Blocks a user or role from a permission on some securable (schema, table, column) inside a Fabric warehouse or SQL analytics endpoint. DENY beats GRANT, while REVOKE clears either.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains T-SQL DENY in context, with comparison tables and the common traps.
Terms in this definition
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- Schema
The middle part of a Unity Catalog name (
catalog.schema.table), grouping tables, views, volumes, functions and models inside a catalog. A grant on it covers everything in it now and later, and nothing inside can be reached withoutUSE SCHEMA. - Event
Table in Log Analytics where entries from Windows event logs are kept.
- Fabric Warehouse
A relational data warehouse in the classic style, offered as a Fabric item, that supports T-SQL fully, transactions included.
- SQL analytics endpoint
Read-only SQL access in Fabric to the data in a lakehouse. Power BI using DirectQuery through it performs more slowly than Direct Lake.
- Deny
An Azure Policy effect that stops any create or update request that would break the policy.
- Authorisation code
OAuth 2.0 grant used by native and web apps: the user signs in, and the app then acts on their behalf with delegated permissions.