What’s the issue?
The remote access server configuration option controls whether stored procedures can be executed from remote servers using the four-part naming convention (servername.database.schema.procedure). It is a legacy setting from older versions of SQL Server, predating the modern linked server architecture, and is enabled by default with a value of 1.Microsoft has marked this feature as deprecated and has stated that it may be removed from a future release of SQL Server. Despite the deprecation, it remains enabled by default in current versions and is still in use by certain operational features, most notably the log shipping status report in SQL Server Management Studio.
This finding identifies instances where the remote access configuration is currently enabled.
Why is this a problem?
The remote access feature predates and overlaps with the linked server functionality that has replaced most of its original use cases. Modern distributed query patterns use linked servers, which provide better security mappings, more granular configuration, and clearer audit trails than the older remote access mechanism. Most environments that have remote access enabled are not actively using the feature and could disable it without operational impact.Leaving the feature enabled when it is not needed is a small surface-area concern. The feature provides a connectivity path that, like other legacy connectivity features, could potentially be misused if combined with other misconfigurations. While the practical risk is low, the principle of disabling unused features applies.
The main complication with disabling remote access is the dependency in SQL Server Management Studio’s log shipping status report. If your environment relies on the SSMS-based log shipping report for monitoring or troubleshooting, the report will not function correctly with remote access disabled. Other log shipping monitoring approaches (custom queries, third-party monitoring tools) are not affected.
The deprecation also matters for long-term planning. Although Microsoft has not announced a specific removal timeline, features marked as deprecated are eventually removed, and any environment that genuinely depends on this functionality will need to migrate before that happens. Evaluating the dependency now provides time to plan the migration on your schedule rather than under deadline pressure.
What should you do about this?
Determine whether remote access is actually required. The remote access server option can also affect stored procedure execution patterns involving servers added via sp_addserver and sp_addlinkedserver.Disable remote access with EXEC sp_configure ‘remote access’, 0; RECONFIGURE;. Microsoft indicates the change doesn’t take effect until SQL Server is restarted, so schedule a service restart and include rollback steps.
If log shipping reporting/alerting depends on it, migrate monitoring first. If you rely on SSMS log shipping status reporting or LSAlert job behavior, transition to alternate monitoring (custom queries, scripted checks, or monitoring tools) before disabling remote access.
If cross-server stored procedure execution is still needed, modernize carefully. Remote servers exist for backward compatibility and Microsoft recommends linked servers for new work, but linked-server stored procedure execution can still be impacted by the remote access setting. Validate your call patterns and dependency chain before disabling the option.