Skip to content
PlainID
← Back to all integrations
SQL Server logo

MSSQL

Apply fine-grained data filtering and masking for application access to Microsoft SQL Server.

About PlainID + MSSQL

Microsoft SQL Server (MSSQL) is a widely used relational database management system. PlainID offers a platform that simplifies the management and control of authorization policies across the enterprise technology stack. By integrating with the PlainID Authorizer for MSSQL Databases, organizations can dynamically modify queries at runtime to only return data that authorized users are permitted to see. This enforces continuous and contextual access to digital assets within the MSSQL database.

The integration of PlainID's Authorization platform enables organizations to centrally create, manage, and enforce authorization policies. Additionally, it allows organizations to define and manage fine-grained access rules, using attributes, roles, and permissions to ensure that only authorized users have access to specific data within the MSSQL database.

Technical Information

The PlainID Authorizer seamlessly operates at the data layer, embedded within applications or within the microservices architecture.
By leveraging a PlainID SQL SDK Library, the user's data requests to the Microsoft SQL Server (MSSQL) database will be intercepted and sent for authorization evaluation by PlainID. A modified query based on authorization policies will be returned and forwarded to the DB for data extraction with the appropriate security filters.
This combination of MSSQL and PlainID provides a powerful solution for enterprises to centralize and enhance data authorization and security in the face of growing data volumes and security concerns.

Architectures

  1. A User using an app that will allow interaction with digital assets.
  2. A PlainID library (Spring Boot or .NET) included in the app-level, or in the app's microservice layer that fetches data from the database, will intercept a DB query and initialize a call to the PlainID SQL Database Authorizer’s REST API. *These PlainID libraries helps developers to apply Data Access Control with low code (very minimal) or no code.
  3. The SQL Database Authorizer process the original query it received (such as SELECT * FROM CLIENTS_TABLE) with the user context and reaches out to PlainID PDP REST API for an authorization decision.
    The SQL Database Authorizer alters the original SQL statement, utilizing the identity-aware decision from the PDP, and returns a new SQL statement which includes data access controls, such as SELECT FNAME, LNAME, ADDRESS from CLIENTS_TABLE where CLIENTS TABLE.REGION=’US’.
  4. The altered SQL statement than sent for execution by MSSQL and the appropriate data is fetched and served to the user.

Technology

  • Data platforms

Capabilities

  • Manage
  • Enforce

Auth Patterns

  • Data Authorization - Filtering
  • Data Authorization - Masking
  • Policy information point (PIP)

Need help integrating?

Our experts can help you architect the perfect authorization strategy for your stack.

Contact Support

Better Together

Connect Context. Centralize Policy. Enforce Everywhere.