<SecScan ID="0" DisplayName="domain\Test" Machine="Test" Date="2021-04-29 14:37:36" LDate="29/04/2021 14:37" Domain="domain" IP="192.168.1.10" Grade="1" HotfixDataVersion="Security updates scan not performed" MbsaToolVersion="2.2.2170.0" IsWorkgroup="False" SUSServer="http://wsus:8530" HFFlags="4" SecurityUpdatesScanDone="False" WUSSource="Windows Server Update Services" IsCSAMode="false">
	<IPList><IP addr="00000000" /></IPList>
	<AdditCabs><Cab Prop="" /></AdditCabs>
	<Check ID="104" Grade="5" Type="1" Cat="1" Rank="1" Name="Local Account Password Test" URL1="Help/Check5315.html" URL2="Help/Check5315fix.html" >
		<Advice>Some user accounts (2 of 24) have blank or simple passwords, or could not be analyzed.</Advice>
		<Detail>
			<Head>
				<Col>User</Col>
				<Col>Weak Password</Col>
				<Col>Locked Out</Col>
				<Col>Disabled</Col>
			</Head>
			<Row Grade="0">
				<Col>DefaultAccount</Col>
				<Col>Weak</Col>
				<Col>-</Col>
				<Col>Disabled</Col>
			</Row>
			<Row Grade="0">
				<Col>Guest</Col>
				<Col>Weak</Col>
				<Col>-</Col>
				<Col>Disabled</Col>
			</Row>
			<Row Grade="0">
				<Col>WDAGUtilityAccount</Col>
				<Col>-</Col>
				<Col>-</Col>
				<Col>Disabled</Col>
			</Row>
			<Row Grade="5">
				<Col>Administrator</Col>
				<Col>-</Col>
				<Col>-</Col>
				<Col>-</Col>
			</Row>
			<Row Grade="5">
				<Col>MSSQLSERVER01</Col>
				<Col>-</Col>
				<Col>-</Col>
				<Col>-</Col>
			</Row>
			<Row Grade="5">
				<Col>MSSQLSERVER02</Col>
				<Col>-</Col>
				<Col>-</Col>
				<Col>-</Col>
			</Row>
			<Row Grade="5">
				<Col>MSSQLSERVER03</Col>
				<Col>-</Col>
				<Col>-</Col>
				<Col>-</Col>
			</Row>
			<Row Grade="5">
				<Col>MSSQLSERVER04</Col>
				<Col>-</Col>
				<Col>-</Col>
				<Col>-</Col>
			</Row>
			<Row Grade="5">
				<Col>MSSQLSERVER05</Col>
				<Col>-</Col>
				<Col>-</Col>
				<Col>-</Col>
			</Row>
			<Row Grade="5">
				<Col>MSSQLSERVER06</Col>
				<Col>-</Col>
				<Col>-</Col>
				<Col>-</Col>
			</Row>
			<Row Grade="5">
				<Col>MSSQLSERVER07</Col>
				<Col>-</Col>
				<Col>-</Col>
				<Col>-</Col>
			</Row>
			<Row Grade="5">
				<Col>MSSQLSERVER08</Col>
				<Col>-</Col>
				<Col>-</Col>
				<Col>-</Col>
			</Row>
			<Row Grade="5">
				<Col>MSSQLSERVER09</Col>
				<Col>-</Col>
				<Col>-</Col>
				<Col>-</Col>
			</Row>
			<Row Grade="5">
				<Col>MSSQLSERVER10</Col>
				<Col>-</Col>
				<Col>-</Col>
				<Col>-</Col>
			</Row>
			<Row Grade="5">
				<Col>MSSQLSERVER11</Col>
				<Col>-</Col>
				<Col>-</Col>
				<Col>-</Col>
			</Row>
			<Row Grade="5">
				<Col>MSSQLSERVER12</Col>
				<Col>-</Col>
				<Col>-</Col>
				<Col>-</Col>
			</Row>
			<Row Grade="5">
				<Col>MSSQLSERVER13</Col>
				<Col>-</Col>
				<Col>-</Col>
				<Col>-</Col>
			</Row>
			<Row Grade="5">
				<Col>MSSQLSERVER14</Col>
				<Col>-</Col>
				<Col>-</Col>
				<Col>-</Col>
			</Row>
			<Row Grade="5">
				<Col>MSSQLSERVER15</Col>
				<Col>-</Col>
				<Col>-</Col>
				<Col>-</Col>
			</Row>
			<Row Grade="5">
				<Col>MSSQLSERVER16</Col>
				<Col>-</Col>
				<Col>-</Col>
				<Col>-</Col>
			</Row>
			<Row Grade="5">
				<Col>MSSQLSERVER17</Col>
				<Col>-</Col>
				<Col>-</Col>
				<Col>-</Col>
			</Row>
			<Row Grade="5">
				<Col>MSSQLSERVER18</Col>
				<Col>-</Col>
				<Col>-</Col>
				<Col>-</Col>
			</Row>
			<Row Grade="5">
				<Col>MSSQLSERVER19</Col>
				<Col>-</Col>
				<Col>-</Col>
				<Col>-</Col>
			</Row>
			<Row Grade="5">
				<Col>MSSQLSERVER20</Col>
				<Col>-</Col>
				<Col>-</Col>
				<Col>-</Col>
			</Row>
		</Detail>
	</Check>
	<Check ID="10500" Grade="1" Type="5" Cat="1" Rank="1" Name="Security Updates" >
		<Advice>No result data. (0x80070002)</Advice>
	</Check>
	<Check ID="10101" Grade="4" Type="1" Cat="2" Rank="15" Name="Windows Version" URL1="Help/Check53117.html" >
		<Advice>Computer is running Microsoft Windows Unknown.</Advice>
	</Check>
	<Check ID="102" Grade="5" Type="1" Cat="1" Rank="3" Name="File System" URL1="Help/Check5313.html" URL2="Help/Check5313fix.html" >
		<Advice>All hard drives (5) are using the NTFS file system.</Advice>
		<Detail>
			<Head>
				<Col>Drive Letter</Col>
				<Col>File System</Col>
			</Head>
			<Row Grade="5">
				<Col>C:</Col>
				<Col>NTFS</Col>
			</Row>
			<Row Grade="5">
				<Col>E:</Col>
				<Col>NTFS</Col>
			</Row>
			<Row Grade="5">
				<Col>G:</Col>
				<Col>NTFS</Col>
			</Row>
			<Row Grade="5">
				<Col>R:</Col>
				<Col>NTFS</Col>
			</Row>
			<Row Grade="5">
				<Col>S:</Col>
				<Col>NTFS</Col>
			</Row>
		</Detail>
	</Check>
	<Check ID="106" Grade="3" Type="1" Cat="1" Rank="8" Name="Password Expiration" URL1="Help/Check5317.html" URL2="Help/Check5317fix.html" >
