Zero Trust for SQL Server: A Three-Layer Security Architecture
DOI:
https://doi.org/10.7719/jpair.v66i1.1058Keywords:
database security architecture, applied experimental research, SQL Server privilege management, Zero Trust security, Role-Based Access Control (RBAC), Attribute-Based Access Control (ABAC), Row-Level Security (RLS), Just-in-Time privilege elevation, least privilege enforcement, data classificationAbstract
Enterprise database systems are frequently targeted due to their reliance on perimeter-based, static access control models that lack continuous verification and privilege minimization. This study designed and empirically validated a three-layer Zero Trust architecture for Microsoft SQL Server that natively integrates instance-level authentication governance, enhanced Role-Based Access Control (RBAC) with Row-Level Security (RLS) and Just-in-Time (JIT) privilege elevation, and metadata-driven Attribute-Based Access Control (ABAC) through data classification — all without requiring external security middleware. Employing design science and applied experimental methodology, architecture was deployed in a live production environment comprising 589 databases and 132 identities over a 90-day post-implementation period. Chi-square tests of independence with Cramér's V effect size confirmed statistically significant reductions: login misuse declined by 82.1%, malicious authentication attempts by 66.7%, deployment errors by 59.8%, and reporting disruptions by 43.7%. Overprivileged accounts decreased by 84.2%. These results demonstrate that a coordinated, database native Zero Trust pipeline substantially reduces attack surfaces and insider risk in enterprise SQL Server environments. The proposed architecture aligns with globally recognized compliance frameworks, including ISO/IEC 27001 and GDPR, offering a replicable and regulatory-ready deployment model for enterprise environments across diverse jurisdictions.
Downloads
References
Benedict, J. O. S. E. P. H. (2023). An Appraisal of Database Security in a Business Organization (Case Study: Fintrak Software Company Limited). University of East London, United kingdom. https://tinyurl.com/mrxapuft
Bush, J. (2022). Practical database auditing for Microsoft SQL Server and Azure SQL: Troubleshooting, regulatory compliance, and governance. Apress. https://doi.org/10.1007/978-1-4842-8634-0
Carter, P. A. (2022). SQL Server Security Model. In Pro SQL Server 2019 Administration: A Guide for the Modern DBA (pp. 329-369). Berkeley, CA: Apress. https://doi.org/10.1007/978-1-4842-8864-1_10
Published
Issue
Section
License
Copyright (c) 2026 Maynard I. Capil, Daniel D. Dasig Jr.

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.
Open Access. This article published by JPAIR Multidisciplinary Research is licensed under a Creative Commons Attribution-Noncommercial 4.0 International (CC BY-NC 4.0). You are free to share (copy and redistribute the material in any medium or format) and adapt (remix, transform, and build upon the material). Under the following terms, you must give appropriate credit, provide a link to the license, and indicate if changes were made. You may do so in any reasonable manner, but not in any way that suggests the licensor endorses you or your use. You may not use the material for commercial purposes.







