Removes a users membership in a role or his or her ability to administer the role.
REVOKE [ ADMIN OPTION FOR ] ROLE role_name [,...] FROM grantee [,...] role_name dbo††† | diagnostics††† | PUBLIC††† | rs_systabgroup††† | SA_DEBUG††† | SYS††† | SYS_AUTH_SA_ROLE | SYS_AUTH_SSO_ROLE | SYS_AUTH_DBA_ROLE | SYS_AUTH_RESOURCE_ROLE | SYS_AUTH_BACKUP_ROLE | SYS_AUTH_VALIDATE_ROLE | SYS_AUTH_WRITEFILE_ROLE | SYS_AUTH_WRITEFILECLIENT_ROLE | SYS_AUTH_READFILE_ROLE | SYS_AUTH_READFILECLIENT_ROLE | SYS_AUTH_PROFILE_ROLE | SYS_AUTH_USER_ADMIN_ROLE | SYS_AUTH_SPACE_ADMIN_ROLE | SYS_AUTH_MULTIPLEX_ADMIN_ROLE | SYS_AUTH_OPERATOR_ROLE | SYS_AUTH_PERMS_ADMIN_ROLE | SYS_REPLICATE_ADMIN_ROLE††† | SYS_RUN_REPLICATE_ROLE††† | SYS_SPATIAL_ADMIN_ROLE††† | user-defined role name
†††The ADMIN OPTION FOR clause is not supported for system roles.
REVOKE ROLE Role1 FROM User1
After you execute this command, User1 no longer has the rights to perform any authorized tasks using any system privileges granted to Role1.
REVOKE ADMIN OPTION FOR ROLE SYS_AUTH_WRITEFILE_ROLE FROM User1
User1 retains the ability to perform any authorized tasks granted by SYS_AUTH_WRITEFILE_ROLE.