<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Change name in User Manager in SMC in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216915#M3318</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There appears to be lots of helpful information here, as well as a correct answer or two. Given that, I am marking the original question as "assumed answered" so that others with a similar question can find the help they need. You can do this yourself, at any time. Thanks for using the communities!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 10 Apr 2015 14:22:04 GMT</pubDate>
    <dc:creator>ShelleySessoms</dc:creator>
    <dc:date>2015-04-10T14:22:04Z</dc:date>
    <item>
      <title>Change name in User Manager in SMC</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216894#M3297</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Greetings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I like to follow the recommendation that user names and group names as seen in the General Tab of User Manager in SMC are short and without blanks (and unique of course).&amp;nbsp; Example&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Name:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Franklin Delano Roosevelt&lt;/P&gt;&lt;P&gt;Display Name: [blank]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I change to&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Name:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; fdroos&lt;/P&gt;&lt;P&gt;Display Name: Franklin Delano Roosevelt &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I come to a site where the previous admins did not read that page of the manual, I usually change the names.&lt;/P&gt;&lt;P&gt;At this site, 9.4 under Linux with grid, the "Name:" field is (ghosted) not modifiable.&amp;nbsp; Other versions this was always changable.&lt;/P&gt;&lt;P&gt;I have unrestricted Metadata using my own ID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why is this field ghosted to me ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a logic puzzle to ponder -&lt;/P&gt;&lt;P&gt;What can we conclude when&lt;/P&gt;&lt;P&gt;1. Wisconsin beats Kentucky&lt;/P&gt;&lt;P&gt;2. Rutgers beats Wisconsin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My answer is "Nothing logical applies. That's why they play the game(s)!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance, Bob&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Apr 2015 17:36:43 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216894#M3297</guid>
      <dc:creator>Bob_Berto</dc:creator>
      <dc:date>2015-04-06T17:36:43Z</dc:date>
    </item>
    <item>
      <title>Re: Change name in User Manager in SMC</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216895#M3298</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Very puzzling, indeed and illogical at first guess :smileyconfused:. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only way I can think of to get a Read-Only pane in the User Plug-ins logged in with unrestricted privileges would be&lt;/P&gt;&lt;P&gt;to have selected the user &lt;EM&gt;inside&lt;/EM&gt; the &lt;STRONG&gt;Members&lt;/STRONG&gt; tab of a Group properties windows by clicking on the 'Properties' buttton.&lt;/P&gt;&lt;P&gt;This button would then &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;open a second window wich looks almost exactly like the User individual object selected from the User plugin list, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;except it is a (Read-Only) glimpse on the user's properties.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.select MyGroup then display Members pane, select a user in the list and click on &lt;EM&gt;Properties&lt;/EM&gt;&lt;/P&gt;&lt;P&gt; &lt;IMG alt="Capture.JPG" class="jive-image-thumbnail jive-image" src="https://communities.sas.com/legacyfs/online/9933_Capture.JPG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;2. User properties windows is obviously (Read-Only) as suggested by the title, the attributes are greyed out accordingly&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture.JPG" class="jive-image-thumbnail jive-image" src="https://communities.sas.com/legacyfs/online/9934_Capture.JPG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried selecting the user directly in the SMC plug-in or indirectly like the method above ? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Apr 2015 12:32:30 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216895#M3298</guid>
      <dc:creator>ronan</dc:creator>
      <dc:date>2015-04-07T12:32:30Z</dc:date>
    </item>
    <item>
