Azure SQL Database
An Azure relational database service.
3,550 questions
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Hi Team,
I got below Vulnerabilities for the Azure SQL Managed Instance. Could you please provide the remediation for the VA ?
VA2114 - Minimal set of principals should be members of fixed server roles
Remove members that should not have access to the fixed server roles. After that approve as baseline.
Here are the fixed roles except ##MS_PerformanceDefinitionReader##, ##MS_ServerPerformanceStateReader##, and ##MS_ServerSecurityStateReader#
Here are the fixed roles except ##MS_PerformanceDefinitionReader##, ##MS_ServerPerformanceStateReader##, and ##MS_ServerSecurityStateReader#
I can see we have below server roles except highlighted ones ? can we delete those server roles and will it have any impact if we delete ?
Fixed server roles cannot be removed as per documentation.
Hi Alberto,
I have below logins for sysadmin roles. In that case what will be the exact remediation steps ? whether we need to remove sysadmin roles for these 2 logins ?
Hi Alberto,
I can see we have sysadmin role for the below logins apart from fixed roles. So the remediation is to remove sysadmin roles to these logins ?
Hi Alberto,
we have two logins as sysadmin access. do we need to remove those sysadmin access for the remediation ?
If you agree that they need to be sysadmin then accept it as baseline, otherwise remove them.
Sign in to comment