Saturday, December 4, 2010

DB_OWNER Role remediation

DDL Admin role Can issue ALL DDL, but cannot issue GRANT, REVOKE, orDENY statements.When you dont want to give you developer DB Owner rightfor security concerns , You can assign this role to your developer withDB Data Reader and Data Writer permission.
The members of db_ddladmin database role can make any data definition language commands in the database.


1.db_datareader – select ? Developer role

   The members of db_datareader database role can see any data from all user tables in the database.

2.db_datawriter – insert, update, delete ?
The members of db_datawriter database role can add, change, or delete data from all user tables in the database.

3. db_ddladmin – Create,alter,drop,truncate -?
The members of db_ddladmin database role can make any data definition language commands in the database.

No comments:

Post a Comment