		<Advice>Some user accounts (23 of 24) have non-expiring passwords. </Advice>
		<Detail text="Accounts with a green check have passwords that do not expire but were specified in NoExpireOk.txt">
			<Head>
				<Col>User</Col>
			</Head>
			<Row Grade="3">
				<Col>Administrator</Col>
			</Row>
			<Row Grade="3">
				<Col>DefaultAccount</Col>
			</Row>
			<Row Grade="3">
				<Col>Guest</Col>
			</Row>
			<Row Grade="3">
				<Col>MSSQLSERVER01</Col>
			</Row>
			<Row Grade="3">
				<Col>MSSQLSERVER02</Col>
			</Row>
			<Row Grade="3">
				<Col>MSSQLSERVER03</Col>
			</Row>
			<Row Grade="3">
				<Col>MSSQLSERVER04</Col>
			</Row>
			<Row Grade="3">
				<Col>MSSQLSERVER05</Col>
			</Row>
			<Row Grade="3">
				<Col>MSSQLSERVER06</Col>
			</Row>
			<Row Grade="3">
				<Col>MSSQLSERVER07</Col>
			</Row>
			<Row Grade="3">
				<Col>MSSQLSERVER08</Col>
			</Row>
			<Row Grade="3">
				<Col>MSSQLSERVER09</Col>
			</Row>
			<Row Grade="3">
				<Col>MSSQLSERVER10</Col>
			</Row>
			<Row Grade="3">
				<Col>MSSQLSERVER11</Col>
			</Row>
			<Row Grade="3">
				<Col>MSSQLSERVER12</Col>
			</Row>
			<Row Grade="3">
				<Col>MSSQLSERVER13</Col>
			</Row>
			<Row Grade="3">
				<Col>MSSQLSERVER14</Col>
			</Row>
			<Row Grade="3">
				<Col>MSSQLSERVER15</Col>
			</Row>
			<Row Grade="3">
				<Col>MSSQLSERVER16</Col>
			</Row>
			<Row Grade="3">
				<Col>MSSQLSERVER17</Col>
			</Row>
			<Row Grade="3">
				<Col>MSSQLSERVER18</Col>
			</Row>
			<Row Grade="3">
				<Col>MSSQLSERVER19</Col>
			</Row>
			<Row Grade="3">
				<Col>MSSQLSERVER20</Col>
			</Row>
		</Detail>
	</Check>
	<Check ID="107" Grade="5" Type="1" Cat="1" Rank="5" Name="Guest Account" URL1="Help/Check5318.html" URL2="Help/Check5318fix.html" >
		<Advice>The Guest account is disabled on this computer.</Advice>
	</Check>
	<Check ID="110" Grade="5" Type="1" Cat="1" Rank="4" Name="Autologon" URL1="Help/Check5319.html" URL2="Help/Check5319fix.html" >
		<Advice>Autologon is not configured on this computer.</Advice>
	</Check>
	<Check ID="117" Grade="5" Type="1" Cat="1" Rank="6" Name="Restrict Anonymous" URL1="Help/Check53110.html" URL2="Help/Check53110fix.html" >
		<Advice>Computer is properly restricting anonymous access.</Advice>
	</Check>
	<Check ID="118" Grade="2" Type="4" Cat="1" Rank="10" Name="IE Zones" URL1="Help/Check53111.html" URL2="Help/Check53111fix.html" >
		<Advice>Internet Explorer zones do not have secure settings for some users.</Advice>
		<Detail text="Some or all of the user settings for the following zones are below the recommended level.">
			<Head>
				<Col>User</Col>
				<Col>Zone</Col>
				<Col>Level</Col>
				<Col>Recommended Level</Col>
			</Head>
			<Row Grade="2">
				<Col>METIS-TH\Administrator</Col>
				<Col HasZoneName="true">Internet</Col>
				<Col custom="false">High</Col>
				<Col>High</Col>
				<SETTINGS ID="1">
					<Head>
						<Col>Setting</Col>
						<Col>Current</Col>
						<Col>Recommended</Col>
					</Head>
					<Row Grade="2">
						<Col>Run components not signed with Authenticode</Col>
						<Col>Enable</Col>
						<Col>Disable</Col>
					</Row>
					<Row Grade="2">
						<Col>Run components signed with Authenticode</Col>
						<Col>Enable</Col>
						<Col>Disable</Col>
					</Row>
				</SETTINGS>
			</Row>
			<Row Grade="2">
				<Col>NT SERVICE\SSASTELEMETRY</Col>
				<Col HasZoneName="true">Internet</Col>
				<Col custom="true">Custom</Col>
				<Col>High</Col>
				<SETTINGS ID="2">
					<Head>
						<Col>Setting</Col>
						<Col>Current</Col>
						<Col>Recommended</Col>
					</Head>
					<Row Grade="2">
						<Col>Run components not signed with Authenticode</Col>
						<Col>Enable</Col>
						<Col>Disable</Col>
					</Row>
					<Row Grade="2">
						<Col>Run components signed with Authenticode</Col>
						<Col>Enable</Col>
						<Col>Disable</Col>
					</Row>
					<Row Grade="2">
						<Col>Run ActiveX controls and plug-ins</Col>
						<Col>Enable</Col>
						<Col>Disable</Col>
					</Row>
					<Row Grade="2">
						<Col>Active scripting</Col>
						<Col>Enable</Col>
						<Col>Disable</Col>
					</Row>
				</SETTINGS>
			</Row>
			<Row Grade="2">
				<Col>NT SERVICE\SSISTELEMETRY130</Col>
				<Col HasZoneName="true">Internet</Col>
				<Col custom="false">High</Col>
				<Col>High</Col>
				<SETTINGS ID="3">
					<Head>
						<Col>Setting</Col>
						<Col>Current</Col>
						<Col>Recommended</Col>
					</Head>
					<Row Grade="2">
						<Col>Run components not signed with Authenticode</Col>
						<Col>Enable</Col>
						<Col>Disable</Col>
					</Row>
					<Row Grade="2">
						<Col>Run components signed with Authenticode</Col>
						<Col>Enable</Col>
						<Col>Disable</Col>
