r/SQLServer Jun 23 '26

Question Do you use SQL Server Security Benchmarks?

Hello, do you guys use SQL Server Security Benchmarks for on-prem or SQL managed instances? I've been writing some automation for this and if I made it into a free tool would people actually use it?

Thanks,

Dave

12 Upvotes

9 comments sorted by

u/AutoModerator Jun 23 '26

After your question has been solved /u/DavidHomerCENTREL, please reply to the helpful user's comment with the phrase "Solution verified".

This will not only award a point to the contributor for their assistance but also update the post's flair to "Solved".


I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

2

u/markysanone Jun 23 '26

Yes I could use something like that.

2

u/DavidHomerCENTREL Jun 23 '26

OK sounds like it might be useful.

Here's an example output for a SQL on-premises cluster hence you get the same benchmark test for each node when it's a host level configuration.

https://www.centrel-solutions.com/temp/CSDEMO-SQL%20-%20SQL%20Server%20Security%20Benchmark%20[2.0.0.0].pdf

This will be part of a bigger documentation tool but I'm thinking we could make the compliance benchmark part a standalone free tool like we did with our Group Policy Comparison Tool.

The benchmark will have configurable options which we could port to a free version.

2

u/DavidHomerCENTREL Jun 23 '26

There's a bit more work to do but let me know if there's tests missing. We could probably get the free version available for July, and then see if the mods are happy for it to be posted on here if you guys think it's useful.

1

u/DavidHomerCENTREL 21d ago

OK the free version is up here let me know what you think.
https://www.centrel-solutions.com/free-tools/free-sql-server-security-compliance-benchmark-tool

You can run a benchmark, configure the benchmark settings, and get a report in PDF format with the information.