SQL Server Audit Log Event ID 24219

SourceSQL Server (LOGbinder SQL)
Action GroupDATABASE_OBJECT_PERMISSION_CHANGE_GROUP
Windows Security Log
Category
 • Subcategory
Object Access
 • Application Generated
Type Success

24219: Issued revoke database role permissions with grant command (action_id RWG class_type RL)

This is an event from SQL Server audit event from LOGbinder SQL generated by Action Group  DATABASE_OBJECT_PERMISSION_CHANGE_GROUP.

On this page

A command to revoke permissions to a database role was issued, including ability to grant permissions

Free Security Log Resources by Randy

Description Fields in 24219

FieldDescription
OccurredWhen event was reported by SQL Server
Authorization resultIf the command passed authorization checks
Session IDID of the session on which the event occurred
User
Server
DatabaseDatabase affected by the event
Target object
 IDTarget object ID
 NameTarget object name
 Permission bitmaskTarget object permission bitmask
StatementTransact-SQL statement

Supercharger Free Edition


Your entire Windows Event Collection environment on a single pane of glass.

Free.

 

Where Does This Event Come From?

This Event Is Produced By

Which Integrates with Your SIEM

Examples of 24219

Issued revoke database role permissions with grant command
A command to revoke permissions to a database role was issued, including ability to grant permissions
Action Group: DATABASE_OBJECT_PERMISSION_CHANGE_GROUP
Occurred: 8/22/2013 6:07:51.0000000 PM
Authorization result: Access allowed
Session ID: 67
User: LB\Administrator
Server: DEV3
Database: TestDatabase
Target Object
  ID: 8
  Name: TestDBRole
  Permission bitmask: System.Byte[]
Statement: REVOKE GRANT OPTION FOR ALTER ON ROLE::[TestDBRole] TO [TestUser2] CASCADE

For more information, see http://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24219

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection

 

Additional Resources