate your comments i want to share that Get all data about the flight booking at Southwest Airlines Phone Number, the brisk and proficient helpline helping a large number of travelers.


May 18, 2020 11:02 PM

Delta Airlines Reservations said:

I like the post very much.

For any airline reservations seats, need data about airlines can Book Direct with Delta Airlines.


May 25, 2020 5:56 AM

aviation capstone said:

What a wonderful piece of article I have bookmarked for future checkup. If you are a student and you are interested in designing, developing, producing, operating, and using aircraft, chances are that you are pursuing an aviation course. In most academic institutions, in order for you to graduate in this course, then you must prepare a capstone project. One is supposed to apply the skills taught in this class when writing a capstone paper. Learn more on <a href=""> Aviation Capstone Writing Help </a>.

May 27, 2020 1:09 AM

Maxwillor said: believes in the ability of learning, and translating that learning into rapid actions, which is our ultimate competitive advantage. We cater to all the assignment help needs of the students so that they receive the right guidance towards approaching the assignments, which is a big help for them to move forward in their academics.  You Can Email Us at Or Phone Number: +61-2-8005-8656.  For More Details Visit:-

June 27, 2020 3:43 AM

Leave a Comment

Privacy Statement