Description
SQL Server’s remote access is a legacy setting controlling stored procedure execution between servers. It does not block ordinary client network connections. Disable server-to-server execution paths that are unnecessary.
Potential impact
Unneeded remote procedure execution can increase the reach of misused permissions on connected servers.
Remediation
Check linked-server and job dependencies, then set remote access to off in settings.database_flags if it is unnecessary. Plan the required restart and manage ordinary connection paths through separate network policies.
Examples
These excerpts show a configuration that does not require remote procedure execution between servers. Other required instance settings are omitted.
Before
hcl
resource "google_sql_database_instance" "sqlserver_instance" {
name = "sqlserver-instance"
database_version = "SQLSERVER_2017_STANDARD"
region = "us-central1"
settings {
database_flags {
name = "remote access"
value = "on"
}
}
}
After
hcl
resource "google_sql_database_instance" "sqlserver_instance" {
name = "sqlserver-instance"
database_version = "SQLSERVER_2019_STANDARD"
region = "us-central1"
settings {
database_flags {
name = "remote access"
value = "off"
}
}
}