DENY Object Permissions (Transact-SQL)
Denies permissions on a member of the OBJECT class of securables. These are the members of the OBJECT class: tables, views, table-valued functions, stored procedures, extended stored procedures, scalar functions, aggregate functions, service queues, and synonyms.
DENY <permission> [ ,...n ] ON
[ OBJECT :: ][ schema_name ]. object_name [ ( column [ ,...n ] ) ]
TO <database_principal> [ ,...n ]
[ CASCADE ]
[ AS <database_principal> ]
<permission> ::=
ALL [ PRIVILEGES ] | permission [ ( column [ ,...n ] ) ]
<database_principal> ::=
Database_user
| Database_role
| Application_role
| Database_user_mapped_to_Windows_User
| Database_user_mapped_to_Windows_Group
| Database_user_mapped_to_certificate
| Database_user_mapped_to_asymmetric_key
| Database_user_with_no_login
Information about objects is visible in various catalog views. For more information, see Object Catalog Views (Transact-SQL).
An object is a schema-level securable contained by the schema that is its parent in the permissions hierarchy. The most specific and limited permissions that can be denied on an object are listed in the following table, together with the more general permissions that include them by implication.
|
Object permission |
Implied by object permission |
Implied by schema permission |
|---|---|---|
|
ALTER |
CONTROL |
ALTER |
|
CONTROL |
CONTROL |
CONTROL |
|
DELETE |
CONTROL |
DELETE |
|
EXECUTE |
CONTROL |
EXECUTE |
|
INSERT |
CONTROL |
INSERT |
|
RECEIVE |
CONTROL |
CONTROL |
|
REFERENCES |
CONTROL |
REFERENCES |
|
SELECT |
RECEIVE |
SELECT |
|
TAKE OWNERSHIP |
CONTROL |
CONTROL |
|
UPDATE |
CONTROL |
UPDATE |
|
VIEW CHANGE TRACKING |
CONTROL |
VIEW CHANGE TRACKING |
|
VIEW DEFINITION |
CONTROL |
VIEW DEFINITION |
A. Denying SELECT permission on a table
The following example denies SELECT permission to the user RosaQdM on the table Person.Address in the AdventureWorks2012 database.
USE AdventureWorks2012; DENY SELECT ON OBJECT::Person.Address TO RosaQdM; GO
B. Denying EXECUTE permission on a stored procedure
The following example denies EXECUTE permission on the stored procedure HumanResources.uspUpdateEmployeeHireInfo to an application role called Recruiting11.
USE AdventureWorks2012;
DENY EXECUTE ON OBJECT::HumanResources.uspUpdateEmployeeHireInfo
TO Recruiting11;
GO
C. Denying REFERENCES permission on a view with CASCADE
The following example denies REFERENCES permission on the column BusinessEntityID in the view HumanResources.vEmployee to the user Wanida with CASCADE.
USE AdventureWorks2012;
DENY REFERENCES (BusinessEntityID) ON OBJECT::HumanResources.vEmployee
TO Wanida CASCADE;
GO
Caution