Configuration
The 33 checks in the “Configuration” category of a SQL Server audit: what each one verifies, its severity and the versions covered.
- Checks in this category
- 33
- Weight in the score
- 16
- Breakdown by severity
- 1 critical · 5 high · 8 medium · 8 low · 11 info
Checks in this category
CFG001Max Server Memory
CriticalMax server memory must be configured to leave RAM for the OS
Versions : 2012-2025
CFG004MAXDOP
HighMAXDOP should be configured based on NUMA core count
Versions : 2012-2025
CFG005Priority Boost
HighPriority Boost should be disabled (can cause deadlocks)
Versions : 2012-2025
CFG006Lightweight Pooling
HighLightweight Pooling should be disabled on modern systems
Versions : 2012-2025
CFG013Lock Pages in Memory
HighChecks if Lock Pages in Memory is enabled for the SQL Server service account
Versions : 2012-2025
CFG018Server name mismatch (@@SERVERNAME vs actual network name)
HighCompares @@SERVERNAME (local name in sys.servers server_id=0, not auto-updated) against the real network name SERVERPROPERTY('ServerName'). A mismatch reveals a cloned/renamed host never fixed with sp_dropserver + sp_addserver: silently breaks replication, SQL Agent jobs, linked servers and scheduled backups.
Versions : 2012-2025
CFG003Cost Threshold for Parallelism
MediumDefault value (5) is often too low for OLTP workloads
Versions : 2012-2025
CFG007Remote Admin Connections
MediumRemote DAC (Dedicated Admin Connection) should be enabled
Versions : 2012-2025
CFG010OLE Automation
MediumOLE Automation should be disabled if not used
Versions : 2012-2025
CFG012Optimize for Ad Hoc Workloads
MediumChecks if optimize for ad hoc workloads is enabled to reduce plan cache bloat
Versions : 2012-2025
CFG017Server configuration drift (value <> value_in_use)
MediumFlags sp_configure options whose configured value differs from the running value (value_in_use): RECONFIGURE not run/failed, or a Database Engine restart pending. A silent gap between intended and effective configuration.
Versions : 2012-2025
OPS005Risky / undocumented trace flags
MediumCompares active global trace flags against a known list; unknown flags may alter engine behaviour unexpectedly.
Versions : 2012-2025
QOPT001Legacy CE forced (DB scope)
MediumDetects LEGACY_CARDINALITY_ESTIMATION = ON at database scope, masking the modern cardinality estimator.
Versions : 2016-2025
QOPT003Parameter sniffing disabled
MediumDetects PARAMETER_SNIFFING = OFF at DB scope (equivalent to TF4136), a blunt tool that can degrade good plans.
Versions : 2016-2025
CFG002Min Server Memory
LowMin server memory should be configured appropriately
Versions : 2012-2025
CFG008Default Trace
LowDefault trace should be enabled for diagnostics
Versions : 2012-2025
CFG016Default Fill Factor
LowChecks the default fill factor value at the server level
Versions : 2012-2025
CFG019blocked process threshold (blocked process report)
LowServer-level option 'blocked process threshold (s)' (sys.configurations, value_in_use), in seconds, above which SQL Server emits a blocked process report (consumable by an Extended Events session or an Agent alert). Default = 0: no report produced. The lock monitor only wakes every 5 s, so a value of 1-4 is a misconfiguration (reports are never generated). Classified under 'configuration' as an instance-level setting, not per database.
Versions : 2012-2025
OPS002Number of error logs retained
LowChecks that SQL Server keeps at least 12 ErrorLog files, preserving enough history across recycles.
Versions : 2012-2025
OPS003Default paths off system drive
LowChecks that the default data/log/backup directories are not on the system drive (C:), to avoid filling the OS volume.
Versions : 2012-2025
RG002Resource Governor classifier function
LowChecks the presence and validity (SCHEMABINDING) of the classifier function that routes connections to groups.
Versions : 2012-2025
RG003Resource Governor reconfigure pending
LowDetects is_reconfiguration_pending = 1, signalling pool/group changes that were never applied.
Versions : 2012-2025
CFG009CLR Enabled
InfoCLR should only be enabled if necessary
Versions : 2012-2025
CFG011Trace Flags
InfoVerify active trace flags and their relevance
Versions : 2012-2025
CFG014Max Worker Threads
InfoChecks if max worker threads is set to 0 (auto) or manually configured
Versions : 2012-2025
CFG015Contained Database Authentication
InfoChecks if contained database authentication is enabled
Versions : 2012-2025
OPS004Deprecated features in use
InfoDetects, via the 'Deprecated Features' counter, usage of features slated for removal, to fix before upgrading.
Versions : 2012-2025
OPS006TF 4199 optimizer hotfixes
InfoChecks whether TF 4199 (post-RTM optimizer fixes) is enabled; on 2016+ the DB-scoped QUERY_OPTIMIZER_HOTFIXES option is an alternative.
Versions : 2012-2025
QOPT002MAXDOP overridden at DB scope
InfoInventories databases whose DB-scope MAXDOP overrides the instance setting.
Versions : 2016-2025
QOPT004PSP optimization disabled (2022)
InfoDetects PARAMETER_SENSITIVE_PLAN_OPTIMIZATION = OFF on 2022 (compat 160), usually a regression workaround.
Versions : 2022-2025
QOPT005Compat level blocking IQP
InfoDetects databases whose compatibility level is below the engine default, blocking Intelligent Query Processing features.
Versions : 2012-2025
QOPT006DOP/CE feedback off (2022)
InfoDetects DOP_FEEDBACK or CE_FEEDBACK = OFF on 2022, forgoing self-tuning (requires Query Store read-write).
Versions : 2022-2025
RG001Resource Governor pools/groups
InfoInventories non-default pools and workload groups and how many impose CPU/memory limits.
Versions : 2012-2025
Other categories
- Security 103
- Backups 11
- Reliability 64
- Encryption 14
- Maintenance 33
- Performance 29
- Database Settings 13
- Files 10
- Wait Statistics 9
- Advanced I/O 5
- Advanced Memory 8
- Blocking & Deadlocks 8
- Agent 8
- Query Store 8
- Linked Servers 5
- Capacity 9
- Updates 7
- Hardware 10
- Top Queries 7
- Stored Procedures 4
- Connections 6
- Extended Events 4
- Database Mail 3
- Database Level 7