Removing Administrative Rights Only on a Table or Column Permission from a User or Role

Remove administrative rights only from a permission granted to a user, user-extended role, or standalone role, on a table or column.

Prerequisites
Database Version Role-Based Database Object Privileges
SAP Sybase IQ 15.3 and 15.4 Not supported.
SAP Sybase IQ 16.0 Requires one of:
  • MANAGE ANY OBJECT PRIVILEGE system privilege.
  • You have administrative rights to the permission being modified.
  • You own the database object.
Task
The REVOKE command applies to the database object permission itself, not to any administrative right granted on the permission. Therefore, to remove the administrative right only and leave the database object permission intact, do not use the Revoke button. Rather, regrant the specific permission without administrative rights. Only the original grantor can remove the administrative rights only from a granted permission. If another grantor regrants the same permission without administrative rights, a new permission without administrative rights is granted, but the original permission with administrative rights remains and takes precedence over any other non-administrative grants of the same permission to the same user or role.
  1. In the Perspective Resources view, select the resource and select Resource > Administration Console.
  2. In the left pane, select IQ Servers > Security > Role-Based.
  3. Select:
    • Users
    • User-Extended Roles
    • Standalone Roles
  4. Select:
    • Click the arrow to the right of the name and select Properties, or
    • From the Administration Console menu bar, select Resource > Properties.
  5. In the left pane, select Permissions.
  6. In the right pane, click Grant.
  7. On the Welcome page, based on the table level of the permission to be regranted, select Tables or Table columns.
  8. Click Next.
  9. On the Permissions page, select the permissions from which the administrative rights are being revoked.
  10. Click Finish.
  11. Click OK.
Related tasks
Authenticating a Login Account for a Managed Resource
Related reference
Role-Based Database Object Permissions Privilege Summary