azure-sql-database-query-results

SQL tables and query results may contain arbitrary credentials, PII, and customer data. No single Azure RBAC action authorizes this service-native path; its own authentication and authorization apply.

azurecritical service: azure:sql emits CanReadData

Where it sits

locationTDS SELECT result-set cells
location kinddata_record
data kindsdatabase_credential sensitive_data pii customer_data credential password api_key access_key secret_key oauth_token connection_string
emits edgeCanReadData
serviceAzure SQL / SQL MI (azure:sql)

Collection recipe

access modedata_plane
operationTDS SELECT
response pathresult sets
encodingprotocol_native
params{"resource_id": "\u003cazure-resource-id\u003e"}

References

move · open · esc close