Remove NT AUTHORITY\SYSTEM from sysadmin role - sql 2008 r2

This topic was somewhat covered for SQL server 2005, I couldn't find any on 2008 R2, so asking again.
I have NT AUTHORITY\SYSTEM, NT SERVICE\MSSQLSERVER and NT SERVICE\MSSQLSERVER$AGENT accounts in sql server sysadmin role on all my servers. SQL Server service and sql server agent service are running under different Active directory service accounts
accounts, not the last two mentioned above.
How do I remove these accounts from sysadmin role without breaking anything? Can anyone provide documentations addressing this problem specific for SQL server 2008 R2? If you know any reasons for I should not attempt to remove them,
please point me to the 2008 r2 specific documentation. These came up in security audit and I have to provide specific docs.
Thanks In advance.
Mars

Hi,
I recommend you not to remove NT AUTHORITY\SYSTEM, NT SERVICE\MSSQLSERVER and NT SERVICE\MSSQLSERVER$AGENT accounts from sysadmin role in SQL Server 2008 R2.
NT AUTHORITY\SYSTEM is a very high-privileged built-in account. It has extensive privileges on the local system and acts as the computer on the network.
The Database Engine runs in Windows as a Windows service named MSSQLSERVER. The NT SERVICE\MSSQLSERVER login is used by the service to connect to the Database Engine. The SQL Server Agent runs as a Windows service named NT SERVICE\SQLSERVERAGENT. The NT SERVICE\SQLSERVERAGENT
login is used by the SQL Server Agent service to connect to the Database Engine. The two logins act as a Security Identifier (SID) for the two services respectively in Windows, and they are members of the sysadmin fixed server role in SQL Server, so they can
do anything in the Database Engine.
For more details, please review the following links:
Setting Up Windows Service Accounts:http://msdn.microsoft.com/en-us/library/ms143504(v=sql.105).aspx
How to Create Secure SQL Server Service Accounts:http://www.mssqltips.com/sqlservertip/2503/how-to-create-secure-sql-server-service-accounts/
Thanks
Lydia Zhang

Similar Messages

  • How do i remove the authorized signature from a certificate widget on captivate 8?

    Does anyone know how to remove the authorized signature from a certificate widget on captivate 8?
    or
    How to build my own widget to include quiz results/score and print widget?

    Strange workaround, but just checked it and it works (even for responsive project): you can drag the Signature, I dragged it as far out as possible (to the bottom) and when previewing the Certificate it was gone.
    Do you need a widget? It is not that easy if you need it both for SWF and HTML output because I'm aware at this moment of only very few widgets available on the market. You can create a slide with all you need, using the quizzing system variables and a button with a JS to print?
    Maybe some inspiration here: Intermediate Score Slides - Captivate blog

  • How do I remove an authorized computer from my itunes account? I am only using one.

    How do I remove an authorized computer from my itunes account? I am only using one.

    http://support.apple.com/kb/PH12303
    Barry

  • How we can remove  one authorization object from multiplt roles

    How we can remove one authorization object from multiplt roles

    > Correct me if I am wrong !!
    O.K., Here I go
    > But if the object is maintained in SU24 and if you use Expert mode for generation of the role then again those objects may be pulled.(make sure you never use expert mode once you delete the objects)
    Actually using expert mode and choosing 'edit old status' is the only way to avoid objects being 'pulled in' after menu changes.
    > As jurjen said, you may download the tables and instead of deleting the object from the excel sheet, change the value of the object in column "DELETED" = X, by doing this only the objects get inactivated(but remain in PFCG).
    I am not speaking of downloading tables but about downloading roles from PFCG. This will not get you a spreadsheet but a flat textfile. If you whish to set the object status to deleted you'll have to swap the space on position 207, right behind the 'U, S, G' flag,  with an 'X' for all corresponding lines.
    Jurjen

  • Access a view on a 32 bit Oracle 9i  from a MS SQL 2008 R2 64 bit

    NOt sure if this is the right forum for this.
    We need to access a view on a 32 bit Oracle 9i - Release 9.2.0.8.0 database running on Windows 2003 Server, from a MS SQL 2008 R2 64 bit system running on Windows Server 2008 64 bit.
    Edited by: 854859 on Apr 26, 2011 3:21 PM

    When yu want to access a view hosted in Oracle and retrieve data from this view in a MS SQl Server, then you need to use MS SQL Server Linked Server mechanism based on OLEDB/ODBC.
    Since MS SQL Server this feature is integrated in MS Integration Services and more details can be found at the MS knowledge base.

