True, when ever a new user is created it is added to public role by default. While creating a user if you set it for the particular db access he/she can access that particular database only (including system databases). Refer http://www.databasejournal.com/features/mssql/article.php/1478701 or BOL for...