VA2108 - Minimal set of principals should be members of fixed high impact database roles

Rishineken Pongen 176 Reputation points
2023-02-16T07:22:17.59+00:00

Got this alert . VA2108 - Minimal set of principals should be members of fixed high impact database roles and I have attached the screenshot below . The only user id that I see different is bulkadmin. If I'm planning to remove it , how should i go ahead and do it ? Remove all from baseline or would that remove all the db roles present too ?

User's image

Azure SQL Database
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. GeethaThatipatri-MSFT 29,557 Reputation points Microsoft Employee Moderator
    2023-02-21T18:19:58.93+00:00

    Hi, @Rishineken Pongen Thanks for posting your question in the Microsoft Q&A forum.

    I am not quite following. What do you mean “that I see different is bulkadmin”?
    In the results, it only shows db_owner

    What is confusing and wrong though, is that it calls out the dbo-account. That is by design and cannot be changed.in this case, the dbo should be made part of the baseline. however, I will check with the internal team and provide you with more details.

    Regards

    Geetha


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.