Quantcast
Channel: SQLServerCentral » SQL Server 2014 » Administration - SQL Server 2014 » Latest topics
Viewing all articles
Browse latest Browse all 6525

Deny user from running Alter Server Role

$
0
0
Greetings,In testing with SQL 2014, I have found that any user that is granted a server role (default roles) has the ability to add any other defined user within the SQL environment to that same role.Example would be:I assign the diskadmin role to a user. That user now has the ability to assign that role to another user that didn't have it before.The user does not have access to securityadmin, however they can simply script it using alter server role to add the member, and it works.Is there any way to prevent a user from doing this?I've already tried setting the 'Alter any server role' permissions to deny, and it didn't work.I'm not sure what i'm missing.thanks!

Viewing all articles
Browse latest Browse all 6525

Trending Articles