SQL Server Check

C2 audit mode

This is one of many SQL Server checks performed by our free sp_Check tools.

Learn More About Our sp_check Tools

Checks Performed

ID
Check
341
C2 audit mode enabled

What’s the issue?

C2 audit mode is a legacy SQL Server feature that enables auditing of system level activities to support compliance with the U.S. Department of Defense “C2” security standard. When enabled, SQL Server writes a comprehensive audit trail of successful and failed login attempts, statement permissions checks, and many other security relevant events to trace files in the default data directory.

The feature was introduced in earlier SQL Server versions and is enabled through the c2 audit mode server configuration option, which requires show advanced options to be on. C2 audit mode has been deprecated for many years and is replaced by SQL Server Audit, which provides equivalent or better functionality with significantly more flexibility and lower operational impact.

This finding identifies instances where c2 audit mode is currently enabled. The condition is most often the result of a configuration applied many years ago to meet a specific compliance requirement that has since evolved or been replaced.

Why is this a problem?

C2 audit mode produces a very high volume of audit data, since it captures every statement permission check and many other low level events. The resulting trace files can grow rapidly and consume significant storage, particularly on busy instances where each query generates multiple audit records.

The feature also has a critical operational characteristic that catches teams by surprise: if SQL Server cannot write audit records (because the disk is full, the audit directory is unreachable, or the trace fails for any reason), the SQL Server service shuts down. This behavior is by design under the C2 standard, which requires that auditing not silently fail, but it means that any disruption to the audit destination causes a complete outage of the database engine.

C2 audit mode is also deprecated and will eventually be removed from SQL Server. Microsoft has documented this deprecation across many versions and recommends migrating to SQL Server Audit, which offers granular control over which events are captured, multiple destination types (file, Windows event log, security log), and better performance characteristics.

What should you do about this?

Determine whether C2 audit mode is genuinely required by current compliance obligations. Most organizations that originally enabled C2 audit mode are now able to satisfy the same requirements through SQL Server Audit, which is the supported, modern replacement. Engage with your compliance and security teams to confirm the current requirement before making changes.

If C2 audit mode is no longer required, disable it with EXEC sp_configure ‘c2 audit mode’, 0; RECONFIGURE; followed by a SQL Server service restart, since the change requires a restart to take full effect. After disabling, review the accumulated trace files in the data directory and archive or delete them according to your data retention policy.

If audit functionality is still required, plan a migration to SQL Server Audit. Define server level and database level audit specifications that capture the events your compliance requirements actually call for, configure the audit destination (file, application log, or security log), and verify that the new audit configuration produces the data needed for compliance reporting before disabling C2 mode.

Read more…

Server configuration: c2 audit mode

Type

Security

Importance

Medium

sp_Checks