If you are talking about the the 'sde' user, then that is your problem right there. The 'sde' user
should not ever own spatial data. It exists solely for administration of the instance (and the
password to it should be tightly controlled).
All other users (data owners or data viewers) should be granted the minimum privileges necessary
to what they need to do (I can't tell you exactly what because I don't have access to my SQL-Server
box right now, and those accesses change by release anyway). After 23 years as a SQL-Server
administrator (and Oracle, and Informix, DB2, PostreSQL, and a bunch of very odd RDBMSes), I no
longer need to follow rote directions on configuration, but I can't explain what I'm doing either.
An administration class would be a lot more beneficial than paying to have me try to brain-dump
the jumble of cross-linked lessons learned on database security.
- V