      <title>Re: Change name in User Manager in SMC</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216896#M3299</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Upon reading the fine manual (RTFM), page 24 of &lt;STRONG&gt;SAS 9.4 Management Console - Guide to Users and Permissions&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;TIP You cannot change the name of an identity after it is saved.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;You can instead add of change the display name of an identity.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My changing of this field has always been before 9.4&lt;/P&gt;&lt;P&gt;I'l have to look at earlier versions of this book &amp;amp; see what is there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply, Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Apr 2015 13:51:55 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216896#M3299</guid>
      <dc:creator>Bob_Berto</dc:creator>
      <dc:date>2015-04-07T13:51:55Z</dc:date>
    </item>
    <item>
      <title>Re: Change name in User Manager in SMC</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216897#M3300</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Going back to the 9.3 version of the like named manual, page 17, the TIP above is not present.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For now, I will need to live with the real names for users (~200)&lt;/P&gt;&lt;P&gt;I will fix it for the groups with a count of 30 or less.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Apr 2015 14:01:30 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216897#M3300</guid>
      <dc:creator>Bob_Berto</dc:creator>
      <dc:date>2015-04-07T14:01:30Z</dc:date>
    </item>
    <item>
      <title>Re: Change name in User Manager in SMC</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216898#M3301</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nice nice there us a change going on. I see also this one: &lt;A href="http://support.sas.com/documentation/cdl/en/mcsecug/64770/HTML/default/viewer.htm#n05epzfefjyh3dn1xdw2lkaxwyrz.htm" title="http://support.sas.com/documentation/cdl/en/mcsecug/64770/HTML/default/viewer.htm#n05epzfefjyh3dn1xdw2lkaxwyrz.htm"&gt;SAS(R) 9.4 Management Console: Guide to Users and Permissions&lt;/A&gt;&lt;/P&gt;&lt;P&gt;" Tip: We recommend that you avoid using spaces or special characters in the name of a user, group, or role that you create. Not all components support spaces and special characters in identity names."&lt;/P&gt;&lt;P&gt;Until now you could change the name as the products were using that generic URI that the metadata is really using.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These Tips are indicators that not all products are using that anymore or never did or changed by design or never knew that object-uri approach. So they used the typed names instead of that.&lt;BR /&gt;Now you have to design a naming convention to solve that. you could use the object-uri or login-id. And than we see this happening again.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Just an update checking for the word user name. These are used for both the Login-s&amp;nbsp; the name and uri-object. &lt;BR /&gt;Would like to know wich product have become dependend of the user name seen int SMC. SAS-VA? event-manager? VMfabric/midtier? all of them.&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Message was edited by: Jaap Karman&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Apr 2015 14:59:41 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216898#M3301</guid>
      <dc:creator>jakarman</dc:creator>
      <dc:date>2015-04-07T14:59:41Z</dc:date>
    </item>
    <item>
      <title>Re: Change name in User Manager in SMC</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216899#M3302</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the solution. There are new uniqueness &lt;SPAN style="font-size: 13.3333330154419px;"&gt; constraints &lt;/SPAN&gt;beginning with SAS 9.4 enforced by the SMC User Plug-in :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://support.sas.com/documentation/cdl/en/bisecag/67045/PDF/default/bisecag.pdf" title="http://support.sas.com/documentation/cdl/en/bisecag/67045/PDF/default/bisecag.pdf"&gt;http://support.sas.com/documentation/cdl/en/bisecag/67045/PDF/default/bisecag.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;
&lt;P&gt;You cannot change the name of an existing user, group, or role in SAS Management Console. You can change the display name.&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;:smileyshocked:&lt;SPAN style="font-size: 13.3333330154419px;"&gt; . so now, back to the metadata data step functions or even proc metadata queries in order to update a simple Group or Role's name ?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Apr 2015 16:00:36 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216899#M3302</guid>
      <dc:creator>ronan</dc:creator>
      <dc:date>2015-04-07T16:00:36Z</dc:date>
    </item>
    <item>
