A data control (DCL) command that takes away a permission a user or role was earlier granted or denied. The other DCL commands are GRANT and DENY.
Read more: Microsoft Learn
In the Ultra Transcenders books
DP-900DP-750DP-600DP-700DP-800
Each book explains REVOKE in context, with comparison tables and the common traps.
Terms in this definition
- CONTROL
Granting this on a securable gives all other permissions on it too, making it the most powerful SQL permission. At database scope that includes UNMASK and ALTER ANY MASK. Warehouse access through the Admin, Member or Contributor workspace roles carries it.
- DCL
Data Control Language, the SQL statements GRANT, DENY and REVOKE that control permissions on database objects. Database administrators are the people who typically use them.
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- EARLIER
Within nested DAX row contexts, lets an inner calculation read a column as it stood in an outer pass; EARLIEST jumps to the outermost. Most people now use variables, which read more clearly.
- Authorisation code
OAuth 2.0 grant used by native and web apps: the user signs in, and the app then acts on their behalf with delegated permissions.
- Deny
An Azure Policy effect that stops any create or update request that would break the policy.
Related terms
- DDL trigger
A trigger that responds to server or database events like CREATE, ALTER, DROP, GRANT, DENY or REVOKE. It is commonly used to record or prevent changes to the schema.
- GRANT
Gives a user or group permission to do particular things to a database object; it is a Data Control Language (DCL) statement. To take a permission back use REVOKE, and to block one use DENY.
- MANAGE
A Unity Catalog privilege allowing a principal to grant and revoke access on an object, hand over its ownership and drop it, all without being the owner. It gives no data access by itself and is not part of
ALL PRIVILEGES. - T-SQL DENY
Blocks a user or role from a permission on some securable (schema, table, column) inside a Fabric warehouse or SQL analytics endpoint. DENY beats GRANT, while REVOKE clears either.