Ask a Question
Ask Question Login
Corporate Training
  1. Community
  2. SQL Server
  3. Question
SQL Server

What to do when select permission was denied on the object?

Asked by David Edmunds Mar 20, 2023 9.0K views 3 answers
Share

About this question

 I'm a programmer, not a dba... I know just enough to be dangerous.


I've inherited a database with a legacy user that is a db_owner for the database. We can't adjust this user's permission for existing tables, schemas, etc., for business reasons, but some new tables are being created, and I only want this user to have SELECT access on them.


Permissions have been set for this user for these tables so that everything is DENIED, except SELECT, which is set to GRANT.


Yet when this user (dbadmin) attempts to perform a SELECT on one of these tables (AccountingAudit), this error happens:


The SELECT permission was denied on the object 'AccountingAudit', database 'billing', schema 'dbo'.

I've run this SQL to try and see what permissions are set for this table/user:


select object_name(major_id) as object,
 user_name(grantee_principal_id) as grantee,
 user_name(grantor_principal_id) as grantor,
 permission_name,
 state_desc
from sys.database_permissions
And this is what I get back:
AccountingAudit dbadmin dbo ALTER   DENY
AccountingAudit dbadmin dbo CONTROL DENY
AccountingAudit dbadmin dbo DELETE  DENY
AccountingAudit dbadmin dbo INSERT  DENY
AccountingAudit dbadmin dbo REFERENCES  DENY
AccountingAudit dbadmin dbo SELECT  GRANT
AccountingAudit dbadmin dbo TAKE OWNERSHIP  DENY
AccountingAudit dbadmin dbo UPDATE  DENY
AccountingAudit dbadmin dbo VIEW DEFINITION DENY
AccountingAudit dbadmin dbo VIEW CHANGE TRACKING    DENY

Seems like it should be working right?

The SELECT call I'm making is a very basic SELECT * FROM AccountingAudit, from within SSMS. I'm not doing any special sp_executesql or anything like that.

I've tried explicitly granting permission:

GRANT SELECT ON [dbo].AccountingAudit TO dbadmin
This has no effect (why would it, the query above already shows it's granted! ;-)


I've searched through stackoverflow.com and elsewhere, and cannot find anything I haven't tried yet. I'm wondering if it has something to do with how the schemas are setup. (At this point I know very little about schemas.)

Your answer

3 Answers

Ranjana Admin JanBask Expert Latest answer

Answered on Mar 4, 2025

If you’re seeing the error "SELECT permission was denied on the object" in Salesforce, it means your user does not have read access to the object. Here’s how to fix it:

1. Check Profile Permissions

  • Go to Setup → Users → Profiles.
  • Select your profile and navigate to Object Settings.
  • Find the object and ensure "Read" permission is enabled.

2. Use Permission Sets

  • Instead of modifying the profile, create a Permission Set:
  • Go to Setup → Permission Sets.
  • Click New, assign a name, and select the object.
  • Enable the Read permission and assign it to the user.
  • This is helpful if multiple users need access without changing profiles.

3. Check Field-Level Security

  • Even if you have access to the object, specific fields might be restricted.
  • Go to Setup → Object Manager → Select the object → Fields & Relationships.
  • Click the field and check Field-Level Security to ensure visibility.

4. Verify Sharing Settings

  • If the object is private, check Sharing Rules in Setup → Sharing Settings.
  • Grant access to specific users or roles if necessary.

5. Debug with System Admin Access

  • If unsure, log in as a System Administrator to test access.
  • Use SOQL Query in Developer Console:

  SELECT Id, Name FROM ObjectName LIMIT 10

If it works as an admin but fails for a user, it’s a permissions issue.

Once permissions are adjusted, you should be able to run queries without errors!

Was this helpful?

Ranjana Admin JanBask Expert

Answered on Apr 25, 2024


If you're encountering a "Select permission was denied on the object" error in Salesforce, it means that the user trying to access the object doesn't have the necessary permissions. Here's what you can do to address this issue:

Check User Permissions: Verify that the user has the appropriate permissions to access the object in question. Ensure that the user's profile or permission set includes the necessary permissions for reading the object's data.

Check Field-Level Security: Even if a user has access to an object, they might not have access to view certain fields on that object due to field-level security settings. Check the field-level security settings for the fields that are being accessed in the query.

Check Sharing Settings: If the object's sharing settings are set to anything other than "Public Read/Write" or "Public Read Only", make sure that the user has been granted access to the object through sharing rules, manual sharing, or other means.

Check Record-Level Access: If the object's OWD (Organization Wide Defaults) are set to "Private", the user might not have access to certain records within the object. Ensure that the user has been granted access to the records they need through sharing rules, role hierarchy, or record-level permissions.

Check Apex Code or Processes: If the query is being executed from Apex code, make sure that the code is running in a context where the user has the necessary permissions. If the query is part of a process or automation, ensure that the process or automation is running with the appropriate permissions.

Check for API Access: If the query is being executed via an API call, make sure that the API user has the necessary permissions to access the object and its fields.

Review Object Permissions: Review the permissions assigned to the user's profile or permission set, as well as any permission set assignments or role hierarchies that may affect their access to the object.

Check Field-Level Security for Integration Users: If the query is being executed by an integration user, ensure that the integration user's profile or permission set has the necessary field-level security settings configured.

By following these steps and ensuring that the user has the appropriate permissions at both the object and field levels, you should be able to resolve the "Select permission was denied on the object" error in Salesforce.

Was this helpful?

More SQL Server discussions

Learn & Explore

Free tutorials and interview questions from industry experts — learn the skill, then get ready to prove it.

Latest SQL Server Blogs

Guides, tips and career advice on SQL Server from JanBask experts.