					</Row>
				</SETTINGS>
			</Row>
			<Row Grade="2">
				<Col>NT SERVICE\SQLTELEMETRY</Col>
				<Col HasZoneName="true">Internet</Col>
				<Col custom="false">High</Col>
				<Col>High</Col>
				<SETTINGS ID="4">
					<Head>
						<Col>Setting</Col>
						<Col>Current</Col>
						<Col>Recommended</Col>
					</Head>
					<Row Grade="2">
						<Col>Run components not signed with Authenticode</Col>
						<Col>Enable</Col>
						<Col>Disable</Col>
					</Row>
					<Row Grade="2">
						<Col>Run components signed with Authenticode</Col>
						<Col>Enable</Col>
						<Col>Disable</Col>
					</Row>
				</SETTINGS>
			</Row>
			<Row Grade="2">
				<Col>NT SERVICE\MSSQLServerOLAPService</Col>
				<Col HasZoneName="true">Internet</Col>
				<Col custom="true">Custom</Col>
				<Col>High</Col>
				<SETTINGS ID="5">
					<Head>
						<Col>Setting</Col>
						<Col>Current</Col>
						<Col>Recommended</Col>
					</Head>
					<Row Grade="2">
						<Col>Run components not signed with Authenticode</Col>
						<Col>Enable</Col>
						<Col>Disable</Col>
					</Row>
					<Row Grade="2">
						<Col>Run components signed with Authenticode</Col>
						<Col>Enable</Col>
						<Col>Disable</Col>
					</Row>
					<Row Grade="2">
						<Col>Run ActiveX controls and plug-ins</Col>
						<Col>Enable</Col>
						<Col>Disable</Col>
					</Row>
					<Row Grade="2">
						<Col>Active scripting</Col>
						<Col>Enable</Col>
						<Col>Disable</Col>
					</Row>
				</SETTINGS>
			</Row>
			<Row Grade="2">
				<Col>NT SERVICE\ReportServer</Col>
				<Col HasZoneName="true">Internet</Col>
				<Col custom="true">Custom</Col>
				<Col>High</Col>
				<SETTINGS ID="6">
					<Head>
						<Col>Setting</Col>
						<Col>Current</Col>
						<Col>Recommended</Col>
					</Head>
					<Row Grade="2">
						<Col>Run components not signed with Authenticode</Col>
						<Col>Enable</Col>
						<Col>Disable</Col>
					</Row>
					<Row Grade="2">
						<Col>Run components signed with Authenticode</Col>
						<Col>Enable</Col>
						<Col>Disable</Col>
					</Row>
					<Row Grade="2">
						<Col>Run ActiveX controls and plug-ins</Col>
						<Col>Enable</Col>
						<Col>Disable</Col>
					</Row>
					<Row Grade="2">
						<Col>Active scripting</Col>
						<Col>Enable</Col>
						<Col>Disable</Col>
					</Row>
				</SETTINGS>
			</Row>
			<Row Grade="2">
				<Col>NT SERVICE\MSSQLFDLauncher</Col>
				<Col HasZoneName="true">Internet</Col>
				<Col custom="false">High</Col>
				<Col>High</Col>
				<SETTINGS ID="7">
					<Head>
						<Col>Setting</Col>
						<Col>Current</Col>
						<Col>Recommended</Col>
					</Head>
					<Row Grade="2">
						<Col>Run components not signed with Authenticode</Col>
						<Col>Enable</Col>
						<Col>Disable</Col>
					</Row>
					<Row Grade="2">
						<Col>Run components signed with Authenticode</Col>
						<Col>Enable</Col>
						<Col>Disable</Col>
					</Row>
				</SETTINGS>
			</Row>
			<Row Grade="2">
				<Col>NT SERVICE\SQLSERVERAGENT</Col>
				<Col HasZoneName="true">Internet</Col>
				<Col custom="true">Custom</Col>
				<Col>High</Col>
				<SETTINGS ID="8">
					<Head>
						<Col>Setting</Col>
						<Col>Current</Col>
						<Col>Recommended</Col>
					</Head>
					<Row Grade="2">
						<Col>Run components not signed with Authenticode</Col>
						<Col>Enable</Col>
						<Col>Disable</Col>
					</Row>
					<Row Grade="2">
						<Col>Run components signed with Authenticode</Col>
						<Col>Enable</Col>
						<Col>Disable</Col>
					</Row>
					<Row Grade="2">
						<Col>Run ActiveX controls and plug-ins</Col>
						<Col>Enable</Col>
						<Col>Disable</Col>
					</Row>
					<Row Grade="2">
						<Col>Active scripting</Col>
						<Col>Enable</Col>
						<Col>Disable</Col>
					</Row>
				</SETTINGS>
			</Row>
			<Row Grade="2">
				<Col>NT SERVICE\MSSQLLaunchpad</Col>
				<Col HasZoneName="true">Internet</Col>
				<Col custom="false">High</Col>
				<Col>High</Col>
				<SETTINGS ID="9">
					<Head>
						<Col>Setting</Col>
						<Col>Current</Col>
						<Col>Recommended</Col>
					</Head>
					<Row Grade="2">
						<Col>Run components not signed with Authenticode</Col>
						<Col>Enable</Col>
						<Col>Disable</Col>
					</Row>
					<Row Grade="2">
						<Col>Run components signed with Authenticode</Col>
						<Col>Enable</Col>
						<Col>Disable</Col>
					</Row>
				</SETTINGS>
			</Row>
			<Row Grade="2">
				<Col>NT SERVICE\MsDtsServer130</Col>
				<Col HasZoneName="true">Internet</Col>
				<Col custom="false">High</Col>
				<Col>High</Col>
				<SETTINGS ID="10">
					<Head>
						<Col>Setting</Col>
						<Col>Current</Col>
						<Col>Recommended</Col>
					</Head>
