Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Applies to: 
 SQL Server  
 Azure SQL Database 
 Azure SQL Managed Instance
The Audit Server Principal Management event class occurs when server principals are created, altered, or dropped.
Audit Server Principal Management Event Class Data Columns
| Data column name | Data type | Description | Column ID | Filterable | 
|---|---|---|---|---|
| ApplicationName | nvarchar | Name of the client application that created the connection to an instance of Microsoft SQL Server. This column is populated with the values passed by the application rather than the displayed name of the program. | 10 | Yes | 
| DatabaseID | int | ID of the database specified by the USE database statement or the default database if no USE database statement has been issued for a given instance. SQL Server Profiler displays the name of the database if the ServerName data column is captured in the trace and the server is available. Determine the value for a database by using the DB_ID function. | 3 | Yes | 
| DatabaseName | nvarchar | Name of the database in which the user statement is running. | 35 | Yes | 
| DBUserName | nvarchar | SQL Server user name of the client. | 40 | Yes | 
| EventSequence | int | Sequence of a given event within the request. | 51 | No | 
| EventSubClass | int | Type of event subclass. 1=Create 2=Alter 3=Drop 4=Dump 5=Disable 6=Enable 11=Load | 21 | Yes | 
| HostName | nvarchar | Name of the computer on which the client is running. This data column is populated if the client provides the host name. To determine the host name, use the HOST_NAME function. | 8 | Yes | 
| IsSystem | int | Indicates whether the event occurred on a system process or a user process. 1 = system, 0 = user. | 60 | Yes | 
| LoginSid | image | Security identification number (SID) of the logged-in user. You can find this information in the sys.server_principals catalog view. Each SID is unique for each login in the server. | 41 | Yes | 
| NTDomainName | nvarchar | Windows domain to which the user belongs. | 7 | Yes | 
| NTUserName | nvarchar | Windows user name. | 6 | Yes | 
| ObjectName | nvarchar | Name of the object being referenced. | 34 | Yes | 
| ObjectType | int | Value representing the type of the object involved in the event. This value corresponds to the type column in the sys.objects catalog view. For values, see ObjectType Trace Event Column. | 28 | Yes | 
| OwnerName | nvarchar | Database user name of the object owner. | 37 | Yes | 
| RequestID | int | ID of the request containing the statement. | 49 | Yes | 
| ServerName | nvarchar | Name of the instance of SQL Server being traced. | 26 | No | 
| SessionLoginName | nvarchar | Login name of the user who originated the session. For example, if you connect to SQL Server using Login1 and execute a statement as Login2, SessionLoginName shows Login1 and LoginName shows Login2. This column displays both SQL Server and Windows logins. | 64 | Yes | 
| SPID | int | ID of the session on which the event occurred. | 12 | Yes | 
| StartTime | datetime | Time at which the event started, if available. | 14 | Yes | 
| Success | int | 1 = success. 0 = failure. For example, a value of 1 indicates success of a permissions check and a value of 0 indicates failure of that check. | 23 | Yes | 
| XactSequence | bigint | Token used to describe the current transaction. | 50 | Yes |