UDL files with TRUSTED authentication - a security risk?

By chuckboycejr, 2012/10/18

Hi everyone,

So the other day on twitter in #sqlhelp and privately with some friends at Microsoft and elsewhere I had a lively and surprising conversation about UDL files.

We all know that we should be using Windows authentication, but if you're an Ops DBA like me you know that there are p-l-e-n-t-y of legacy systems and (sadly) even modern day vendors that have applications that rely on SQL Server (or non-trusted) authentication.

