<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://sqlblog.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>It’s 2011: Do you know where your SA credentials are?</title><link>http://sqlblog.com/blogs/merrill_aldrich/archive/2011/07/12/it-s-2011-do-you-know-where-your-sa-credentials-are.aspx</link><description>Today I am assisting a vendor with an upgrade / migration, as is very common in my work. I am amazed to still see the following practices in place with software vendors, even today, even after so many well-publicized data breaches. We’ve done what we</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP2 (Build: 61129.1)</generator><item><title>re: It’s 2011: Do you know where your SA credentials are?</title><link>http://sqlblog.com/blogs/merrill_aldrich/archive/2011/07/12/it-s-2011-do-you-know-where-your-sa-credentials-are.aspx#36846</link><pubDate>Tue, 12 Jul 2011 22:17:09 GMT</pubDate><guid isPermaLink="false">21093a07-8b3d-42db-8cbf-3350fcbf5496:36846</guid><dc:creator>Davide Mauri</dc:creator><description>&lt;p&gt;I like the option 3. Vendor must understand that as DBA is our duty check that security is not compromised in any way, ever. No way I'm going to enable &amp;quot;sa&amp;quot; anymore. &lt;/p&gt;
</description></item><item><title>re: It’s 2011: Do you know where your SA credentials are?</title><link>http://sqlblog.com/blogs/merrill_aldrich/archive/2011/07/12/it-s-2011-do-you-know-where-your-sa-credentials-are.aspx#36849</link><pubDate>Tue, 12 Jul 2011 23:15:31 GMT</pubDate><guid isPermaLink="false">21093a07-8b3d-42db-8cbf-3350fcbf5496:36849</guid><dc:creator>Josh Feierman</dc:creator><description>&lt;p&gt;Couldn't agree more here. I hate it when vendors are lazy and just demand blanket sysadmin rights. It's even more inexcusable to demand THE sa account.&lt;/p&gt;
&lt;p&gt;I've sworn in front of people that if I ever own an ISV my software will make administrators (as well as business people) smile, not cringe.&lt;/p&gt;
</description></item><item><title>re: It’s 2011: Do you know where your SA credentials are?</title><link>http://sqlblog.com/blogs/merrill_aldrich/archive/2011/07/12/it-s-2011-do-you-know-where-your-sa-credentials-are.aspx#36873</link><pubDate>Wed, 13 Jul 2011 08:36:41 GMT</pubDate><guid isPermaLink="false">21093a07-8b3d-42db-8cbf-3350fcbf5496:36873</guid><dc:creator>Peter</dc:creator><description>&lt;p&gt;Have a look at Microsoft Dynamics CRM which needs the sysadmin role and to be in the local administrators group on the database server while a new organization database is created.&lt;/p&gt;
</description></item><item><title>re: It’s 2011: Do you know where your SA credentials are?</title><link>http://sqlblog.com/blogs/merrill_aldrich/archive/2011/07/12/it-s-2011-do-you-know-where-your-sa-credentials-are.aspx#36878</link><pubDate>Wed, 13 Jul 2011 12:44:12 GMT</pubDate><guid isPermaLink="false">21093a07-8b3d-42db-8cbf-3350fcbf5496:36878</guid><dc:creator>eccentricDBA</dc:creator><description>&lt;p&gt;I agree. My major issue is the number of products produced by Microsoft that does this. It would be great if someone would start a website that would document that rights required for these applications or at least list the applications the applications that either do things right or wrong. &amp;nbsp;It would help when performing application selection.&lt;/p&gt;
&lt;p&gt;Honestly, I would be a fan of saying any application that is &amp;quot;black&amp;quot; listed it is automatically removed during the application selection process.&lt;/p&gt;
</description></item><item><title>re: It’s 2011: Do you know where your SA credentials are?</title><link>http://sqlblog.com/blogs/merrill_aldrich/archive/2011/07/12/it-s-2011-do-you-know-where-your-sa-credentials-are.aspx#36912</link><pubDate>Wed, 13 Jul 2011 22:33:49 GMT</pubDate><guid isPermaLink="false">21093a07-8b3d-42db-8cbf-3350fcbf5496:36912</guid><dc:creator>merrillaldrich</dc:creator><description>&lt;p&gt;@Peter - I know, right? I've done that one. MS is also an offender, though less often.&lt;/p&gt;
</description></item><item><title>re: It’s 2011: Do you know where your SA credentials are?</title><link>http://sqlblog.com/blogs/merrill_aldrich/archive/2011/07/12/it-s-2011-do-you-know-where-your-sa-credentials-are.aspx#37004</link><pubDate>Sun, 17 Jul 2011 15:49:51 GMT</pubDate><guid isPermaLink="false">21093a07-8b3d-42db-8cbf-3350fcbf5496:37004</guid><dc:creator>magasvs</dc:creator><description>&lt;p&gt;Another Microsoft application that requires sysadmin role is SCCM. &lt;/p&gt;
</description></item></channel></rss>