Investigating access denied
Use the audit trail and governance context to understand why a person, group, or account could not reach a piece of data.
When to use this
- Use it when someone reports access denied.
- Use it to confirm whether a rule should have allowed the query.
- Use it to tell a lack of access apart from an expiry or a protection restriction.
Before you start
- Have the user or service account involved.
- Have the catalog, schema, and table that were queried.
- Have the approximate time of the attempt.
Step by step
- Open Audit Center.
- Filter by the user or service account.
- Narrow the period to the time reported.
- Look for records with a denied outcome.
- Read the data requested and the reason shown.
- Compare it with the existing data rules.
- Adjust the rule, or explain the denial to the requester.
What happens next
- You will have evidence of the reason for the denial.
- The manager can create, edit, or keep the current rule.
- The decision taken is recorded too.
Common errors
- Investigating the wrong user when the query was made by a service account.
- Forgetting that group-based access may have changed recently.
- Adjusting a rule without validating the business purpose.
Good practice
- Ask the user for the message and the time of the attempt.
- Confirm whether the access should be temporary or permanent.
- Apply least privilege when correcting the denial.
Next steps
Was this page helpful?
Report a problem on this pageDo not send passwords, keys, tokens, or customer data.