What’s the issue?
SQL Server Agent proxies let job steps run under a specific Windows account rather than under the Agent service account. Each proxy maps to a credential holding that account and its password, and is then authorized for particular subsystems such as CmdExec, PowerShell, SSIS, and Analysis Services.
Access to a proxy is granted separately, to specific logins, fixed server roles, or msdb database roles. Members of sysadmin can use every proxy implicitly, so proxy access grants exist specifically to extend that capability to principals who are not sysadmins.
Why is this a problem?
A principal with proxy access can create or modify a job step in an authorized subsystem and have it execute under the proxy account. For CmdExec and PowerShell subsystems, that means running operating system commands on the SQL Server host under an account the principal does not otherwise control.
The effective authority is whatever the proxy account holds on the host and in the domain, not what the principal holds in SQL Server. A proxy account with local administrator rights, broad file share access, or membership in privileged domain groups extends all that to anyone granted use of the proxy.
Proxy access lives in msdb rather than in server-level permissions or role membership, so a login with no notable SQL Server privileges can hold a path to command execution that a standard access review will not surface.
What should you do about this?
Review the current access by querying msdb.dbo.sysproxies, msdb.dbo.sysproxylogin, and msdb.dbo.sysproxysubsystem, capturing which principals can use each proxy and which subsystems each proxy is authorized for. Check the underlying credential in sys.credentials to identify the Windows account behind each one.
Remove proxy access for principals that no longer need it using sp_revoke_login_from_proxy, and remove subsystem authorizations that are not being used. Where access is legitimate, confirm the proxy is authorized only for the subsystems the job steps actually require.
Configure each proxy account to least privilege on the host, granting only the specific file system, network, and database permissions its job steps need.