Tag: SQL Server Security
-
DBA Scripts: Get Backup Encryption Status
🔧Part of the DBA-Tools Project, copy/paste SQL Server scripts and health checks.In: Backup & Recovery TDE (Transparent Data Encryption) and backup encryption are two different things that get confused constantly. TDE encrypts the data and log files at rest. It does not automatically encrypt your backups in a way msdb tracks as an encrypted backup…
Written by
-
Creating SQL Logins on an Availability Group (AG) Environment
In an Availability Group, the databases fail over. Your SQL logins do not. For Windows domain logins, the SID is owned by AD, so you just create the login on each replica and it syncs up. For SQL logins, the SID is generated inside SQL Server. If the SID differs between replicas, the database user…
Written by
-
Grant VIEW SERVER STATE in SQL Server
🚨Part of the SQL Server Errors series, the exact messages and what actually causes them.In: Security Msg 300 · Level 14 · State 1 VIEW SERVER STATE permission was denied on object ‘server’, database ‘master’. Msg 297, Level 16, State 1 The user does not have permission to perform this action. ⚡GRANT VIEW SERVER STATE…
Written by
-
Working with SQL Server Database Master Keys
SQL Server uses an encryption hierarchy to protect secrets such as credentials, asymmetric keys and certificates. At the database level, that hierarchy is anchored by the database master key (DMK). Because all other encrypted objects depend on it, losing access to the DMK can render those objects unusable. This post walks through how to: It…
Written by
-
Check SQL Server Connection Encryption and Protocol
Modern SQL Server environments often use encrypted connections by default, but that does not always mean what people think it means. When troubleshooting connectivity problems, certificate errors, performance questions, or unexpected client behaviour, DBAs usually need to answer one very specific question: What protocol and encryption is this connection actually using right now? This post…
Written by
-
SSMS Certificate Chain Not Trusted Error (Trust Server Certificate Fix)
🚨Part of the SQL Server Errors series, the exact messages and what actually causes them.In: Security You upgraded SSMS, sqlcmd or an application driver, and a connection that worked yesterday now fails with this. Nothing changed on the server: the client got stricter, and it now refuses the certificate it used to accept without checking.…
Written by
-
DBA Scripts: Get Database Mail and xp_cmdshell Configuration
🔧Part of the DBA-Tools Project, copy/paste SQL Server scripts and health checks.In: Security An audit or a pen test report asks whether xp_cmdshell is on, or alert emails stopped arriving and you need to know whether Database Mail is even switched on. This script answers both in one result, alongside CLR, force encryption and live…
Written by
- DBA Scripts: Get Log Shipping Status
- SQL Server Row-Level Security: The Filter Does Not Stop Cross-Tenant Writes
- View the Definition of a Stored Procedure in SQL Server
- TempDB Is Full or Still Growing: Find What Is Using It, Right Now
- SQL Server Service Will Not Start: Error 17113, 17058, 1067 and Where the Real Reason Is
- How to Move TempDB Files in SQL Server
- Backups & Recovery (17)
- DBA Scripts (152)
- High Availability (HA) (13)
- Installation & Configuration (49)
- Maintenance (25)
- Migration & Upgrades (14)
- Monitoring (9)
- Performance Tuning (37)
- Security (Encryption & Permissions) (20)
- Storage & Capacity (16)
- T-SQL Fundamentals (15)
- Troubleshooting (94)
- Wait Types (235)