					<Row Grade="2">
						<Col>Run components not signed with Authenticode</Col>
						<Col>Enable</Col>
						<Col>Disable</Col>
					</Row>
					<Row Grade="2">
						<Col>Run components signed with Authenticode</Col>
						<Col>Enable</Col>
						<Col>Disable</Col>
					</Row>
				</SETTINGS>
			</Row>
			<Row Grade="2">
				<Col>NT SERVICE\MSSQLSERVER</Col>
				<Col HasZoneName="true">Internet</Col>
				<Col custom="false">High</Col>
				<Col>High</Col>
				<SETTINGS ID="11">
					<Head>
						<Col>Setting</Col>
						<Col>Current</Col>
						<Col>Recommended</Col>
					</Head>
					<Row Grade="2">
						<Col>Run components not signed with Authenticode</Col>
						<Col>Enable</Col>
						<Col>Disable</Col>
					</Row>
					<Row Grade="2">
						<Col>Run components signed with Authenticode</Col>
						<Col>Enable</Col>
						<Col>Disable</Col>
					</Row>
				</SETTINGS>
			</Row>
		</Detail>
	</Check>
	<Check ID="176" Grade="5" Type="4" Cat="1" Rank="12" Name="IE Enhanced Security Configuration for Administrators" URL1="Help/Check53176.html" URL2="Help/Check53176fix.html" >
		<Advice>The use of Internet Explorer is restricted for administrators on this server.</Advice>
	</Check>
	<Check ID="177" Grade="5" Type="4" Cat="1" Rank="12" Name="IE Enhanced Security Configuration for Non-Administrators" URL1="Help/Check53177.html" URL2="Help/Check53177fix.html" >
		<Advice>The use of Internet Explorer is restricted for non-administrators on this server.</Advice>
	</Check>
	<Check ID="119" Grade="4" Type="1" Cat="2" Rank="12" Name="Auditing" URL1="Help/Check53114.html" URL2="Help/Check53114fix.html" >
		<Advice>Neither Logon Success nor Logon Failure auditing are enabled. Enable auditing and turn on auditing for specific events such as logon and logoff. Be sure to monitor your event log to watch for unauthorized access.</Advice>
	</Check>
	<Check ID="121" Grade="4" Type="1" Cat="2" Rank="14" Name="Shares" URL1="Help/Check53115.html" URL2="Help/Check53115fix.html" >
		<Advice>8 share(s) are present on your computer. </Advice>
		<Detail text="Access: F - Full, R - Read, W - Write, D - Delete, X - Execute, C - Change">
			<Head>
				<Col>Share</Col>
				<Col>Directory</Col>
				<Col>Share ACL</Col>
				<Col>Directory ACL</Col>
			</Head>
			<Row Grade="4">
				<Col>ADMIN$</Col>
				<Col>C:\Windows</Col>
				<Col>Admin Share</Col>
				<Col>NT SERVICE\TrustedInstaller -  F, NT AUTHORITY\SYSTEM -  RWXD, BUILTIN\Administrators -  RWXD, BUILTIN\Users -  RX, APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES -  RX, APPLICATION PACKAGE AUTHORITY\ALL RESTRICTED APPLICATION PACKAGES -  RX</Col>
			</Row>
		</Detail>
	</Check>
	<Check ID="122" Grade="5" Type="1" Cat="1" Rank="7" Name="Administrators" URL1="Help/Check5316.html" URL2="Help/Check5316fix.html" >
		<Advice>No more than 2 Administrators were found on this computer. </Advice>
		<Detail>
			<Head>
				<Col>User</Col>
			</Head>
			<Row Grade="5">
				<Col>Domain\Testuser</Col>
			</Row>
			<Row Grade="5">
				<Col>Administrator</Col>
			</Row>
		</Detail>
	</Check>
	<Check ID="10124" Grade="6" Type="4" Cat="1" Rank="11" Name="Macro Security" >
		<Advice>No supported Microsoft Office products are installed.</Advice>
	</Check>
	<Check ID="10123" Grade="4" Type="1" Cat="2" Rank="13" Name="Services" URL1="Help/Check53116.html" >
		<Advice>No potentially unnecessary services were found.</Advice>
	</Check>
	<Check ID="10178" Grade="4" Type="1" Cat="1" Rank="9" Name="Windows Firewall" >
		<Advice>This check was skipped because it cannot be done remotely.</Advice>
	</Check>
	<Check ID="179" Grade="2" Type="1" Cat="1" Rank="10" Name="Automatic Updates" URL1="Help/Check53178.html" URL2="Help/Check53178fix.html" >
		<Advice>The Automatic Updates system service is not configured to be started as Automatic.</Advice>
	</Check>
	<Check ID="180" Grade="3" Type="1" Cat="1" Rank="10" Name="Incomplete Updates" URL1="Help/Check5340.html" URL2="Help/Check5340fix.html" >
		<Advice>A previous software update installation was not completed. You must restart your computer to finish the installation. If the incomplete installation was a security update, then the computer may be at risk until the computer is restarted.</Advice>
	</Check>
	<SQLInstance Name="(default)">
	<Check ID="201" Grade="5" Type="2" Cat="1" Rank="4" Name="Domain Controller Test" URL1="Help/Check5331.html" URL2="Help/Check5331fix.html" >
		<Advice>SQL Server and/or MSDE is not running on a domain controller.</Advice>
	</Check>
	<Check ID="203" Grade="3" Type="2" Cat="1" Rank="5" Name="SQL Server/MSDE Security Mode" URL1="Help/Check5333.html" URL2="Help/Check5333fix.html" >
