SQL Server Audit Log Event ID 24397

SourceSQL Server (LOGbinder SQL)
Windows Security Log
Category
 • Subcategory
Object Access
 • Application Generated
Type Success

24397: Issued a revoke with cascade external model permission command (action_id RWC; class_type EM)

This is an event from SQL Server audit event from LOGbinder SQL generated by Label  .

On this page

A revoke with cascade external model permission command was issued

Free Security Log Resources by Randy

Description Fields in 24397

Field Description
Occurred When event was reported by SQL Server.
Authorization result If the command passed authorization checks.
Session ID ID of the session on which the event occurred.
User User
Server Server
Database Database affected by the event.
Target object  
  ID Target object ID
  Name Target object name
  Permission bitmask Target object permission bitmask
Statement Transact-SQL statement

Supercharger Free Edition


Centrally manage WEC subscriptions.

Free.

 

Where Does This Event Come From?

This Event Is Produced By

Which Integrates with Your SIEM

Examples of 24397

Issued a revoke with cascade external model permission command
A revoke with cascade external model permission command was issued
Action Group: DATABASE_OBJECT_PERMISSION_CHANGE_GROUP
Occurred: 5/26/2026 3:07:42.0000000 AM
Authorization result: Access allowed
Session ID: 74
User: LAB\tuser
Server: lab-sql-13\SQLEXPRESS2025
Database: TestDatabase
Original Context
  Server login: LAB\tuser
  Database user: dbo
Target Context
  ID: 65551
  Database user: MyAiModel
Statement: REVOKE EXECUTE ON EXTERNAL MODEL::[MyAiModel] FROM [TestUser1] CASCADE;


For more information, see http://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24397

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection

 

Upcoming Webinars
    Additional Resources

      Go To Event ID:

      Security Log
      Quick Reference
      Chart
      Download now!