Hi,
I tried setting S-GATE Terminate and S-TAP Terminate options on the command ALTER SERVER ROLE.
On both - session level policy and data security policy.
While using the script - ALTER SERVER ROLE MEMBER [sysadmin] ADD/DROP LOGIN 'xxx'
Guardium blocks it without any issues (logs, terminate session and alerts).
But, While using the GUI - Logins => Properties => Server Roles => mark the sysadmin checkbox and press OK
Guardium doesn't block anything (logs and alerts on the action but doesn't terminate it).
How can I make sure that it also blocks the GUI option?
Thanks for your help.
------------------------------
itay Mor
------------------------------