16.10 - Controlling the Granting and Revoking of Logons - Teradata Database

Teradata Database Security Administration

prodname
Teradata Database
vrm_release
16.10
created_date
June 2017
category
Administration
Security
featnum
B035-1100-161K

The ability to grant and revoke logons for database users is controlled by the EXECUTE privilege on the DBC.LogonRule macro. User DBC has this privilege by default. You must grant the privilege to any other user who needs to use the GRANT LOGON or REVOKE LOGON statement. For an example:

GRANT EXECUTE ON DBC.LogonRule

See Creating the Security Administrator User for other administrator privileges.

When an administrator with the GRANT EXECUTE ON DBC.LogonRule privilege submits a GRANT LOGON or REVOKE LOGON statement, the DBC.LogonRule macro adds or deletes a row in the DBC.logonRules table for the affected user. See DBC.LogonRulesV in Data Dictionary and GRANT LOGON/REVOKE LOGON in SQL Data Control Language.