← All articles
securitymigrationshealth-check

Database owners, orphaned users, and the TRUSTWORTHY bit

Ownership chains, orphaned users after restore, and TRUSTWORTHY settings create security and operational surprises after migrations.

Restores and migrations leave identity debris: orphaned users, unexpected database owners, and occasionally TRUSTWORTHY ON inherited from a lab.

Why it matters

  • Apps fail login mapping after restore
  • Ownership chaining behaves differently than expected
  • TRUSTWORTHY expands risk if modules run with higher privileges
  • Audit findings appear years after a migration “succeeded”

Health-check hygiene

  • Map users to logins correctly
  • Standardise database owners (often a controlled principal, not a random DBA login)
  • Review TRUSTWORTHY and cross-db patterns intentionally
  • Document migration runbooks so the next restore does not reintroduce chaos

Quiet risk

These issues rarely cause CPU spikes. They cause outages on failover day and security exceptions on audit day — both expensive.

Need hands-on SQL Server help?

Allay Data Solutions offers maintenance, tuning, and assessments from Port Elizabeth, South Africa.

Get in touch