      <title>Re: Change name in User Manager in SMC</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216900#M3303</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You don't have to revert to code as yet. &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Using SAS Management Console and the Authorization Manager plug-in, navigate to Resource Management &amp;gt; By Type &amp;gt; Person. Right mouse click over &lt;/SPAN&gt;&lt;EM style="font-size: 10pt; line-height: 1.5em;"&gt;NameOfUser&lt;/EM&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; and open the Properties dialog. This basic properties dialog still allows you to change the name of the object.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Having said that, I would exercise caution. I'm assuming that there are good reasons for not changing the name of a user after it has been initially created, otherwise the constraint would not have been introduced in SAS 9.4. Perhaps it is related to the use of name based associations rather than object id based associations (like responsible party metadata for example)? Perhaps a SAS employee might post any additional reasons why changing the name post-creation might have some negative consequences.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Apr 2015 00:03:43 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216900#M3303</guid>
      <dc:creator>PaulHomes</dc:creator>
      <dc:date>2015-04-08T00:03:43Z</dc:date>
    </item>
    <item>
      <title>Re: Change name in User Manager in SMC</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216901#M3304</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Concur with Paul - yes, you can code a workaround, but (as we've probably all realised) with the right level of access (SASAdmin?) it's actually possible to do a lot of damage with code.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've tended to have the User Name match the O/S and/or ActiveDirectory name - which simplifies the SAS ADSync scripts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Apr 2015 00:18:27 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216901#M3304</guid>
      <dc:creator>AndrewHowell</dc:creator>
      <dc:date>2015-04-08T00:18:27Z</dc:date>
    </item>
    <item>
      <title>Re: Change name in User Manager in SMC</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216902#M3305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;After a very quick test in SAS 9.4 M2 , I saw that a renamed user retained their link to their old private user folder. The folder had the old name but there is a metadata object association between the user and the folder that survives the rename. I could also see that with some responsible party metadata, whilst the old name could be seen in the metadata, the object association remained intact. This is by no means an endorsement of changing the name, just a follow up on a couple of items I was curious about. Obviously a quick five minute test like this is nowhere near sufficient for a &lt;SPAN style="font-size: 13.3333330154419px;"&gt;large complex enterprise platform with lots of cooperating software clients/components. &lt;/SPAN&gt;I would still recommend holding off any Person object name changes before finding out from SAS what software components might be impacted and what the ramifications might be.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Apr 2015 00:24:58 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216902#M3305</guid>
      <dc:creator>PaulHomes</dc:creator>
      <dc:date>2015-04-08T00:24:58Z</dc:date>
    </item>
    <item>
      <title>Re: Change name in User Manager in SMC</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216903#M3306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks Paul. The test shows the renaming is still robust as regards associations. I can understand the uniqueness constraint on the User (Person) object name because the object might be linked to different sub-systems therefore uniquely defined :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Metadata personal folder's name&lt;/P&gt;&lt;P&gt;2. Content server (WebDAV) corresponding pathname&lt;/P&gt;&lt;P&gt;3. Report's authoring (Responsible party)&lt;/P&gt;&lt;P&gt;4.Comment's ownership (id. ?)&lt;/P&gt;&lt;P&gt;5.Audit/performance/usage trace as stored in the &lt;SPAN style="color: #353535; font-family: lato, arial, 'Arial Unicode MS', geneva, 'Lucida Grande', sans-serif; font-size: 13.4399995803833px; background-color: #ffffff;"&gt;&lt;A href="http://support.sas.com/documentation/cdl/en/bimtag/66823/HTML/default/viewer.htm#p1wm2vva6wgsynn11oa4hxibn9b5.htm"&gt;SAS Web Infrastructure Platform Data Server&lt;/A&gt; (?)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #353535; font-family: lato, arial, 'Arial Unicode MS', geneva, 'Lucida Grande', sans-serif; font-size: 13.4399995803833px; background-color: #ffffff;"&gt;...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the uniqueness constraint also &lt;SPAN style="font-size: 13.3333330154419px; line-height: 1.5em;"&gt;inexplicably &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;applies&amp;nbsp; to Groups/Roles names : that's a regression from my point of view because those are not fine-grained 'atomic' objects like users but on the contrary, higher level 'storage' objects.&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;This new requirements means you cannot&amp;nbsp; change &lt;/SPAN&gt;&lt;SPAN style="font-size: 13.3333330154419px; line-height: 1.5em;"&gt;anymore &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;your security model on-the-fly using the SMC User manager, groups &amp;amp; roles names must be carefully planned beforehand. Great.&lt;/SPAN&gt;:smileyplain:&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Apr 2015 10:48:04 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216903#M3306</guid>
