A quarterly permission review checks server and database roles, new grants, orphaned users, service accounts, and owner signoff.
Least Privilege for Application Logins
Design least privilege for SQL Server application logins with roles, schema permissions, and stored procedures, then test real workflows.
Auditing Who Has sysadmin
Audit who has sysadmin in SQL Server, including direct members and Windows groups, then investigate nested access and forgotten logins.
SQL SERVER – Enable Login – Disable Login using ALTER LOGIN – Change name of the ‘SA’
Use ALTER LOGIN in SQL Server 2005 to disable or enable any login, including ‘sa’, and to rename the SA account to a name that is hard to guess.
Auditing Who Holds CONTROL SERVER and IMPERSONATE Rights
Audit CONTROL SERVER and impersonation grants alongside sysadmin and role inheritance, test effective rights, and remove excess access.





