A Unity Catalog privilege allowing a principal to grant and revoke access on an object, hand over its ownership and drop it, all without being the owner. It gives no data access by itself and is not part of ALL PRIVILEGES.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains MANAGE in context, with comparison tables and the common traps.
Terms in this definition
- Unity Catalog
Azure Databricks' governance solution covering both data and AI in one place, with centralised permissions, auditing, data discovery and lineage.
- Principal
A user, group or service principal: anything that can receive a privilege grant.
- Authorisation code
OAuth 2.0 grant used by native and web apps: the user signs in, and the app then acts on their behalf with delegated permissions.
- REVOKE
A data control (DCL) command that takes away a permission a user or role was earlier granted or denied. The other DCL commands are GRANT and DENY.
- OVER
Gives a T-SQL window function its window: PARTITION BY, ORDER BY and, if wanted, a ROWS or RANGE frame. Rankings and running totals can then be worked out while every row is kept.
- Object owner
Every Unity Catalog securable, and every workspace object such as a job or warehouse, has exactly one owner (IS OWNER), which can be a user, a group or a service principal. That owner holds every capability on the object, though child objects do not inherit the ownership.
- DROP
A DDL (Data Definition Language) statement that deletes a database object like a table. Once a table is dropped, its rows are gone unless a backup exists.
- ALL
A DAX function that ignores any filters and gives back every row of a table or every value of the named columns. Used within CALCULATE, it works as a modifier that clears filters, although REMOVEFILTERS states that intent more clearly where it is available.
Related terms
- Account Operators
A built-in group allowed to create and manage most user, group and computer accounts, except those of administrators. Microsoft advises leaving it without members.
- ADM
The Architecture Development Method is a proven, iterative and repeatable way to develop and manage architectures. It runs through a Preliminary Phase and Phases A to H, with Requirements Management sitting in the middle.
- ALL PRIVILEGES
A shortcut grant in Unity Catalog covering every privilege relevant to an object. Four are deliberately left out:
MANAGE,READ METADATAand the two external use privileges for schemas and locations. - Allowlist
Held at metastore level, it records which JAR files, Maven libraries and init scripts may run on compute using the standard access mode. It begins with no entries, and only holders of
MANAGE ALLOWLISTmay change it. - Android Enterprise
How Google lets organisations manage Android devices that run Google Mobile Services. After a Managed Google Play account is connected, Intune handles four scenarios: fully managed, dedicated, corporate-owned work profile and personally owned work profile.
- Application Administrator
Microsoft Entra role able to manage every enterprise application and app registration, application proxy included. It may grant admin consent, apart from Microsoft Graph app roles.
- Azure Deployment Stack Contributor
Can manage deployment stacks, but has no right to add or remove deny assignments; an Azure built-in role.
- Azure PowerShell
Set of Az.* modules from Microsoft that let you manage Azure from PowerShell, using cmdlets like
Set-AzStorageAccount.