Skip to Content
Microsoft® SQL Server® 2008 Bible
book

Microsoft® SQL Server® 2008 Bible

by Paul Nielsen, Mike White, Uttam Parui
August 2009
Beginner to intermediate
1680 pages
42h 30m
English
Wiley
Content preview from Microsoft® SQL Server® 2008 Bible

Chapter 50. Authorizing Securables

IN THIS CHAPTER

  • Object ownership

  • Securables permissions

  • Object security

  • Views and security

This chapter adds another important piece to the SQL Server security puzzle—securables. These are objects (for example, tables, views, stored procedures, columns) that can be secured in order to prevent unauthorized access.

Object Ownership

A very important aspect of SQL Server's security model involves object ownership. Every object is contained by a schema. The default schema is dbo—not to be confused with the dbo role.

Ownership becomes critical when permission is being granted to a user to run a stored procedure when the user doesn't have permission to the underlying tables. If the ownership chain from the tables to the stored procedure is consistent, then the user can access the stored procedure, and the stored procedure can access the tables as its owner. However, if the ownership chain is broken, meaning there's a different owner somewhere between the stored procedure and the table, then the user must have rights to the stored procedure, the underlying tables, and every other object in between.

There is a fine point in the details. A schema is owned; and because a schema is owned, anything that is contained by it has the same owner.

Most security management can be performed in Management Studio. With code, security is managed by means of the GRANT, REVOKE, and DENY Data Control Language (DCL) commands and several system stored procedures.

Object Security

If a ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Microsoft® SQL Server 2008 R2 Unleashed

Microsoft® SQL Server 2008 R2 Unleashed

Ray Rankins, Paul Bertucci, Chris Gallelli, Alex T. Silverstein
Microsoft® SQL Server 2005 Unleashed

Microsoft® SQL Server 2005 Unleashed

Ray Rankins, Paul Bertucci, Chris Gallelli, Alex T. Silverstein, Tudor Trufinescu, John Kane

Publisher Resources

ISBN: 9780470257043Purchase book