/
Quick Start Guide: Non-Domain Joined MS SQL Database Scanning (GUI)

Quick Start Guide: Non-Domain Joined MS SQL Database Scanning (GUI)

Overview

This guide will walk through scanning a non-domain joined Microsoft SQL Database using CIS-CAT Pro Assessor v4. If the Database is domain joined, please see the this guide: Quick Start Guide: MSSQL Database Scanning w/ Integrated Security (GUI)

Requirements

Implementation Steps

  1. Change Server Authentication Mode in SSM

    1. In SQL Server Management Studio Object Explorer, right-click the server, and then click Properties.

    2. On the Security page, under Server authentication, select the SQL Server and Windows Authentication mode, and then click OK.

    3. In the SQL Server Management Studio dialog box, click OK to acknowledge the requirement to restart SQL Server.

    4. In Object Explorer, right-click your server, and then click Restart. If SQL Server Agent is running, it must also be restarted.

 

2. For a local assessment, use the following JDBC string format (Using a SQL admin account):

jdbc:sqlserver://hostname;user=MyUserName;password=******;

For a remote assessment, use the following JDBC string format (Using a SQL admin account):

jdbc:sqlserver://CIS-SERVER:1433;databaseName=TestDB;user=db_user;password=db_pass;instanceName=TestInstance;

3. Run the assessment using the GUI or CLI. See this section of the documentation for Workflow steps

Troubleshooting Steps

If the scan is unsuccessful, check the SQL logs for a ’Login failed for user' message that matches the username in your JDBC string. Here’s a way to get SQL logs: View the SQL Server error log (SSMS) - SQL Server

See the this section of the documentation for more information on JDBC string structure:
https://ciscat-assessor.docs.cisecurity.org/en/latest/Configuration%20Guide/#database-assessment


 

Copyright © 2022 Center for Internet Security® Privacy Policy

 


Related content

Quick Start Guide: MSSQL Database Scanning w/ Integrated Security (GUI)
Quick Start Guide: MSSQL Database Scanning w/ Integrated Security (GUI)
More like this
Minimum login permissions for SQL assessment
Minimum login permissions for SQL assessment
More like this
Quick Start Guide: Tailoring Benchmarks
Quick Start Guide: Tailoring Benchmarks
Read with this
CIS-CAT Pro Assessor GUI v4.2.0 SQL 2019 connection problems
CIS-CAT Pro Assessor GUI v4.2.0 SQL 2019 connection problems
More like this
Quick Start Guide: CIS Windows Build Kits
Quick Start Guide: CIS Windows Build Kits
Read with this
SQL Server Authentication issues in CIS-CAT Pro Assessor
SQL Server Authentication issues in CIS-CAT Pro Assessor
More like this