Every Unity Catalog securable, and every workspace object such as a job or warehouse, has exactly one owner (IS OWNER), which can be a user, a group or a service principal. That owner holds every capability on the object, though child objects do not inherit the ownership.
Also called ownership.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Object owner in context, with comparison tables and the common traps.
Terms in this definition
- Unity Catalog
Azure Databricks' governance solution covering both data and AI in one place, with centralised permissions, auditing, data discovery and lineage.
- Workspace
Teams in Power BI and Microsoft Fabric collaborate in this folder-style container, which groups items such as reports, semantic models and lakehouses, controls who can access them and is assigned a capacity.
- Job
A sequence of steps executed together on one agent or runner, or on the server for agentless work. While running, each occupies one of your parallel jobs.
- Warehouse
Fabric item offering complete T-SQL support (DML, DDL, multi-table transactions) over Delta tables held in OneLake; lakehouse SQL analytics endpoints, by contrast, are read-only.
- Full control
Gives every right over protected content, EXTRACT included, plus the ability to alter or strip the encryption. Owners and the Rights Management issuer always hold it.
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
- Service principal
The tenant-local instance of a managed identity or app registration, which users and Azure or directory roles are assigned to. Those from app registrations authenticate with a stored certificate or secret that needs rotating and can be copied, which suits code running outside Azure.
- Capability
Something that a person, organisation or system is able to do.
Related terms
- afdverify
Verification CNAME in Front Door (classic), mapping afdverify.<host> to afdverify.<name>.azurefd.net, which proves ownership of a custom domain while live traffic stays where it is.
- Candidate (Defender EASM asset state)
Asset state in Defender EASM meaning there is some, but insufficient, linkage to your seeds; someone must check ownership by hand, and the asset is only scanned during discovery.
- Custom domain name
A DNS domain you own, contoso.com for example, added to a Microsoft Entra tenant next to the permanent onmicrosoft.com initial domain. Users can sign in with it once you have proved ownership through a TXT or MX record.
- Defender EASM labels
Free-form tags for recording business context on Defender EASM assets. Adding one alters neither an asset's state nor its scanning or ownership.
- DENY policy
A Beta ABAC policy type that takes a privilege away rather than granting one; at the moment it can only block
MANAGE ACCESS CONTROL. It applies wherever governed tags match and beats every grant, ownership too, though it never restricts metastore admins. - Enrollment restrictions
Microsoft describes these as a best-effort barrier rather than a security feature. Intune's device limit and device platform restrictions can stop enrolment by device count, ownership, manufacturer, OS version or platform.
- Foreign catalog
Mirrors a database living in another system so it can be queried read-only from Unity Catalog over a Lakehouse Federation connection. Making one takes
CREATE CATALOG, and on the connection you need ownership orCREATE FOREIGN CATALOG. - MANAGE
A Unity Catalog privilege allowing a principal to grant and revoke access on an object, hand over its ownership and drop it, all without being the owner. It gives no data access by itself and is not part of
ALL PRIVILEGES.