		<Advice>SQL Server and/or MSDE authentication mode is set to SQL Server and/or MSDE and Windows (Mixed Mode).</Advice>
	</Check>
	<Check ID="207" Grade="5" Type="2" Cat="1" Rank="7" Name="CmdExec role" URL1="Help/Check53311.html" URL2="Help/Check53311fix.html" >
		<Advice>CmdExec is restricted to sysadmin only.</Advice>
	</Check>
	<Check ID="213" Grade="1" Type="2" Cat="1" Rank="6" Name="Registry Permissions" URL1="Help/Check53310.html" URL2="Help/Check53310fix.html" >
		<Advice>Internal error.(43.7)</Advice>
	</Check>
	<Check ID="216" Grade="5" Type="2" Cat="1" Rank="8" Name="Folder Permissions" URL1="Help/Check53312.html" URL2="Help/Check53312fix.html" >
		<Advice></Advice>
		<Detail text="The following users/groups have unnecessary access to the SQL Server/MSDE installation folders.">
			<Head>
				<Col>Instance</Col>
				<Col>Folder</Col>
				<Col>User</Col>
			</Head>
			<Row Grade="1">
				<Col>(default)</Col>
				<Col>Internal error.</Col>
				<Col>-</Col>
			</Row>
		</Detail>
	</Check>
	<Check ID="204" Grade="5" Type="2" Cat="1" Rank="12" Name="Sysadmin role members" URL1="Help/Check5335.html" URL2="Help/Check5335fix.html" >
		<Advice>BUILTIN\Administrators group is not part of sysadmin role.</Advice>
	</Check>
	<Check ID="206" Grade="5" Type="2" Cat="1" Rank="9" Name="Guest Account" URL1="Help/Check5339.html" URL2="Help/Check5339fix.html" >
		<Advice>The Guest account is not enabled in any of the databases.</Advice>
	</Check>
	<Check ID="215" Grade="3" Type="2" Cat="1" Rank="10" Name="Sysadmins" URL1="Help/Check5337.html" URL2="Help/Check5337fix.html" >
		<Advice>More than 2 members of sysadmin role are present. </Advice>
	</Check>
	<Check ID="218" Grade="1" Type="2" Cat="1" Rank="11" Name="Service Accounts" URL1="Help/Check5334.html" URL2="Help/Check5334fix.html" >
		<Advice>SQL Server, SQL Server Agent, MSDE and/or MSDE Agent service accounts should not be members of the local Administrators group or run as LocalSystem.</Advice>
		<Detail>
			<Head>
				<Col>Instance</Col>
				<Col>Service</Col>
				<Col>Account</Col>
				<Col>Issue</Col>
			</Head>
			<Row Grade="1">
				<Col>(default)</Col>
				<Col>MSSQLServer</Col>
				<Col>NT Service\MSSQLSERVER</Col>
				<Col>This is a Domain Account. Baseline Security Analyzer cannot determine whether it belongs to the Domain Admins group due to the following error:  1212 The format of the specified domain name is invalid..</Col>
			</Row>
			<Row Grade="1">
				<Col>(default)</Col>
				<Col>SQLServerAgent</Col>
				<Col>NT Service\SQLSERVERAGENT</Col>
				<Col>This is a Domain Account. Baseline Security Analyzer cannot determine whether it belongs to the Domain Admins group due to the following error:  1212 The format of the specified domain name is invalid..</Col>
			</Row>
		</Detail>
	</Check>
	<Check ID="225" Grade="2" Type="2" Cat="1" Rank="15" Name="Password Policy" URL1="Help/check53313.html" URL2="Help/check53313fix.html" >
		<Advice>Enable password expiration for the SQL server accounts.</Advice>
	</Check>
	<Check ID="227" Grade="5" Type="2" Cat="1" Rank="17" Name="SSIS Roles" URL1="Help/check53315.html" URL2="Help/check53315fix.html" >
		<Advice>The BUILTIN Admin does not belong to the SSIS roles.</Advice>
	</Check>
	<Check ID="228" Grade="5" Type="2" Cat="1" Rank="18" Name="Sysdtslog" URL1="Help/check53316.html" URL2="Help/check53316fix.html" >
		<Advice>Sysdtslogs90 table does not exist in the Master or MSDB databases</Advice>
	</Check>
	</SQLInstance>
	<SQLInstance Name="MSAS13.MSSQLSERVER">
	<Check ID="201" Grade="5" Type="2" Cat="1" Rank="4" Name="Domain Controller Test" URL1="Help/Check5331.html" URL2="Help/Check5331fix.html" >
		<Advice>SQL Server and/or MSDE is not running on a domain controller.</Advice>
	</Check>
	<Check ID="203" Grade="3" Type="2" Cat="1" Rank="5" Name="SQL Server/MSDE Security Mode" URL1="Help/Check5333.html" URL2="Help/Check5333fix.html" >
		<Advice>SQL Server and/or MSDE authentication mode is set to SQL Server and/or MSDE and Windows (Mixed Mode).</Advice>
	</Check>
	<Check ID="207" Grade="5" Type="2" Cat="1" Rank="7" Name="CmdExec role" URL1="Help/Check53311.html" URL2="Help/Check53311fix.html" >
		<Advice>CmdExec is restricted to sysadmin only.</Advice>
	</Check>
	<Check ID="213" Grade="1" Type="2" Cat="1" Rank="6" Name="Registry Permissions" URL1="Help/Check53310.html" URL2="Help/Check53310fix.html" >
		<Advice>Internal error.(43.7)</Advice>
	</Check>
	<Check ID="216" Grade="5" Type="2" Cat="1" Rank="8" Name="Folder Permissions" URL1="Help/Check53312.html" URL2="Help/Check53312fix.html" >
		<Advice></Advice>