      <dc:creator>ronan</dc:creator>
      <dc:date>2015-04-08T10:48:04Z</dc:date>
    </item>
    <item>
      <title>Re: Change name in User Manager in SMC</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216904#M3307</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ronan a security model planned and designed using ACT's not the roles/groups/users. The last ones are just administrative processes. Andrew's logical choice for using the accounts as the name is avoiding a lot of translations. Having a wrong name you must backup (selective) then delete and add followed with a restore (selective) according following the tips/limitation.&lt;/P&gt;&lt;P&gt;Not a very nice one for just a wrong name, something to improve.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Apr 2015 13:51:55 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216904#M3307</guid>
      <dc:creator>jakarman</dc:creator>
      <dc:date>2015-04-08T13:51:55Z</dc:date>
    </item>
    <item>
      <title>Re: Change name in User Manager in SMC</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216905#M3308</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jaap. I'm sorry, I don't quite follow you. SAS &lt;SPAN style="font-size: 13.3333330154419px;"&gt;ACTs are interfaces linking target resources (Servers, Folders, Reports) with Users/Groups. Would you recommend not to use Groups but only Users in ACTs ? This wouldn't be a good practice, generally speaking.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;We design our own security models based on Metadata Groups/Roles/ACT/Servers + Operating System permissions (groups/accounts/permissions profiles on folders) + SAS restricted options.Since we implement multitenancy DI + EBI platforms, the standard single SASApp + default groups installment is not sufficient.&lt;/P&gt;&lt;P&gt;SAS metadata security can be very flexible and doesn't require external systems like LDAP Directories security (filters, groups, roles), for instance. &lt;/P&gt;&lt;P&gt;In turn, this flexibility relies for a good part on the convenience to create/alter/delete the main components like Groups, Roles or ACTs. &lt;/P&gt;&lt;P&gt;As you say, it's always possible in order to change the Name attribute of a Group/User/Role to purge it then to re-create it slightly modified : but this is quite tedious instead of a modification on the fly, isn't it ? especially now when we've reached the 4th generation of metadata servers.&lt;/P&gt;&lt;P&gt;Anyway, an explanation for this technical change would be welcome, as Paul suggested.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Apr 2015 14:41:32 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216905#M3308</guid>
      <dc:creator>ronan</dc:creator>
      <dc:date>2015-04-08T14:41:32Z</dc:date>
    </item>
    <item>
      <title>Re: Change name in User Manager in SMC</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216906#M3309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I like the rules of &lt;A href="http://support.sas.com/resources/papers/proceedings11/376-2011.pdf" title="http://support.sas.com/resources/papers/proceedings11/376-2011.pdf"&gt;http://support.sas.com/resources/papers/proceedings11/376-2011.pdf&lt;/A&gt; Although I do not like their example as that is implying copyin the SAS Danish office Organization. Definitely not yours. Like your remark of the stadnard SASApp is not enough. Only for demo and single department it will do.&lt;/P&gt;&lt;P&gt;I would following that recommendation&lt;/P&gt;&lt;P&gt;1/ only setting ACT's on all Artifacts never change (hmm never) change it by adding groups/users for additional rights. &lt;/P&gt;&lt;P&gt;2/ only having groups being mentioned in the ACT's never having users in those.&lt;/P&gt;&lt;P&gt;3/ only adding users to groups (this is the common RBAC process approach). An &lt;A href="http://en.wikipedia.org/wiki/Identity_management_system" title="http://en.wikipedia.org/wiki/Identity_management_system"&gt;Identity management system - Wikipedia, the free encyclopedia&lt;/A&gt; yis becoming often a business requirement with all auditability traceability belonging to those.&lt;/P&gt;&lt;P&gt;Yup, it is some more work adding maintaining Act's as initial steps but they can be made scripted.&amp;nbsp; (batch tools are there)&lt;/P&gt;&lt;P&gt;Put the OS security at the same structure (user/groups) and it must become highly structured with the best achievable security.&amp;nbsp; (No SAS restrictions needed)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes agree for the anyway it is too tedious, explanation welcome.&lt;/P&gt;&lt;P&gt;To be added a dedicated backup/restore with metadata and webdav content (you can store egp projects there) is lacking. &lt;/P&gt;&lt;P&gt;This is normal required functionality having end-users allowed to store data somewhere. &lt;BR /&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Apr 2015 15:07:41 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216906#M3309</guid>
