MS SQL Server Audit Event: 24233

SQL » 24233: Issued revoke symmetric key permissions with grant command

24233: Issued revoke symmetric key permissions with grant command

A symmetric key uses the same password to both encrypt and decrypt data. Event 24233 occurs when a command to revoke symmetric key permissions (including the privilege to assign permissions to other users) from a user has been issued. It is generated by the DATABASE_OBJECT_PERMISSION_CHANGE_GROUP action group. Important information can be derived from this event including the:

  • Date and time at which the event occurred.
  • Session identifier of the event.
  • Privileged user who performed the action.
  • Server and database associated with the event.
  • ID, name, and permission bitmask of the target object (in this case, the symmetric key).

MS SQL Server Auditing Tool

EventLog Analyzer is a comprehensive log management software with which you can centrally collect, analyze, and manage logs from all the different log sources in your network. You also get reports and alerts on your network security, making it a power-packed IT security tool.