		<Detail text="The following users/groups have unnecessary access to the SQL Server/MSDE installation folders.">
			<Head>
				<Col>Instance</Col>
				<Col>Folder</Col>
				<Col>User</Col>
			</Head>
			<Row Grade="1">
				<Col>MSAS13.MSSQLSERVER</Col>
				<Col>Internal error.</Col>
				<Col>-</Col>
			</Row>
		</Detail>
	</Check>
	<Check ID="204" Grade="6" Type="2" Cat="1" Rank="12" Name="Sysadmin role members" URL1="Help/Check5335.html" URL2="Help/Check5335fix.html" >
		<Advice>[DBNETLIB][ConnectionOpen (Connect()).]SQL Server does not exist or access denied.</Advice>
	</Check>
	<Check ID="206" Grade="6" Type="2" Cat="1" Rank="9" Name="Guest Account" URL1="Help/Check5339.html" URL2="Help/Check5339fix.html" >
		<Advice>[DBNETLIB][ConnectionOpen (Connect()).]SQL Server does not exist or access denied.</Advice>
	</Check>
	<Check ID="215" Grade="6" Type="2" Cat="1" Rank="10" Name="Sysadmins" URL1="Help/Check5337.html" URL2="Help/Check5337fix.html" >
		<Advice>[DBNETLIB][ConnectionOpen (Connect()).]SQL Server does not exist or access denied.</Advice>
	</Check>
	<Check ID="218" Grade="5" Type="2" Cat="1" Rank="11" Name="Service Accounts" URL1="Help/Check5334.html" URL2="Help/Check5334fix.html" >
		<Advice>SQL Server, SQL Server Agent, MSDE and/or MSDE Agent service accounts are not members of the local Administrators group and do not run as LocalSystem.</Advice>
	</Check>
	<Check ID="225" Grade="6" Type="2" Cat="1" Rank="15" Name="Password Policy" URL1="Help/check53313.html" URL2="Help/check53313fix.html" >
		<Advice>[DBNETLIB][ConnectionOpen (Connect()).]SQL Server does not exist or access denied.</Advice>
	</Check>
	<Check ID="227" Grade="6" Type="2" Cat="1" Rank="17" Name="SSIS Roles" URL1="Help/check53315.html" URL2="Help/check53315fix.html" >
		<Advice>[DBNETLIB][ConnectionOpen (Connect()).]SQL Server does not exist or access denied.</Advice>
	</Check>
	<Check ID="228" Grade="6" Type="2" Cat="1" Rank="18" Name="Sysdtslog" URL1="Help/check53316.html" URL2="Help/check53316fix.html" >
		<Advice>[DBNETLIB][ConnectionOpen (Connect()).]SQL Server does not exist or access denied.</Advice>
	</Check>
	</SQLInstance>
	<SQLInstance Name="MSRS13.MSSQLSERVER">
	<Check ID="201" Grade="5" Type="2" Cat="1" Rank="4" Name="Domain Controller Test" URL1="Help/Check5331.html" URL2="Help/Check5331fix.html" >
		<Advice>SQL Server and/or MSDE is not running on a domain controller.</Advice>
	</Check>
	<Check ID="203" Grade="3" Type="2" Cat="1" Rank="5" Name="SQL Server/MSDE Security Mode" URL1="Help/Check5333.html" URL2="Help/Check5333fix.html" >
		<Advice>SQL Server and/or MSDE authentication mode is set to SQL Server and/or MSDE and Windows (Mixed Mode).</Advice>
	</Check>
	<Check ID="207" Grade="5" Type="2" Cat="1" Rank="7" Name="CmdExec role" URL1="Help/Check53311.html" URL2="Help/Check53311fix.html" >
		<Advice>CmdExec is restricted to sysadmin only.</Advice>
	</Check>
	<Check ID="213" Grade="1" Type="2" Cat="1" Rank="6" Name="Registry Permissions" URL1="Help/Check53310.html" URL2="Help/Check53310fix.html" >
		<Advice>Internal error.(43.7)</Advice>
	</Check>
	<Check ID="216" Grade="5" Type="2" Cat="1" Rank="8" Name="Folder Permissions" URL1="Help/Check53312.html" URL2="Help/Check53312fix.html" >
		<Advice></Advice>
		<Detail text="The following users/groups have unnecessary access to the SQL Server/MSDE installation folders.">
			<Head>
				<Col>Instance</Col>
				<Col>Folder</Col>
				<Col>User</Col>
			</Head>
			<Row Grade="1">
				<Col>MSRS13.MSSQLSERVER</Col>
				<Col>Internal error.</Col>
				<Col>-</Col>
			</Row>
		</Detail>
	</Check>
	<Check ID="204" Grade="6" Type="2" Cat="1" Rank="12" Name="Sysadmin role members" URL1="Help/Check5335.html" URL2="Help/Check5335fix.html" >
		<Advice>[DBNETLIB][ConnectionOpen (Connect()).]SQL Server does not exist or access denied.</Advice>
	</Check>
	<Check ID="206" Grade="6" Type="2" Cat="1" Rank="9" Name="Guest Account" URL1="Help/Check5339.html" URL2="Help/Check5339fix.html" >
		<Advice>[DBNETLIB][ConnectionOpen (Connect()).]SQL Server does not exist or access denied.</Advice>
	</Check>
	<Check ID="215" Grade="6" Type="2" Cat="1" Rank="10" Name="Sysadmins" URL1="Help/Check5337.html" URL2="Help/Check5337fix.html" >
		<Advice>[DBNETLIB][ConnectionOpen (Connect()).]SQL Server does not exist or access denied.</Advice>
	</Check>
	<Check ID="218" Grade="5" Type="2" Cat="1" Rank="11" Name="Service Accounts" URL1="Help/Check5334.html" URL2="Help/Check5334fix.html" >
		<Advice>SQL Server, SQL Server Agent, MSDE and/or MSDE Agent service accounts are not members of the local Administrators group and do not run as LocalSystem.</Advice>
	</Check>