      <dc:creator>jakarman</dc:creator>
      <dc:date>2015-04-08T15:07:41Z</dc:date>
    </item>
    <item>
      <title>Re: Change name in User Manager in SMC</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216907#M3310</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are parallel security mechanisms outside of Metadata in 9.4 that use the name of identities as an effective foreign key. These mechanisms will be impacted when renaming identities. If you'd like to proceed with the renaming process, can you please open a tech support track and we can work through some options to propagate the changes? If you open a track, please ask that I be included on it so we can short circuit the triage and cut to the chase.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Apr 2015 15:11:40 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216907#M3310</guid>
      <dc:creator>nooooooooo</dc:creator>
      <dc:date>2015-04-08T15:11:40Z</dc:date>
    </item>
    <item>
      <title>Re: Change name in User Manager in SMC</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216908#M3311</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ronan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please could you expand on your thoughts regarding how this prevents changing the security model on-the-fly? My take on this is that whilst the name now cannot be, or should not be, changed post-creation, the Display Name (which is shown to the user in most cases) can still be changed. Clearly thought would need to go into setting the Names in the first place (given they need to be unique and preferably have no whitespace/special characters) but you still have the flexibility to change the Display Name at a later date. The Name attribute is used in the userid of any Internal Accounts created, but there would normally be very few of those, and they would most likely be for admin-type people who could probably get by using the old name for login with the Internal Account when needed? I'd be interested to hear of any other areas you're aware of where a constant Name &lt;SPAN style="font-size: 13.3333330154419px;"&gt;would be a concern &lt;/SPAN&gt;(but where the Display Name could still be changed)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Apr 2015 22:00:46 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216908#M3311</guid>
      <dc:creator>PaulHomes</dc:creator>
      <dc:date>2015-04-08T22:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: Change name in User Manager in SMC</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216909#M3312</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Zachary,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for providing some background. Is it possible for you to name some of those software components that are using the &lt;SPAN style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px; background-color: #ffffff;"&gt;parallel security mechanisms. i.e. is there the possibility that some customers might not have those components and so it may not be so much of a concern for them? Having said that, &lt;SPAN style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px; background-color: #ffffff;"&gt;I'm wondering if one of those components might be SAS Environment Manager and so used in all new SAS 9.4 platform installations?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you also able to shed some light on why the Name attribute (known to change on some occasions) was used as an effective foreign key over an unchanging unique key like the metadata object id?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Finally, I believe that the bulk user loading macros (%MDU*) still allow for a Name attribute change when updating users. Will these macros be modified in a later release to prevent Name attribute changes too?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Apr 2015 22:08:02 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216909#M3312</guid>
      <dc:creator>PaulHomes</dc:creator>
      <dc:date>2015-04-08T22:08:02Z</dc:date>
    </item>
    <item>
