SV-213988r617437_rule
V-213988
SRG-APP-000380-DB-000360
SQL6-D0-011500
CAT II
10
Remove users from the local Administrators group who are not authorized.
Obtain a list of users who have privileged access to the server via the local Administrators group.
Launch lusrmgr.msc
Select Groups
Double-click Administrators
Alternatively, execute the following command in PowerShell:
net localgroup administrators
Check the server documentation to verify the users returned are authorized.
If the users are not documented and authorized, this is a finding.
V-213988
False
SQL6-D0-011500
Obtain a list of users who have privileged access to the server via the local Administrators group.
Launch lusrmgr.msc
Select Groups
Double-click Administrators
Alternatively, execute the following command in PowerShell:
net localgroup administrators
Check the server documentation to verify the users returned are authorized.
If the users are not documented and authorized, this is a finding.
M
3993