Skip to main content

Investigating access denied

Use the audit trail and governance context to understand why a person, group, or account could not reach a piece of data.

When to use this​

  • Use it when someone reports access denied.
  • Use it to confirm whether a rule should have allowed the query.
  • Use it to tell a lack of access apart from an expiry or a protection restriction.

Before you start​

  • Have the user or service account involved.
  • Have the catalog, schema, and table that were queried.
  • Have the approximate time of the attempt.

Step by step​

  1. Open Audit Center.
  2. Filter by the user or service account.
  3. Narrow the period to the time reported.
  4. Look for records with a denied outcome.
  5. Read the data requested and the reason shown.
  6. Compare it with the existing data rules.
  7. Adjust the rule, or explain the denial to the requester.

What happens next​

  • You will have evidence of the reason for the denial.
  • The manager can create, edit, or keep the current rule.
  • The decision taken is recorded too.

Common errors​

  • Investigating the wrong user when the query was made by a service account.
  • Forgetting that group-based access may have changed recently.
  • Adjusting a rule without validating the business purpose.

Good practice​

  • Ask the user for the message and the time of the attempt.
  • Confirm whether the access should be temporary or permanent.
  • Apply least privilege when correcting the denial.

Next steps​