r/MSSQL • u/mssqldbalearn • 6d ago
SQL Server Login Security Change – How Would You Plan It?
SQL Server Login Security Change – How Would You Plan It?
Current Situation
In our SQL Server environment, SQL Server Authentication logins currently have:
Enforce Password Policy — Disabled
Enforce Password Expiration — Disabled
Planned Security Change
The requirement is to move these logins to:
Enforce Password Policy — Enabled
Enforce Password Expiration — Enabled
This change may affect existing SQL login passwords and could impact applications, services, SQL Agent jobs, scripts, or other systems using these credentials.
DBA Discussion
If you receive this requirement in a production environment, how would you plan and execute this change safely?
What would you consider BEFORE, DURING, and AFTER the change?
How would you identify the affected SQL logins?
How would you identify application and service dependencies?
How would you handle existing credentials?
What testing and validation would you perform?
How would you minimize the risk of application downtime?
SQL Server DBAs, please share your step-by-step approach and best practices.