Security cache invalidations

tokens. All different securables inside the database.

Description

One per database

tokens. All different securables inside the database.

This section describes issues with the security cache.

Various scenarios can trigger security cache invalidations at either the database or server level.

When an invalidation occurs, all current cache entries are invalidated.

permission checks follow the full “No cache” workflow until the caches are repopulated.

active connections need to rebuild the cached entries.

this impact worse.

database are treated as server-wide invalidations,

affecting the caches in all databases on the instance.

2025 introduces a feature that invalidates caches for only a specific login. This

affected login are affected.

login L2 remain unaffected.

permission changes for individual logins. Group logins continue to experience server-level

invalidation.

security cache.

Specified

database

ObjectPerm

ObjPerm

master

CREATE/ALTER/DROP
APPLICATION ROLE
SYMMETRIC KEY
ASYMMETRIC KEY
AUTHORIZATION
CERTIFICATE
ROLE
SCHEMA
USER