Prevent grants to public database role

    Hi All,

    I'm trying to prevent anyone from being able to apply grants to just the public database role. There doesn't appear to be an event type to help me prevent this.....Any ideas?

    I didn’t try it, so I can’t tell you for sure that it works, but if I had to come up with a solution for it, I would have try to write a trigger in the database for grant, deny and revoke events. In the trigger I’d check if the permissions were modified for the public role. If it did, I would rollback the operation. As I wrote at the beginning, I didn’t check it, but this would be the first direction that I would explore.


    you can deny/remove rights to/from the public role, we have had to do that before as part of auditing and compliance.

