Is the SA password still hard coded on SQL Server 2019 ?

Goris, Gerrit 20 Reputation points
2023-06-20T14:10:33.7666667+00:00

During an external Cyber Security Audit , it was found by the auditors that the SA account (SQL Server system administrator ) password was hard-coded and could be accessed by unauthorized individuals. Today we use version SQL server 2019, I would like to know if the SA password is still hard-coded ?

We use Mixed Mode (SQL Server authentication and Windows authentication ) .

All info about protection of the SA password is welcome.

Windows for business | Windows Client for IT Pros | User experience | Other
SQL Server | Other
0 comments No comments
{count} votes

Accepted answer
  1. Limitless Technology 44,766 Reputation points
    2023-06-21T12:12:13.19+00:00

    hello there,

    I wish i had another another for this

    In my knowledge cutoff in September 2021, the SA (System Administrator) password is not hard-coded in SQL Server 2019 or any recent versions. When you install SQL Server, you are prompted to set a password for the SA account. It is crucial to choose a strong and secure password to protect your database.

    However, it's worth noting that the SA account is a powerful administrative account with extensive privileges. It is recommended to follow security best practices to safeguard your SQL Server installation, such as:

    Use a complex and unique password for the SA account.

    Limit the number of people who have access to the SA account.

    Regularly review and audit the privileges granted to the SA account.

    And see if it helps,

    Thank you

    --If the reply is helpful, please Upvote and Accept as answer--

    1 person found this answer helpful.
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Olaf Helper 47,441 Reputation points
    2023-06-23T05:25:57.9566667+00:00

    by the auditors that the SA account (SQL Server system administrator ) password was hard-coded

    The password for the SysAdmin account "sa" is and never was hard-coded, you assign the password during installation.

    1 person found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.