Data Control Language, the SQL statements GRANT, DENY and REVOKE that control permissions on database objects. Database administrators are the people who typically use them.
Also called Data Control Language.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains DCL in context, with comparison tables and the common traps.
Terms in this definition
- Serverless
Compute tier for single Azure SQL databases that scales automatically, pauses when idle and charges by the second. It is offered in General Purpose and Hyperscale, not Business Critical, and reserved capacity does not apply.
- Authorisation code
OAuth 2.0 grant used by native and web apps: the user signs in, and the app then acts on their behalf with delegated permissions.
- Deny
An Azure Policy effect that stops any create or update request that would break the policy.
- REVOKE
A data control (DCL) command that takes away a permission a user or role was earlier granted or denied. The other DCL commands are GRANT and DENY.
- CONTROL
Granting this on a securable gives all other permissions on it too, making it the most powerful SQL permission. At database scope that includes UNMASK and ALTER ANY MASK. Warehouse access through the Admin, Member or Contributor workspace roles carries it.
- AGDLP
Nesting pattern: users go into global groups, which go into domain local groups, which receive the permissions. AGUDLP adds universal groups for forests with several domains.
- Schema
The middle part of a Unity Catalog name (
catalog.schema.table), grouping tables, views, volumes, functions and models inside a catalog. A grant on it covers everything in it now and later, and nothing inside can be reached withoutUSE SCHEMA.
Related terms
- GRANT
Gives a user or group permission to do particular things to a database object; it is a Data Control Language (DCL) statement. To take a permission back use REVOKE, and to block one use DENY.