Azure Databases built-in role

SQL Security Manager

Manages security-related policies for Azure SQL logical servers, databases, and managed instances without granting database data access. Its control-plane Actions cover security features such as auditing, threat protection, vulnerability assessment, masking, sensitivity labels, firewall rules, encryption settings, and Microsoft Entra-only authentication; it has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 056cd41c-7e88-42e1-933e-88ba6a50c9c3

Control-plane actions (73)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the SQL server, managed instance, database, or dedicated resource group containing the security resources the administrator owns. Parent-scope assignments are inherited. SQL queries and database-engine permissions remain separate from these Azure control-plane security settings.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign SQL Security Manager to the database security team on the individual logical server, managed instance, database, or dedicated security scope. Keep SQL DB, Server, or Managed Instance Contributor and database-engine permissions separate unless the same trusted administrator explicitly owns those duties.

Related roles (3)

Editorial sources (6)

Official Microsoft Learn documentation →