A Few Best Practices for Strong SQL Server Security

  • -- Create a login with a strong password
    CREATE LOGIN [NewUser] WITH PASSWORD = 'StR0nG_p@ssW0rd!';

    I am not sure SQL Server authentication represents best practice but I suspect it is used a lot due to slow AD connections, Kerberos double-hop problems, non-Windows applications etc. Maybe at least try to have a CA certificate on the server to avoid MITM attacks. As most organizations now have their own CA certificate servers, this should not be as awkward as it used to be.


