Why app roles are bad in MSSQL
let's see.
I don't like it because:
1) Any user can execute sp_setapprole by providing the correct password for the role
2) all users will have the same permissions under approle
3) somebody executes sp_setapprole means creates a connection to the database. you can restrict his permissions, but agree with me that it is some kind of a workaround
4) and at last see this (no word about it in BOL)
Saturday, December 13, 2003 3:35 AM