      <title>Re: Change name in User Manager in SMC</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216910#M3313</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Paul,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The so-called 'security model' is not affected by changing any attributes of the User. We all agree that it's preferable to keep a user name stable over time, especially since it often comes for the external directory (security requirement) and, as Andrew points out, is used as a primary key in the synchronization process (%MDU) between metadata and LDAP. The security model is like the fortress walls of defence, it doesn't go as far as the soldier's uniform (in my own personal view).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's not the same with the underlying Metadata Groups or Roles structure supporting the permissions : in this case, the distinction between Name and Display Name is pointless in my opinion ; as far as I know, there is only one default interface to display both and it's the SMC User Manager (+New Environment Manager). The Diagnostic Portlet of the SAS BI Portal is the only exception I can think of which also displays Groups and Roles (actual names). Besides at least wirh 9.2/9.3, the Display Name is not a required attribute for the Group or Role so that usually we simply omit to fill in the place with a value.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the Group name might be used elsewhere as a security parameter : OLAP Dimension MDX condition, Information Map Group-based filter, we don't change it every week, of course : its naming must be stable over time. However, setting up a new model might involve many change of names and we speak of dozens of Groups / Roles on large multitenant platforms... The unability to change the names 'conveniently' using the User Manager implies tedious workarounds :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Systematically using the Display Name in addition to the Name : great, two values instead of one previously:smileyplain:&lt;/P&gt;&lt;P&gt;2. Purging/re-creating the Group / Role whenever we change our minds to rename it ...&lt;/P&gt;&lt;P&gt;3. Coding a new User Manager based on Metadata requests which adresses the need ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This new requirement might not be very cost-efficient in the long run.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Apr 2015 11:05:05 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216910#M3313</guid>
      <dc:creator>ronan</dc:creator>
      <dc:date>2015-04-09T11:05:05Z</dc:date>
    </item>
    <item>
      <title>Re: Change name in User Manager in SMC</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216911#M3314</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ronan, You mentioned one place where hard code the names of user (or display name) is used: the cubes at row level.&lt;/P&gt;&lt;P&gt;As it is programmed by application/report builders it can cause headaches by lack of standards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another is Zachary's paper &lt;A href="http://support.sas.com/resources/papers/proceedings11/017-2011.pdf" title="http://support.sas.com/resources/papers/proceedings11/017-2011.pdf"&gt;http://support.sas.com/resources/papers/proceedings11/017-2011.pdf&lt;/A&gt;. As he explaining the user and password are part of the REST http approach easily to decode as it is base64. By that only to be accepted when there is encryption over the wire. That implies it could by seen and leaked with loggings tracing the webtraffic at an unencrypted point.&amp;nbsp; Security by obscurity is not very sensible for a real service level.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Apr 2015 11:14:25 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216911#M3314</guid>
      <dc:creator>jakarman</dc:creator>
      <dc:date>2015-04-09T11:14:25Z</dc:date>
    </item>
    <item>
      <title>Re: Change name in User Manager in SMC</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216912#M3315</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for expanding on your previous comment Ronan. It's good to hear the how other admins use SAS and the impacts on their workflow. In regards to the &lt;SPAN style="font-size: 13.3333330154419px;"&gt;key for identity synchronization, i&lt;/SPAN&gt;n my case, I prefer not to use the user id, due to its capacity to change over time. I have worked with sites in the past where user ids change due to natural name changes, and in some cases contractors get a new user id (but same display name) for each non-contiguous contract term [ that presented some challenges &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://communities.sas.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt; ]. My personal preference for the key is a GUID, SID, or employee id where available - something that is less likely to change over time.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Apr 2015 23:17:44 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216912#M3315</guid>
      <dc:creator>PaulHomes</dc:creator>
      <dc:date>2015-04-09T23:17:44Z</dc:date>
    </item>
    <item>
      <title>Re: Change name in User Manager in SMC</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216913#M3316</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good advice. Thanks Paul.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Apr 2015 08:11:04 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Change-name-in-User-Manager-in-SMC/m-p/216913#M3316</guid>
      <dc:creator>ronan</dc:creator>
      <dc:date>2015-04-10T08:11:04Z</dc:date>
    </item>
  </channel>
</rss>

