A quarterly permission review checks server and database roles, new grants, orphaned users, service accounts, and owner signoff.
Auditing Who Has sysadmin
Audit who has sysadmin in SQL Server, including direct members and Windows groups, then investigate nested access and forgotten logins.
Auditing Who Holds CONTROL SERVER and IMPERSONATE Rights
Audit CONTROL SERVER and impersonation grants alongside sysadmin and role inheritance, test effective rights, and remove excess access.



