Weak passwords are like a key under the door mat. Brian Kelley explains what auditors look for around passwords and exceptions in database security.
SQL SERVER – What Permissions I have on Database I am Connected to?
When I get access to a new server, I first check the permissions I have on the database. One simple query with fn_my_permissions shows the full list.
Granular Server Roles: ##MS_ServerStateReader## and Friends
Assign granular server roles in SQL Server 2022, inspect membership, and give monitoring accounts the state access their queries need.
Auditing Failed Logins With the Error Log and Extended Events
Investigate failed logins with the SQL Server error log and a focused Extended Events session, then group attempts and decide what to do.
Database Security Basics for a Small Business
Database security basics for a small business cover patching, off-site backups, strong logins, limited access, and encryption that works.
Connecting to SQL Server From Home Without Exposing Port 1433
Keep port 1433 off the public internet by checking external reachability and using VPN, a jump host, Bastion, and trusted encryption.
Auditing WITH GRANT OPTION: Who Can Hand Out Permissions
Audit WITH GRANT OPTION at database and server scope, trace delegated permissions, and remove delegation with a reviewed CASCADE plan.