	<Check ID="225" Grade="6" Type="2" Cat="1" Rank="15" Name="Password Policy" URL1="Help/check53313.html" URL2="Help/check53313fix.html" >
		<Advice>[DBNETLIB][ConnectionOpen (Connect()).]SQL Server does not exist or access denied.</Advice>
	</Check>
	<Check ID="227" Grade="6" Type="2" Cat="1" Rank="17" Name="SSIS Roles" URL1="Help/check53315.html" URL2="Help/check53315fix.html" >
		<Advice>[DBNETLIB][ConnectionOpen (Connect()).]SQL Server does not exist or access denied.</Advice>
	</Check>
	<Check ID="228" Grade="6" Type="2" Cat="1" Rank="18" Name="Sysdtslog" URL1="Help/check53316.html" URL2="Help/check53316fix.html" >
		<Advice>[DBNETLIB][ConnectionOpen (Connect()).]SQL Server does not exist or access denied.</Advice>
	</Check>
	</SQLInstance>
	<SQLInstance Name="MSSQL13.MSSQLSERVER">
	<Check ID="201" Grade="5" Type="2" Cat="1" Rank="4" Name="Domain Controller Test" URL1="Help/Check5331.html" URL2="Help/Check5331fix.html" >
		<Advice>SQL Server and/or MSDE is not running on a domain controller.</Advice>
	</Check>
	<Check ID="203" Grade="3" Type="2" Cat="1" Rank="5" Name="SQL Server/MSDE Security Mode" URL1="Help/Check5333.html" URL2="Help/Check5333fix.html" >
		<Advice>SQL Server and/or MSDE authentication mode is set to SQL Server and/or MSDE and Windows (Mixed Mode).</Advice>
	</Check>
	<Check ID="207" Grade="1" Type="2" Cat="1" Rank="7" Name="CmdExec role" URL1="Help/Check53311.html" URL2="Help/Check53311fix.html" >
		<Advice>Error reading registry. If you are scanning a remote computer the Remote Registry service on that computer should be enabled. (13)</Advice>
	</Check>
	<Check ID="213" Grade="1" Type="2" Cat="1" Rank="6" Name="Registry Permissions" URL1="Help/Check53310.html" URL2="Help/Check53310fix.html" >
		<Advice>Internal error.(43.7)</Advice>
	</Check>
	<Check ID="216" Grade="2" Type="2" Cat="1" Rank="8" Name="Folder Permissions" URL1="Help/Check53312.html" URL2="Help/Check53312fix.html" >
		<Advice>Permissions on the SQL Server and/or MSDE installation folders are not set properly.</Advice>
		<Detail text="The following users/groups have unnecessary access to the SQL Server/MSDE installation folders.">
			<Head>
				<Col>Instance</Col>
				<Col>Folder</Col>
				<Col>User</Col>
			</Head>
			<Row Grade="2">
				<Col>MSSQL13.MSSQLSERVER</Col>
				<Col>E:\Program Files\Microsoft SQL Server\MSSQL13.MSSQLSERVER\MSSQL\Binn</Col>
				<Col>\CREATOR OWNER</Col>
			</Row>
			<Row Grade="2">
				<Col>MSSQL13.MSSQLSERVER</Col>
				<Col>E:\Program Files\Microsoft SQL Server\MSSQL13.MSSQLSERVER\MSSQL\Binn</Col>
				<Col>BUILTIN\Users</Col>
			</Row>
			<Row Grade="2">
				<Col>MSSQL13.MSSQLSERVER</Col>
				<Col>E:\Program Files\Microsoft SQL Server\MSSQL13.MSSQLSERVER\MSSQL\Binn</Col>
				<Col>NT SERVICE\MSSQLSERVER</Col>
			</Row>
			<Row Grade="2">
				<Col>MSSQL13.MSSQLSERVER</Col>
				<Col>E:\Program Files\Microsoft SQL Server\MSSQL13.MSSQLSERVER\MSSQL\Data</Col>
				<Col>\CREATOR OWNER</Col>
			</Row>
			<Row Grade="2">
				<Col>MSSQL13.MSSQLSERVER</Col>
				<Col>E:\Program Files\Microsoft SQL Server\MSSQL13.MSSQLSERVER\MSSQL\Data</Col>
				<Col>NT SERVICE\MSSQLSERVER</Col>
			</Row>
			<Row Grade="2">
				<Col>MSSQL13.MSSQLSERVER</Col>
				<Col>E:\Program Files\Microsoft SQL Server\MSSQL13.MSSQLSERVER\MSSQL\Data</Col>
				<Col>Domain\Data</Col>
			</Row>
		</Detail>
	</Check>
	<Check ID="204" Grade="6" Type="2" Cat="1" Rank="12" Name="Sysadmin role members" URL1="Help/Check5335.html" URL2="Help/Check5335fix.html" >
		<Advice>[DBNETLIB][ConnectionOpen (Connect()).]SQL Server does not exist or access denied.</Advice>
	</Check>
	<Check ID="206" Grade="6" Type="2" Cat="1" Rank="9" Name="Guest Account" URL1="Help/Check5339.html" URL2="Help/Check5339fix.html" >
		<Advice>[DBNETLIB][ConnectionOpen (Connect()).]SQL Server does not exist or access denied.</Advice>
	</Check>
	<Check ID="215" Grade="6" Type="2" Cat="1" Rank="10" Name="Sysadmins" URL1="Help/Check5337.html" URL2="Help/Check5337fix.html" >
		<Advice>[DBNETLIB][ConnectionOpen (Connect()).]SQL Server does not exist or access denied.</Advice>
	</Check>
	<Check ID="218" Grade="5" Type="2" Cat="1" Rank="11" Name="Service Accounts" URL1="Help/Check5334.html" URL2="Help/Check5334fix.html" >
		<Advice>SQL Server, SQL Server Agent, MSDE and/or MSDE Agent service accounts are not members of the local Administrators group and do not run as LocalSystem.</Advice>
	</Check>
	<Check ID="225" Grade="6" Type="2" Cat="1" Rank="15" Name="Password Policy" URL1="Help/check53313.html" URL2="Help/check53313fix.html" >
		<Advice>[DBNETLIB][ConnectionOpen (Connect()).]SQL Server does not exist or access denied.</Advice>
