• Do you want to prevent people from attaching data files, or from copying data files off the machine?

    For the first, don't give db_creator rights to anyone. Sysadmins can do in, no one else should (unless you really trust them)

    For the second, ensure no one but the server admins have access to the physical machine. No shares, no login permissions, no file system access. Ensure than no one but the server admins and sysadmins have the rights to stop the SQL service

    Plus very strong admin passwords.

    Gail Shaw
    Microsoft Certified Master: SQL Server, MVP, M.Sc (Comp Sci)
    SQL In The Wild: Discussions on DB performance with occasional diversions into recoverability

    We walk in the dark places no others will enter
    We stand on the bridge and no one may pass