Why are blocked servers prohibited?

I work in a corporate environment where the creation of linked servers is absolutely prohibited. I asked the database administrator, and the only answer I ever received was "This is a policy." Therefore, I have to write and use SSIS packages to move data between databases when the need arises.

Can someone tell me what reasons could be behind creating such a policy? It seems to me unjustified.

+3
source share
5 answers

The theory goes that if one server is hacked, any linked server will also be automatically compromised.

, , , . , , , .

, , , , , , , db . , db, db, , , .

+7

, , .

+3

Simple. - , " " . ( ) ( A B).

, , , . .

, . , .

+2

. - . , :

​​

, - .

"" - -, , ; . , , DBA . , . , , , .

. , SOA - .

P.S. : SOA , , , SOA fantasy kinda : -)

+2

, .

:

  • " ",

  • " ", sys.server_principals, , NT: ( , )

  • " self" ( " " ), "domain\bob" . , SPN, AD.

:

  • , "syadmin", . , SQL .

OPENDATASOURCE, , adhoc . .

, , . , .

, FWIW.

+1
source

Source: https://habr.com/ru/post/1710163/


All Articles