	</Check>
	<Check ID="227" Grade="6" Type="2" Cat="1" Rank="17" Name="SSIS Roles" URL1="Help/check53315.html" URL2="Help/check53315fix.html" >
		<Advice>[DBNETLIB][ConnectionOpen (Connect()).]SQL Server does not exist or access denied.</Advice>
	</Check>
	<Check ID="228" Grade="6" Type="2" Cat="1" Rank="18" Name="Sysdtslog" URL1="Help/check53316.html" URL2="Help/check53316fix.html" >
		<Advice>[DBNETLIB][ConnectionOpen (Connect()).]SQL Server does not exist or access denied.</Advice>
	</Check>
	</SQLInstance>
	<SQLInstance Name="(default) (32-bit)">
	<Check ID="201" Grade="5" Type="2" Cat="1" Rank="4" Name="Domain Controller Test" URL1="Help/Check5331.html" URL2="Help/Check5331fix.html" >
		<Advice>SQL Server and/or MSDE is not running on a domain controller.</Advice>
	</Check>
	<Check ID="203" Grade="3" Type="2" Cat="1" Rank="5" Name="SQL Server/MSDE Security Mode" URL1="Help/Check5333.html" URL2="Help/Check5333fix.html" >
		<Advice>SQL Server and/or MSDE authentication mode is set to SQL Server and/or MSDE and Windows (Mixed Mode).</Advice>
	</Check>
	<Check ID="207" Grade="5" Type="2" Cat="1" Rank="7" Name="CmdExec role" URL1="Help/Check53311.html" URL2="Help/Check53311fix.html" >
		<Advice>CmdExec is restricted to sysadmin only.</Advice>
	</Check>
	<Check ID="213" Grade="1" Type="2" Cat="1" Rank="6" Name="Registry Permissions" URL1="Help/Check53310.html" URL2="Help/Check53310fix.html" >
		<Advice>Internal error.(43.7)</Advice>
	</Check>
	<Check ID="216" Grade="5" Type="2" Cat="1" Rank="8" Name="Folder Permissions" URL1="Help/Check53312.html" URL2="Help/Check53312fix.html" >
		<Advice></Advice>
		<Detail text="The following users/groups have unnecessary access to the SQL Server/MSDE installation folders.">
			<Head>
				<Col>Instance</Col>
				<Col>Folder</Col>
				<Col>User</Col>
			</Head>
			<Row Grade="1">
				<Col>(default) (32-bit)</Col>
				<Col>Internal error.</Col>
				<Col>-</Col>
			</Row>
		</Detail>
	</Check>
	<Check ID="204" Grade="5" Type="2" Cat="1" Rank="12" Name="Sysadmin role members" URL1="Help/Check5335.html" URL2="Help/Check5335fix.html" >
		<Advice>BUILTIN\Administrators group is not part of sysadmin role.</Advice>
	</Check>
	<Check ID="206" Grade="5" Type="2" Cat="1" Rank="9" Name="Guest Account" URL1="Help/Check5339.html" URL2="Help/Check5339fix.html" >
		<Advice>The Guest account is not enabled in any of the databases.</Advice>
	</Check>
	<Check ID="215" Grade="3" Type="2" Cat="1" Rank="10" Name="Sysadmins" URL1="Help/Check5337.html" URL2="Help/Check5337fix.html" >
		<Advice>More than 2 members of sysadmin role are present. </Advice>
	</Check>
	<Check ID="218" Grade="1" Type="2" Cat="1" Rank="11" Name="Service Accounts" URL1="Help/Check5334.html" URL2="Help/Check5334fix.html" >
		<Advice>SQL Server, SQL Server Agent, MSDE and/or MSDE Agent service accounts should not be members of the local Administrators group or run as LocalSystem.</Advice>
		<Detail>
			<Head>
				<Col>Instance</Col>
				<Col>Service</Col>
				<Col>Account</Col>
				<Col>Issue</Col>
			</Head>
			<Row Grade="1">
				<Col>(default) (32-bit)</Col>
				<Col>MSSQLServer</Col>
				<Col>NT Service\MSSQLSERVER</Col>
				<Col>This is a Domain Account. Baseline Security Analyzer cannot determine whether it belongs to the Domain Admins group due to the following error:  1212 The format of the specified domain name is invalid..</Col>
			</Row>
			<Row Grade="1">
				<Col>(default) (32-bit)</Col>
				<Col>SQLServerAgent</Col>
				<Col>NT Service\SQLSERVERAGENT</Col>
				<Col>This is a Domain Account. Baseline Security Analyzer cannot determine whether it belongs to the Domain Admins group due to the following error:  1212 The format of the specified domain name is invalid..</Col>
			</Row>
		</Detail>
	</Check>
	<Check ID="225" Grade="2" Type="2" Cat="1" Rank="15" Name="Password Policy" URL1="Help/check53313.html" URL2="Help/check53313fix.html" >
		<Advice>Enable password expiration for the SQL server accounts.</Advice>
	</Check>
	<Check ID="227" Grade="5" Type="2" Cat="1" Rank="17" Name="SSIS Roles" URL1="Help/check53315.html" URL2="Help/check53315fix.html" >
		<Advice>The BUILTIN Admin does not belong to the SSIS roles.</Advice>
	</Check>
	<Check ID="228" Grade="5" Type="2" Cat="1" Rank="18" Name="Sysdtslog" URL1="Help/check53316.html" URL2="Help/check53316fix.html" >
		<Advice>Sysdtslogs90 table does not exist in the Master or MSDB databases</Advice>
	</Check>
	</SQLInstance>
	<Check ID="10314" Grade="6" Type="3" Cat="4" Rank="1" Name="IIS Status" >
		<Advice>IIS is not running on this computer.</Advice>
	</Check>
	<Composite>43</Composite>
</SecScan>