A server-wide security principal used for connecting to SQL Server or an Azure SQL logical server; users inside each database are linked to it. EXECUTE AS LOGIN can't be used in Azure SQL Database.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Login in context, with comparison tables and the common traps.
Terms in this definition
- Security principal
Identity that a role assignment grants access to. It can be a user, a group, a managed identity or a service principal, which represents an application.
- SQL Server
The relational database from Microsoft that organisations host and run themselves, in their own data centres or on VMs. Its engine also sits underneath the Azure SQL services and SQL database in Fabric.
- Auditing
Azure SQL capability that sends database audit logs to Log Analytics, Event Hubs or a storage account; that account is allowed to be in a different region.
- Logical server
In Azure SQL, the parent resource for a set of databases, carrying their logins, Entra admin, firewall rules, auditing and TDE configuration. Think of it as a management boundary; it isn't an instance of SQL Server.
- Schema
The middle part of a Unity Catalog name (
catalog.schema.table), grouping tables, views, volumes, functions and models inside a catalog. A grant on it covers everything in it now and later, and nothing inside can be reached withoutUSE SCHEMA. - EXECUTE
Allows calling a function or loading a registered model in Unity Catalog, and seeing its definition.
USE CATALOGandUSE SCHEMAare needed too. - Azure SQL Database
Platform-as-a-service database offered as a single database or in an elastic pool, sized up to 4 TB or 128 TB on Hyperscale. SQL Agent, CLR and queries across databases aren't available.
Related terms
- Agent mode
Lets GitHub Copilot chat take several steps towards a goal, running tools and queries as you approve them. Don't treat that approval as a security boundary in SSMS 22.7 or later: every query uses the login's own permissions anyway.
- Azure CLI
Command-line tool for managing Azure that runs on any platform; examples include
az login,az storage queueandaz policy state trigger-scan. - Contained user
Database user that authenticates at database level with no login in master, such as an Entra user, group or managed identity added through CREATE USER ... FROM EXTERNAL PROVIDER.
- EVENTDATA
Inside a logon or DDL trigger, this T-SQL function hands back XML about what fired it, including the command text, login, time and type of event. Anywhere else it simply gives NULL.
- GDPR Compliance dashboard
A Defender EASM dashboard that highlights risks to personal-data compliance, for example exposed PII, cookies, login protocols and problems with certificates.
- GitHub Copilot in SSMS
GitHub Copilot integrated into SQL Server Management Studio 22 through the AI Assistance workload, offering chat and code completions, plus agent mode from version 22.7. Any queries it runs use your own login's permissions.
- HTTP 403 Forbidden
The status returned when the caller has authenticated but is blocked, either because the identity is missing a needed role or because the network denies it. Running az login with no data-plane role assignment is a common cause.
- IMPERSONATE
The permission that lets a principal take on the execution context of another login or database user, as happens when a module is declared with EXECUTE AS.