◆ Microsoft SQL Server

Manage Azure SQL database roles and permissions

This is real work, not a feature someone invented — it comes from real job ads and real questions people asked. Below are four ready AI prompts: get it done, make it easy for the next person to say yes to, work out the right move when you are stuck, and stop it coming back.

4prompts

The same task, four prompts

today's deadline · the next reviewer · the stuck moment · the pattern
AExecute — do the immediate taskAdd David Miller to the 'db_datawriter' role for the 'CustomerPortal' database, and ensure he…+
Add David Miller to the 'db_datawriter' role for the 'CustomerPortal' database, and ensure he can only write to the 'Orders' table, not 'CustomerInfo'. Send confirmation to Sarah in operations by 3 PM.
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?
BImprove — make it easier to acceptBefore I onboard the new analytics team to the Azure database, make sure their access is secure…+
Before I onboard the new analytics team to the Azure database, make sure their access is secure and efficient. Create a custom role that grants read-only access to all 'Reporting' schemas but prevents any access to 'FinancialData', and make sure it's easy to add new team members to this role.
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?
CDecide — diagnose the stuck momentA new third-party vendor, 'DataInsights Inc.', needs read-only access to specific customer data…+
A new third-party vendor needs access to a specific set of customer data in Azure SQL, but our standard roles are too broad.
A new third-party vendor, 'DataInsights Inc.', needs read-only access to specific customer data in our Azure database for a limited time. Our existing 'reader' role gives them too much access, but creating a new role for every vendor feels unsustainable. I'm afraid of over-permissioning or making it too complex to revoke later. What's the most secure and manageable way to grant them precise, time-bound access to only the 'CustomerTransactions' and 'ProductUsage' tables, and how do I ensure it's easy to remove after 30 days?
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?
DBecome — change the patternI'm constantly losing credibility with security audits because I struggle to manage the…+
I frequently struggle to manage and audit the proliferation of custom roles and individual permissions in Azure SQL, especially as teams grow.
I'm constantly losing credibility with security audits because I struggle to manage the proliferation of custom roles and individual permissions in Azure, especially as new teams and projects come online. It's hard to get a clear picture of who has what access. What habit can I change to ensure I maintain a clean, auditable, and easily manageable permission structure across our Azure databases, without constantly reacting to new access requests?
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?

Questions people actually ask

honest answers, no sign-up

Every task here was seen in the real world. Someone doing the job named it, a real job ad asked for it, or a lot of people asked about it online.

If nothing real showed a task, it is not on the page. That is the whole rule.

They are the same job approached four ways, because what you need depends on where you are.

Get it done today. Make it easy for the next person to say yes to. Work out the right move when you are stuck. Learn the pattern so the job stops coming back.

For most of these jobs it can carry the heavy thinking - draft it, sort it, check it, rehearse it with you.

It cannot sit in your chair, take the blame when a number is wrong, or notice what nobody wrote down. Let it do the first 80%. Keep the last 20% that is truly yours.

No. Copy any prompt and paste it into the AI you already use. No account, no score, no wall in the way.

Any of them. The prompts describe the work rather than naming a product, so they are not tied to one assistant.

That is also why they keep working when you switch.

Change it freely. Every prompt is a starting line, not a rule.

Put in your real numbers, your real names and your real deadline. The more you make it yours, the better the answer comes back.

The tasks come from real job ads, published job data and the questions people ask in public forums.

The steps come from Microsoft SQL Server's own documentation, with practitioner sources for the traps the manual does not mention.

Push once. Ask it to sharpen the weakest part and to say what it assumed.

Most wrong answers come from a missing detail rather than a bad prompt - tell it the thing it could not know.