MS SQL Server Audit Event: 24247

SQL » 24247: Issued revoke asymmetric key permissions with grant command

24247: Issued revoke asymmetric key permissions with grant command

In Public Key Cryptography (PKI), a public key and private key are created. The private key is kept a secret, whereas the public key can be distributed to others. Since these two keys are different, they are asymmetric. Event 24247 occurs when a command to revoke asymmetric key permissions (including the privilege to assign permissions to other users) from a user has been issued. It is generated by the DATABASE_OBJECT_PERMISSION_CHANGE_GROUP action group. Important information can be derived from this event including the:

  • Date and time at which the event occurred.
  • Session identifier of the event.
  • Privileged user who performed the action.
  • Server and database associated with the event.
  • ID, name, and permission bitmask of the target object (in this case, the asymmetric key).

MS SQL Server Auditing Tool

EventLog Analyzer is a comprehensive log management software with which you can centrally collect, analyze, and manage logs from all the different log sources in your network. You also get reports and alerts on your network security, making it a power-packed IT security tool.