Gives every right over protected content, EXTRACT included, plus the ability to alter or strip the encryption. Owners and the Rights Management issuer always hold it.
Also called OWNER.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Full control in context, with comparison tables and the common traps.
Terms in this definition
- OVER
Gives a T-SQL window function its window: PARTITION BY, ORDER BY and, if wanted, a ROWS or RANGE frame. Rankings and running totals can then be worked out while every row is kept.
- ELT
Extract, load, transform: raw data lands in the target system first and is transformed there. See ETL for the opposite order.
- Encryption
Scrambling data so it cannot be read without the correct secret key, which is then used to turn it back again. Hashing, by contrast, cannot be reversed.
- Rights Management issuer
Whoever applied Azure Rights Management encryption to an item. That account keeps Full Control permanently, keeps offline access, and can still open the item once it has expired or been revoked.
Related terms
- AKS
Short for Azure Kubernetes Service, a managed Kubernetes offering that gives full control of clusters and node pools. Scaling uses the cluster autoscaler and Horizontal Pod Autoscaler; user sign-in is not built in.
- Allow externally sourced versions
Off unless a Feed Owner turns it on for a given package. While off, if your feed already holds that package name, versions arriving from public upstreams are refused, which guards against dependency confusion attacks.
- ALTER ANY EXTERNAL MIRROR
A permission that the account used for mirroring must hold in an Azure SQL Database, Azure SQL Managed Instance or SQL Server source before Fabric can mirror it. Anyone with CONTROL, or in the db_owner role, already has it.
- Azure Connected Machine Resource Administrator
Gives full control over Azure Arc-enabled servers and their extensions, including onboarding them again, which covers rolling out the Azure Monitor Agent to those machines. It is one of the built-in Azure roles.
- Catalog creator
Anyone holding this tenant-level entitlement management role may set up new catalogs and becomes the first owner of each, yet catalogs owned by others stay invisible and out of reach.
- Circuit authorization
Created by an ExpressRoute circuit's owner, it yields a key that a different subscription redeems to link its gateway to the circuit; each connection needs its own, and no extra circuit is required.
- Classic PAT
Older style of GitHub personal token with wide scopes over all repositories its owner can access; fine-grained tokens are recommended, keeping classic ones only where the newer kind falls short.
- Classic subscription administrator roles
Azure's original way of granting access: Account Administrator, Service Administrator and Co-Administrator. By May 2026 Microsoft had fully retired the latter two, leaving Azure RBAC to control access, while Account Administrator remains only as owner of the billing account.