<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: New Role in Management console - only access data through libraries? in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/New-Role-in-Management-console-only-access-data-through/m-p/509002#M14837</link>
    <description>&lt;P&gt;You might want to provide some more specific info (examples may help) so&amp;nbsp;community members can give you more targeted assistance. e.g. which SAS version and platform is this for? Are you looking for help with access controls or just SAS roles and capabilities? It sounds like it might be a combination of several things. By role do you mean a SAS "Role" or a generic job role?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/13976"&gt;@SASKiwi&lt;/a&gt;&amp;nbsp;mentioned SAS metadata bound libraries&amp;nbsp;may help here. You will probably also need to look at access controls in metadata (via ACTs/ACEs for groups on objects), access controls in the file system (UNIX, Linux or WIndows?) and role/capabilities in metadata (to control access to SAS application features) - a multi-layered approach.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If your question is&amp;nbsp;only about SAS roles and capabilities then I would suggest the following resources:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://documentation.sas.com/?docsetId=bisecag&amp;amp;docsetTarget=p0izoyy5zh63k4n19lz9mlzremt9.htm&amp;amp;docsetVersion=9.4&amp;amp;locale=en" target="_self"&gt;Metadata Roles&lt;/A&gt; section (and associated links) in the &lt;EM&gt;SAS® 9.4 Intelligence Platform: Security Administration Guide&lt;/EM&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://documentation.sas.com/?docsetId=bidaag&amp;amp;docsetTarget=n0jklogerfgzv2n1h0spll13lnpf.htm&amp;amp;docsetVersion=9.4&amp;amp;locale=en" target="_self"&gt;Administering Roles&lt;/A&gt; section in the&amp;nbsp;&lt;EM&gt;SAS® 9.4 Intelligence Platform: Desktop Application Administration Guide&lt;/EM&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://documentation.sas.com/?docsetId=mcsecug&amp;amp;docsetTarget=n0s6jxhq6hmvb3n107jastiuavn9.htm&amp;amp;docsetVersion=9.4&amp;amp;locale=en" target="_self"&gt;Assign Capabilities to a Role&lt;/A&gt; section in the&amp;nbsp;&lt;EM&gt;SAS® 9.4 Management Console: Guide to Users and Permissions.&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;SAS Global Forum 2010 Paper (324-2010) "&lt;A href="http://support.sas.com/resources/papers/proceedings10/324-2010.pdf" target="_self"&gt;Be All That You Can Be: Best Practices in Using Roles to Control Functionality in SAS® 9.2&lt;/A&gt;" by Kathy Wisniewski&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 31 Oct 2018 05:36:29 GMT</pubDate>
    <dc:creator>PaulHomes</dc:creator>
    <dc:date>2018-10-31T05:36:29Z</dc:date>
    <item>
      <title>New Role in Management console - only access data through libraries?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/New-Role-in-Management-console-only-access-data-through/m-p/508800#M14828</link>
      <description>&lt;P&gt;Hi SAS Admins,&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a custom SAS security set up and I need to add an additional role for our organization. I need to create a role that only allows users to access and import sas datasets through libraries pointing to&amp;nbsp;specific physical folders on our&amp;nbsp;SAS server. I know how to create the libraries in Management console.&amp;nbsp; I do not want to allow them any other SAS capabilities for this role (they will get those from another role). Can you please help?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Oct 2018 16:30:51 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/New-Role-in-Management-console-only-access-data-through/m-p/508800#M14828</guid>
      <dc:creator>missmindi</dc:creator>
      <dc:date>2018-10-30T16:30:51Z</dc:date>
    </item>
    <item>
      <title>Re: New Role in Management console - only access data through libraries?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/New-Role-in-Management-console-only-access-data-through/m-p/508891#M14831</link>
      <description>&lt;P&gt;If you want to limit SAS users to accessing SAS data through only libraries set up in metadata and not be able to bypass metadata security by defining their own LIBNAMEs then you need to look at metadata-bound libraries:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://documentation.sas.com/?docsetId=seclibag&amp;amp;docsetTarget=n0tzurc8qfze0vn13z4n6j6mzz14.htm&amp;amp;docsetVersion=9.4&amp;amp;locale=en" target="_blank"&gt;https://documentation.sas.com/?docsetId=seclibag&amp;amp;docsetTarget=n0tzurc8qfze0vn13z4n6j6mzz14.htm&amp;amp;docsetVersion=9.4&amp;amp;locale=en&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I suggest you read the documentation in the link carefully as setting these up is not trivial and it also requires more administration.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Oct 2018 19:05:19 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/New-Role-in-Management-console-only-access-data-through/m-p/508891#M14831</guid>
      <dc:creator>SASKiwi</dc:creator>
      <dc:date>2018-10-30T19:05:19Z</dc:date>
    </item>
    <item>
      <title>Re: New Role in Management console - only access data through libraries?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/New-Role-in-Management-console-only-access-data-through/m-p/509002#M14837</link>
      <description>&lt;P&gt;You might want to provide some more specific info (examples may help) so&amp;nbsp;community members can give you more targeted assistance. e.g. which SAS version and platform is this for? Are you looking for help with access controls or just SAS roles and capabilities? It sounds like it might be a combination of several things. By role do you mean a SAS "Role" or a generic job role?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/13976"&gt;@SASKiwi&lt;/a&gt;&amp;nbsp;mentioned SAS metadata bound libraries&amp;nbsp;may help here. You will probably also need to look at access controls in metadata (via ACTs/ACEs for groups on objects), access controls in the file system (UNIX, Linux or WIndows?) and role/capabilities in metadata (to control access to SAS application features) - a multi-layered approach.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If your question is&amp;nbsp;only about SAS roles and capabilities then I would suggest the following resources:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://documentation.sas.com/?docsetId=bisecag&amp;amp;docsetTarget=p0izoyy5zh63k4n19lz9mlzremt9.htm&amp;amp;docsetVersion=9.4&amp;amp;locale=en" target="_self"&gt;Metadata Roles&lt;/A&gt; section (and associated links) in the &lt;EM&gt;SAS® 9.4 Intelligence Platform: Security Administration Guide&lt;/EM&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://documentation.sas.com/?docsetId=bidaag&amp;amp;docsetTarget=n0jklogerfgzv2n1h0spll13lnpf.htm&amp;amp;docsetVersion=9.4&amp;amp;locale=en" target="_self"&gt;Administering Roles&lt;/A&gt; section in the&amp;nbsp;&lt;EM&gt;SAS® 9.4 Intelligence Platform: Desktop Application Administration Guide&lt;/EM&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://documentation.sas.com/?docsetId=mcsecug&amp;amp;docsetTarget=n0s6jxhq6hmvb3n107jastiuavn9.htm&amp;amp;docsetVersion=9.4&amp;amp;locale=en" target="_self"&gt;Assign Capabilities to a Role&lt;/A&gt; section in the&amp;nbsp;&lt;EM&gt;SAS® 9.4 Management Console: Guide to Users and Permissions.&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;SAS Global Forum 2010 Paper (324-2010) "&lt;A href="http://support.sas.com/resources/papers/proceedings10/324-2010.pdf" target="_self"&gt;Be All That You Can Be: Best Practices in Using Roles to Control Functionality in SAS® 9.2&lt;/A&gt;" by Kathy Wisniewski&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 05:36:29 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/New-Role-in-Management-console-only-access-data-through/m-p/509002#M14837</guid>
      <dc:creator>PaulHomes</dc:creator>
      <dc:date>2018-10-31T05:36:29Z</dc:date>
    </item>
  </channel>
</rss>

