<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question about SAS Roles in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/Question-about-SAS-Roles/m-p/205857#M2971</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Grumbler,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A role is collection of capabilities - the easiest way to envisage roles is to control menu options in the various role-enabled SAS applications.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;For example:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;you may want the Reporting user group to have access to the reporting features of Enterprise Guide, but not the Analytics (and vice-versa)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;for security reasons, you may want to restrict upload/download of local data - again an EG menu option controllable through SAS roles.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;So:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Think of &lt;STRONG&gt;security&lt;/STRONG&gt; as &lt;STRONG&gt;what you can access&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Think of &lt;STRONG&gt;Roles&lt;/STRONG&gt; as &lt;STRONG&gt;what you are allowed to do&lt;/STRONG&gt; with what you access.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;I hope that helps.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Andrew.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 15 Jun 2015 06:42:35 GMT</pubDate>
    <dc:creator>AndrewHowell</dc:creator>
    <dc:date>2015-06-15T06:42:35Z</dc:date>
    <item>
      <title>Question about SAS Roles</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Question-about-SAS-Roles/m-p/205855#M2969</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;can someone explain to me what exactly is SAS roles?&amp;nbsp; in the management consolde, you can select users or groups to be members of a role.&amp;nbsp; then what does that do?&lt;/P&gt;&lt;P&gt;you set the authorization only to users and groups, not roles.&amp;nbsp; so not exactly clear what roles are for.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Jun 2015 04:31:37 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Question-about-SAS-Roles/m-p/205855#M2969</guid>
      <dc:creator>Grumbler</dc:creator>
      <dc:date>2015-06-15T04:31:37Z</dc:date>
    </item>
    <item>
      <title>Re: Question about SAS Roles</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Question-about-SAS-Roles/m-p/205856#M2970</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Roles control the availability of application features such as certain menu items, plug-ins, and buttons. In the initial configuration, registered users have almost all non-administrative capabilities. In many cases, this is appropriate and sufficient." Roles and Capabilities were introduced in SAS 9.2 and this paper gives a nice summary overview of what SAS Roles are, how they relate to capabilities and the effect they have on some of the SAS clients. &lt;A href="http://support.sas.com/resources/papers/proceedings10/324-2010.pdf" title="http://support.sas.com/resources/papers/proceedings10/324-2010.pdf"&gt;http://support.sas.com/resources/papers/proceedings10/324-2010.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At the end of the paper are further resources for details. If you are after specific information on the roles, I'd suggest looking at the associated documentation in the &lt;A href="http://support.sas.com/documentation/cdl/en/bisecag/67045/HTML/default/viewer.htm#p0izoyy5zh63k4n19lz9mlzremt9.htm" title="http://support.sas.com/documentation/cdl/en/bisecag/67045/HTML/default/viewer.htm#p0izoyy5zh63k4n19lz9mlzremt9.htm"&gt;SAS(R) 9.4 Intelligence Platform: Security Administration Guide, Second Edition&lt;/A&gt; or in the Security Admin Guide for the SAS version you are using.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;&lt;P&gt;Michelle&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Jun 2015 04:55:59 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Question-about-SAS-Roles/m-p/205856#M2970</guid>
      <dc:creator>MichelleHomes</dc:creator>
      <dc:date>2015-06-15T04:55:59Z</dc:date>
    </item>
    <item>
      <title>Re: Question about SAS Roles</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Question-about-SAS-Roles/m-p/205857#M2971</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Grumbler,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A role is collection of capabilities - the easiest way to envisage roles is to control menu options in the various role-enabled SAS applications.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;For example:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;you may want the Reporting user group to have access to the reporting features of Enterprise Guide, but not the Analytics (and vice-versa)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;for security reasons, you may want to restrict upload/download of local data - again an EG menu option controllable through SAS roles.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;So:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Think of &lt;STRONG&gt;security&lt;/STRONG&gt; as &lt;STRONG&gt;what you can access&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Think of &lt;STRONG&gt;Roles&lt;/STRONG&gt; as &lt;STRONG&gt;what you are allowed to do&lt;/STRONG&gt; with what you access.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;I hope that helps.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Andrew.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Jun 2015 06:42:35 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Question-about-SAS-Roles/m-p/205857#M2971</guid>
      <dc:creator>AndrewHowell</dc:creator>
      <dc:date>2015-06-15T06:42:35Z</dc:date>
    </item>
    <item>
      <title>Re: Question about SAS Roles</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Question-about-SAS-Roles/m-p/205858#M2972</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry Andrew,&amp;nbsp; I disagree.&amp;nbsp; At first SAS used the word roles for menu tailoring.&amp;nbsp; Rbac role based accès control is a security principle but menu tailoring is not. The new word capabilities is better for menu tailoring. You cannot implement security by menu tailoring it is just helping not experienced users to see an overweight number of menu choices. &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://support.sas.com/documentation/cdl/en/bisecag/67045/HTML/default/viewer.htm#n0ebv8vttay59vn11b5ar2i8ewyg.htm"&gt;http://support.sas.com/documentation/cdl/en/bisecag/67045/HTML/default/viewer.htm#n0ebv8vttay59vn11b5ar2i8ewyg.htm&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Jun 2015 13:54:12 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Question-about-SAS-Roles/m-p/205858#M2972</guid>
      <dc:creator>jakarman</dc:creator>
      <dc:date>2015-06-15T13:54:12Z</dc:date>
    </item>
  </channel>
</rss>

