Auto Admin Mapping in the Security Database
The ALTER ROLE RDB$ADMIN statement cannot enable or disable AUTO ADMIN MAPPING in the security database.However, you can create a global mapping for the predefined group DOMAIN_ANY_RID_ADMINS to the role RDB$ADMIN in the following way:
CREATE GLOBAL MAPPING WIN_ADMINS
  USING PLUGIN WIN_SSPI
  FROM Predefined_Group DOMAIN_ANY_RID_ADMINS
  TO ROLE RDB$ADMIN;Additionally, you can use gsec:
gsec -mapping set gsec -mapping drop
| Note | Depending on the administrative status of the current user, more parameters may be needed when invoking gsec, e.g.  | 
Only SYSDBA can enable AUTO ADMIN MAPPING if it is disabled, but any administrator can turn it off.
When turning off AUTO ADMIN MAPPING in gsec, the user turns off the mechanism itself which gave them access, and thus they would not be able to re-enable AUTO ADMIN MAPPING.Even in an interactive gsec session, the new flag setting takes effect immediately.