  • Removed all members from SysAdmin on SQL 2000

    Aloha
    I had a faulty script that unfortunately removed all members from the SysAdmin role. Unfortunately, I cannot reinstall the instance and I only have short windows of opportunity for downtime.
    I understand if I can get the database into single user mode and log in I can add a new local account to the database with the sysadmin role, however I can't seem to get logged into the single user mode. It keeps saying "Login failed for user '<MYUSERACCOUNT>'.
    Reason: Server is in single user mode. Only one administrator can connect at this time.
    I have the SQL agent shut down, I am not running enterprise manager and, as far as I can tell, there are no other admins connecting to the system. I know with newer SQL versions one can limit the single user mode to only accept SQLCMD. Of course, 2000 doesn't
    have SQLCMD but has OSQL. Any thoughts on how I can limit the access during this maintenance? I've even tried to remove both named pipes and TCP/IP from the accepted connection types but that didn't seem to make a difference.
    Thoughts? Please?

    I'm a little rusty on SQL Server 2000. Sorry if this advise is useless.
    What account are you using to start the Database Engine. If not networkservice, then connect as that account. Try change the account to a local computer account, and then use that account. The general principal here, is that the account running the database
    engine service, can connect.
    Rick Byham, Microsoft, SQL Server Books Online, Implies no warranty

  • Why Oracle removed "Create View" privilege from "Resource" role?

    Seems like a silly question, but does anyone know why?

    >
    Hm.. deprciated and replaced by what? I know they trimmed CONNECT a lot but only create view seemed missing from RESOURCE.
    >
    Replaced by NOTHING. They didn't just 'trim' CONNECT; it only has the CREATE SESSION privilege now.
    The only published info I've seen are these two notes in the Oracle is this from the Database Security Guide.
    http://docs.oracle.com/cd/B28359_01/network.111/b28531/authorization.htm
    >
    Note:
    Each installation should create its own roles and assign only those privileges that are needed, thus retaining detailed control of the privileges in use. This process also removes any need to adjust existing roles, privileges, or procedures whenever Oracle Database changes or removes roles that Oracle Database defines. For example, the CONNECT role now has only one privilege: CREATE SESSION. Both CONNECT and RESOURCE roles will be deprecated in future Oracle Database releases.
    Note:
    Customers should discontinue using the CONNECT and RESOURCE roles, as they will be deprecated in future Oracle Database releases. The CONNECT role presently retains only the CREATE SESSION privilege.

  • How to remove number of systems from collections.

    Is there any way to remove a couple of hostnames from sccm 2007 collection?

    This query based think is we have migrated the win xp systems and also the hostnames are deleted from AD but still the hostnames are reflecting in collection and it's showing the systems amount is more than the original amount. But manually deleting
    one by one is very complicated.  so I am searching some shortcut methods.
    Computers will be removed from CM07 after 90 days. You only other ton is to manually delete each computer from CM07.
    Garth Jones | My blogs: Enhansoft and
    Old Blog site | Twitter:
    @GarthMJ

  • Cancel or Remove a backup to a database in SQL 2008 R2

    I got it, duh it was in the SQL server Agent, just disabled it. Thanks for the help anyways. 

    Need to delete or disable a configured database backup job on SQL Server 2008 R2. 
    Configured it in two places, one through the Maintenance Plan and the other one was done by right-clicking the " database" -->selecting Tasks-->Back up and Set a Schedule to run every 2 hours. I need this one canceled or removed and it won't allow me, I went back in and set the schedule to backup for only one day and it still did not stop.
    Any Ideas, just want to keep the one created in the Maintenance Plan?
    Thanks 
    This topic first appeared in the Spiceworks Community

  • How do I remove a white background from clipart in PowerPoint 2008 for Mac?

    I have several clip arts that are in .jpeg and .png format.  These are of somewhat irregular shapes, and are on a white background.  I want to eliminate the white background so that I can use these clip arts on colored backgrounds.  I know that there is a simple way to do this in MS PowerPoint 2008 for Mac, but I've forgotten how.  Can anyone help?  Time is of the essence.  Thanks in advance.  - Mark

    I still use Office 2008 but have not encountered that issue. However, as Office is not an Apple product, I strongly recommend asking in the Microsoft Office:Mac forums here:
    Office for Mac
    Everyone there is a Mac user AND an Office user, something you can't say about Apple's forums. You will get the fastest help there and I think you will find the contributors more than helpful.

