<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: security issues with SAS Internal ID's? in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/security-issues-with-SAS-Internal-ID-s/m-p/603937#M17665</link>
    <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/15475"&gt;@andreas_lds&lt;/a&gt;&amp;nbsp; - Thanks for pointing that out. We use 9.4M2 and expiring internal accounts is possible in M2 as well.&lt;/P&gt;</description>
    <pubDate>Wed, 13 Nov 2019 19:05:40 GMT</pubDate>
    <dc:creator>SASKiwi</dc:creator>
    <dc:date>2019-11-13T19:05:40Z</dc:date>
    <item>
      <title>security issues with SAS Internal ID's?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/security-issues-with-SAS-Internal-ID-s/m-p/603738#M17650</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;currently we have created some sas internal user id's for a set of associates for special purpose to view few reports on SAS VA, we should not allow them to use external id's ( they are not in our AD group).&lt;/P&gt;
&lt;P&gt;I would like to know is there any security issues raises when they use internal sas id's? if yes please elaborate them? also advise how to mitigate the risk?&lt;/P&gt;
&lt;P&gt;Appreciate your help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Cherry.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 02:37:27 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/security-issues-with-SAS-Internal-ID-s/m-p/603738#M17650</guid>
      <dc:creator>Cherry</dc:creator>
      <dc:date>2019-11-13T02:37:27Z</dc:date>
    </item>
    <item>
      <title>Re: security issues with SAS Internal ID's?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/security-issues-with-SAS-Internal-ID-s/m-p/603772#M17655</link>
      <description>&lt;P&gt;SAS internal IDs must have their passwords stored with them in a SAS metadata repository. These passwords are stored in an encrypted form. OS userids do not normally have passwords stored in SAS metadata, so from that perspective they are more secure.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Perhaps the biggest risk with SAS internal IDs is their passwords are static and there is no mechanism to have them expire automatically so they get changed on a regular basis. So to mitigate this risk you could have a policy of updating them on a regular basis. It is advisable to have these IDs stored in your company's password safe, so they aren't lost.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 05:57:20 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/security-issues-with-SAS-Internal-ID-s/m-p/603772#M17655</guid>
      <dc:creator>SASKiwi</dc:creator>
      <dc:date>2019-11-13T05:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: security issues with SAS Internal ID's?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/security-issues-with-SAS-Internal-ID-s/m-p/603779#M17656</link>
      <description>&lt;P&gt;can we get the audit logs of sas internal id's activities? I mean can we track what they ( sas internal id's) are doing on sas?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Cherry.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 06:31:34 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/security-issues-with-SAS-Internal-ID-s/m-p/603779#M17656</guid>
      <dc:creator>Cherry</dc:creator>
      <dc:date>2019-11-13T06:31:34Z</dc:date>
    </item>
    <item>
      <title>Re: security issues with SAS Internal ID's?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/security-issues-with-SAS-Internal-ID-s/m-p/603783#M17657</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/13976"&gt;@SASKiwi&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;[...]&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Perhaps the biggest risk with SAS internal IDs is their passwords are static and there is no mechanism to have them expire automatically so they get changed on a regular basis. So to mitigate this risk you could have a policy of updating them on a regular basis. It is advisable to have these IDs stored in your company's password safe, so they aren't lost.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Automatic password expiration seems to be possible (using 9.4m5):&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="internal_acc_pw_exp.png" style="width: 400px;"&gt;&lt;img src="https://communities.sas.com/t5/image/serverpage/image-id/33924i4C6ECD42F0F0AD1F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="internal_acc_pw_exp.png" alt="internal_acc_pw_exp.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 07:01:10 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/security-issues-with-SAS-Internal-ID-s/m-p/603783#M17657</guid>
      <dc:creator>andreas_lds</dc:creator>
      <dc:date>2019-11-13T07:01:10Z</dc:date>
    </item>
    <item>
      <title>Re: security issues with SAS Internal ID's?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/security-issues-with-SAS-Internal-ID-s/m-p/603937#M17665</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/15475"&gt;@andreas_lds&lt;/a&gt;&amp;nbsp; - Thanks for pointing that out. We use 9.4M2 and expiring internal accounts is possible in M2 as well.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 19:05:40 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/security-issues-with-SAS-Internal-ID-s/m-p/603937#M17665</guid>
      <dc:creator>SASKiwi</dc:creator>
      <dc:date>2019-11-13T19:05:40Z</dc:date>
    </item>
  </channel>
</rss>

