| title | sp_denylogin (Transact-SQL) | ||
|---|---|---|---|
| description | sp_denylogin Prevents a Windows user or Windows group from connecting to an instance of SQL Server. | ||
| author | markingmyname | ||
| ms.author | maghan | ||
| ms.reviewer | randolphwest | ||
| ms.date | 06/23/2025 | ||
| ms.service | sql | ||
| ms.subservice | system-objects | ||
| ms.topic | reference | ||
| f1_keywords |
|
||
| helpviewer_keywords |
|
||
| dev_langs |
|
[!INCLUDE SQL Server]
Prevents a Windows user or Windows group from connecting to an instance of [!INCLUDE ssNoVersion].
Important
[!INCLUDE ssNoteDepFutureAvoid] Use ALTER LOGIN instead.
:::image type="icon" source="../../includes/media/topic-link-icon.svg" border="false"::: Transact-SQL syntax conventions
sp_denylogin [ @loginame = ] N'loginame'
[ ; ]
The name of a Windows user or group. @loginame is sysname, with no default.
0 (success) or 1 (failure).
sp_denylogin denies CONNECT SQL permission to the server-level principal mapped to the specified Windows user or Windows group. If the server principal doesn't exist, it's created. The new principal is visible in the sys.server_principals catalog view.
sp_denylogin can't be executed within a user-defined transaction.
Requires membership in the sysadmin fixed server role, or execute permission directly on this stored procedure.
The following example shows how to use sp_denylogin to prevent Windows user CORPORATE\GeorgeV from connecting to the server.
EXECUTE sp_denylogin 'CORPORATE\GeorgeV';