Granting this on a securable gives all other permissions on it too, making it the most powerful SQL permission. At database scope that includes UNMASK and ALTER ANY MASK. Warehouse access through the Admin, Member or Contributor workspace roles carries it.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains CONTROL in context, with comparison tables and the common traps.
Terms in this definition
- ALL
A DAX function that ignores any filters and gives back every row of a table or every value of the named columns. Used within CALCULATE, it works as a modifier that clears filters, although REMOVEFILTERS states that intent more clearly where it is available.
- AGDLP
Nesting pattern: users go into global groups, which go into domain local groups, which receive the permissions. AGUDLP adds universal groups for forests with several domains.
- Serverless
Compute tier for single Azure SQL databases that scales automatically, pauses when idle and charges by the second. It is offered in General Purpose and Hyperscale, not Business Critical, and reserved capacity does not apply.
- Schema
The middle part of a Unity Catalog name (
catalog.schema.table), grouping tables, views, volumes, functions and models inside a catalog. A grant on it covers everything in it now and later, and nothing inside can be reached withoutUSE SCHEMA. - Scope
Where an access or policy assignment takes effect. It can be set on a single resource, a resource group, a subscription or a management group, and settings flow down from higher levels.
- UNMASK
Granting this SQL permission lets a user see real values that dynamic data masking would otherwise hide.
- Image edit mask
A PNG matching the input image's dimensions in which fully transparent pixels (alpha 0) mark the sole region the model is allowed to alter.
- Warehouse
Fabric item offering complete T-SQL support (DML, DDL, multi-table transactions) over Delta tables held in OneLake; lakehouse SQL analytics endpoints, by contrast, are read-only.
Related terms
- AAD DC Administrators
Grants members admin rights over joined VMs and control of Group Policy for AADDC containers in an Entra Domain Services managed domain. Enterprise Admins and Domain Admins rights don't exist there.
- Agent
A specialised form of Microsoft Copilot set up for one particular job, pairing instructions with knowledge and skills. You can create one in Copilot Studio, SharePoint or Agent Builder, and administrators control them from the Microsoft 365 admin center.
- AI gateway (Foundry)
API Management instance linked to a Microsoft Foundry resource; it sits in front of registered models, tools and agents, adding access control, rate limiting and diagnostics. Custom agents cannot be registered without one.
- Allowed locations
Built-in Azure Policy that rejects resources in any region missing from its list, making it the usual way to control where deployments go.
- ALTER ANY EXTERNAL MIRROR
A permission that the account used for mirroring must hold in an Azure SQL Database, Azure SQL Managed Instance or SQL Server source before Fabric can mirror it. Anyone with CONTROL, or in the db_owner role, already has it.
- Application Developer
Microsoft Entra role allowing its holders to register apps even if "Users can register applications" is No. Other people's apps are outside its control.
- Application-enforced restrictions
Lets Exchange Online or SharePoint Online learn whether a device is managed and compliant: on such devices users get everything, while elsewhere they get a cut-down experience such as browser-only access. It is a Conditional Access session control.
- Architecture Project
How enterprise architecture work is packaged so the team can be steered and managed: a Request for Architecture Work kicks it off and a Statement of Architecture Work keeps it under control.