  • BDC to PFCG (Delete Authority Objects from Roles.)

    When we try to change an authority object it gives an error message saying that 'This authority object is used in roles XXX'.
    To remove Authority Ojects from roles, transaction PFCG is used. But the problem is that BDC is almost impossible to PFCG.
    Is there any way you can suggest us to change an authority object when it is assigned to a role or how we can BDC delete authority object from a role or a function/badi we can call to achieve this.
    This is a very high level question.

    Hi
    U should consider PFCG trx is enjoy trx so it's not suitable for BDC, what doesn't mean you can't do a BDC program for that trx but it won't be easy.
    Anyway you can know the users assigned to certain profile reading table AGR_USERS. I believe PFCG shows them sorted alphabetical, so you can know the position where an user should be, after u should use PAGE UP and PAGE DOWN command to scroll the table control.
    Max

  • How to remove Production System from Solution manager.

    Hi All,
    We have Three system landscape and solution manager installed.
    All the system are managed by Solution manager.
    here we are looking to remove the Production System from Solution manager.
    as in case if is there any problem in solution manager then we are not dependent on it.
    things will work directly on Production system.
    Could you please let us know the procedure to remove the system from solution manager.
    Please let us know if is there any document provided by SAP.

    Hi,
    Have you implemented charm,ccms monitoring or any other functionalities?
    if yes,.Delete the sytem from tms domain. and TR route needs to be adjusted, if you are using ccms, remove the agent details from RZ21 also.
    Does your production system data coming from SLD?
    if yes, Delete the entry from SLD
    if both the answer is no.
    1.delete  RFC from SOLMAN to the production systems.
    2. delete the production system using SMT2 transaction.
    3. Remove system rom SMSY from SOLMAN.
    Thanks,
    Jansi

  • Unable to Remove group from the Role

    Hi Team,
    I am having an issue in removing the “AAAAAA” group from the Role (BBBBBB) in OBIEE11g EM.
    I am getting an error like below when I remove the group. Please help me to solve this issue.
    Error Codes
    Error :0>= 0
    Kind Regards,
    Mohan

    Restart the services and try removing,It will work.
    Thanks,

  • PowerPivot/Excel Services from SQL 2008 R2

    I am currently setting up a SharePoint 2013 instance. At my company we have an existing SQL Server 2008 R2 (SP1) installation with SSAS, which users are currently accessing with Excel 2010 & 2013 PowerPivot.
    Is it possible to access the Analysis Services from this existing SQL 2008 R2 server from SP 2013? If so, is there anything that needs to be installed on this box? (Or is it the case that I really can't use SQL Server 2008 with SP 2013 Excel Services?)

    Yes, it is possible. It's just like any other external data sources you access from within SharePoint using the different service applications - Excel Services, Reporting Services, PowerPivot, PerformancePoint, etc. However, if you will be using Analysis
    Services in SharePoint mode, this requires SQL Server 2012 with SP1
    Edwin Sarmiento SQL Server MVP | Microsoft Certified Master
    Blog |
    Twitter | LinkedIn
    SQL Server High Availability and Disaster Recover Deep Dive Course

  • Remove all budget entry from non-sysadmin users

    Hi,
    is there any non-customisation way of removing all budget entry from standard users (non-sysadmin).
    I know it is simple enough to remove menus from standard menus, but is there anyway of preventing budgets being created via ADI also?
    We have moved to an external budgeting system and I need to ensure that the only budget entries loaded into E-Business are from this one source.
    thanks for any tips,
    Robert.

    In SQL 2005+, a new right was added to allow users to run their own jobs. However, you still need to be a sysadmin to run jobs which are not owned by you.
    Tom this is not correct . A member of SQLAgentOperator role can execute local jobs even though it is not a owner of the job but this user can only create modify and delete jobs owned by him not by others.
    http://technet.microsoft.com/en-us/library/ms188283.aspx
    Please mark this reply as the answer or vote as helpful, as appropriate, to make it useful for other readers

Maybe you are looking for