News & Opinion

Why Haven’t You Disabled SA? Wrong Answers Only.

On social media, I asked folks, “Why haven’t you disabled the SA account in your SQL Servers? Wrong answers only.” The results were pretty funny:

“I went a step further and also created an account called ‘as’. Now my boss keeps bragging to his golf buddies that we run our database fully SaaS.” – Hugo Kornelis

“How else can I provide job security for the cybersecurity team?” – Evgeny Alexandrovich

Keeping my poker face on

“Because it matches the password of sa.” – Jamie Ridenour

“Oh you can create another account in SQL Server? Mind blown.” – Justin Adrias

“Why would I disable the only login we have?” – Ray FitzGerald

“Because that’s the only account I don’t get permissions errors with!” – Todd Histed

“Because it’s a saved login with password in SSMS.” – Subject 89P13

“Psh. All my linked servers use it.” – Dan White

“Doesn’t SA stand for Software Application? So shouldn’t my application connect with that account?” – Joe Thompson

“Because sa stands for sexy admin. To disable it would be to deny who we are!” – Mladen Prajdic (who, for the record, the ladies love)

Free, 3× a week

Get my new posts by email

Three posts a week, plus a Monday roundup of the best database news from around the web.

31 comments

  1. Because it’s the only account that can do whatever we need to do, and everyone has the password to it and uses it for their daily duties

    1. Before you think it’s a joke, I worked with a customer in the same situation. Plus the username/passwd was admin/admin. No, it wasn’t a small corner shop.

  2. Our vendor requires SA to make the software work.

    Of course, they wanted us to open Port 80 on our firewall so their web interface would work…

  3. Once I was installing MSDE (MS SQL Server 2000 Desktop Engine, for the younger ones) through command line at a customer and it kept failing asking me to provide “a strong SA password”, so I got tired of it and gave it “AStrongSAPassword”… :-p
    Five or six years later the customer called asking about the password… The whole office had a good laugh that day…

  4. My two favorite:

    “Because that’s the only account I don’t get permissions errors with!” – Todd Histed
    “Because it’s a saved login with password in SSMS.” – Subject 89P13

    The first being the most common.

  5. No, no ,no.
    What you do is set up a scott/tiger account then all your devs can migrate from Oracle easily

  6. SA has threatened to leak embarrassing SQL queries I wrote in my early days. I can’t let those skeletons out of the closet!

    1. I always wondered, how his arm strenght really worked, without reinforcing his spine / back / hips etc. so that they wouldn’t crumble when he lifts / throws something really heavy.

    1. I cut off the network cable. Now, it runs not just securely but smoothly. Now I have to cut off the phone cable and change my mobile, and life will be easy. One moment, my boss walked in.

  7. Because it’s been around since SQL Server 6.0 and unlike Microsoft, we subscribe to the practice “if it ain’t broken, don’t fix it!”

  8. Because that’s the account our app uses to connect with. And the end users connect to it with that account from their internet connection to run queries.

Leave a comment

Your email address will not be published. Required fields are marked *

Email me about new comments: