<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Basic User Permissions: how do I restrict users with permissions in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/Basic-User-Permissions-how-do-I-restrict-users-with-permissions/m-p/282360#M5397</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;probably you are giving too many permissions to the SASUSERS or PUBLIC groups.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://support.sas.com/documentation/cdl/en/bisecag/67045/HTML/default/viewer.htm#n0pt0r7u55rqu2n1cdu2wvt47j78.htm" target="_blank"&gt;http://support.sas.com/documentation/cdl/en/bisecag/67045/HTML/default/viewer.htm#n0pt0r7u55rqu2n1cdu2wvt47j78.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- PUBLIC should have deny on all the metadata. (on the Default ACT would make life much easier to you).&lt;/P&gt;
&lt;P&gt;- SASUSERS should have allow read metadata by default (on the Default ACT), the other permissions should be denied.&lt;/P&gt;
&lt;P&gt;- Then, on the folders, SASUSERS and PUBLIC should have Denied all.&lt;/P&gt;
&lt;P&gt;- Ensure the SAS Administrators have full permissions on each folder.&lt;/P&gt;
&lt;P&gt;- Ensure the SAS System Services can have the required permissions:&amp;nbsp;&lt;SPAN&gt;SAS System Services group a grant of ReadMetadata permission on the folders.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- Then provide the required permissions to groups on the root folders.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- Deny the permissions to groups should not access on the root folders.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;And again, if you can implement this with ACTs, this is a bit more time in the begining, it requires some design, but afterwards your life will be easier &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="http://support.sas.com/documentation/cdl/en/bisecag/63082/HTML/default/viewer.htm#p0vhii6t8n64a0n154l3db92mp0w.htm" target="_blank"&gt;http://support.sas.com/documentation/cdl/en/bisecag/63082/HTML/default/viewer.htm#p0vhii6t8n64a0n154l3db92mp0w.htm&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="http://support.sas.com/documentation/cdl/en/bisecag/61133/HTML/default/viewer.htm#a003271263.htm" target="_blank"&gt;http://support.sas.com/documentation/cdl/en/bisecag/61133/HTML/default/viewer.htm#a003271263.htm&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I hope this can help you a bit.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 06 Jul 2016 07:50:14 GMT</pubDate>
    <dc:creator>JuanS_OCS</dc:creator>
    <dc:date>2016-07-06T07:50:14Z</dc:date>
    <item>
      <title>Basic User Permissions: how do I restrict users with permissions</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Basic-User-Permissions-how-do-I-restrict-users-with-permissions/m-p/282312#M5394</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am new application administrator at my institue and have been told I will be working with our SAS softwar. &amp;nbsp;I have two co-workers who have been at the institue through the first phase (SAS is brand new to our institue) of installation SAS. &amp;nbsp;Currenlty the tech that our institue talking with is helping a department set up an appropriate file structure. &amp;nbsp;What I am trying to wrap my head around are the user permissions. &amp;nbsp;We currenlty are using PUBLIC type users that receieve their sign on from our Active Directory. &amp;nbsp;Problem I am running into is every one can see every one else's folders and information. &amp;nbsp;I have looked over several documents but can't wrap my head around the permissions. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These are the doucuments I have been looking at. We are using SAS Managment Console 9.4&lt;/P&gt;&lt;P&gt;1.&amp;nbsp;&lt;A href="http://support.sas.com/documentation/cdl/en/bisecag/67045/HTML/default/viewer.htm#p03h42tf0s7ogyn1pqtsesbu3xuk.htm" target="_blank"&gt;http://support.sas.com/documentation/cdl/en/bisecag/67045/HTML/default/viewer.htm#p03h42tf0s7ogyn1pqtsesbu3xuk.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;2.&lt;A href="http://support.sas.com/documentation/cdl/en/bisecag/67045/HTML/default/viewer.htm#p0soxnjm1vtia9n10f9n7ll0ptnr.htm" target="_blank"&gt;http://support.sas.com/documentation/cdl/en/bisecag/67045/HTML/default/viewer.htm#p0soxnjm1vtia9n10f9n7ll0ptnr.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;3.&lt;A href="http://support.sas.com/documentation/cdl/en/bisag/68240/HTML/default/viewer.htm#n0sopkld74t0wyn1b3wrkjpylddn.htm" target="_blank"&gt;http://support.sas.com/documentation/cdl/en/bisag/68240/HTML/default/viewer.htm#n0sopkld74t0wyn1b3wrkjpylddn.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;4.&lt;A href="http://support.sas.com/documentation/cdl/en/bisecag/67045/HTML/default/viewer.htm#n1gwrrpfx9ujqun17syl8yknhgy0.htm" target="_blank"&gt;http://support.sas.com/documentation/cdl/en/bisecag/67045/HTML/default/viewer.htm#n1gwrrpfx9ujqun17syl8yknhgy0.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;5.&lt;A href="http://support.sas.com/documentation/cdl/en/mcsecug/64770/HTML/default/viewer.htm#n1onkjqqkpz6fin1k0rnufxp57ie.htm" target="_blank"&gt;http://support.sas.com/documentation/cdl/en/mcsecug/64770/HTML/default/viewer.htm#n1onkjqqkpz6fin1k0rnufxp57ie.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have found that Roles allow me to limit groups or user to which applications they can see be I don't understand how I can limit groups into seeing only certain folders.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If someone could assist me into breaking this infromation down to more easily digestable information or provide me with an example of how do I make one person not be able to look at another person's file that would be great.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2016 22:47:30 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Basic-User-Permissions-how-do-I-restrict-users-with-permissions/m-p/282312#M5394</guid>
      <dc:creator>wjsnyder</dc:creator>
      <dc:date>2016-07-05T22:47:30Z</dc:date>
    </item>
    <item>
      <title>Re: Basic User Permissions: how do I restrict users with permissions</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Basic-User-Permissions-how-do-I-restrict-users-with-permissions/m-p/282360#M5397</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;probably you are giving too many permissions to the SASUSERS or PUBLIC groups.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://support.sas.com/documentation/cdl/en/bisecag/67045/HTML/default/viewer.htm#n0pt0r7u55rqu2n1cdu2wvt47j78.htm" target="_blank"&gt;http://support.sas.com/documentation/cdl/en/bisecag/67045/HTML/default/viewer.htm#n0pt0r7u55rqu2n1cdu2wvt47j78.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- PUBLIC should have deny on all the metadata. (on the Default ACT would make life much easier to you).&lt;/P&gt;
&lt;P&gt;- SASUSERS should have allow read metadata by default (on the Default ACT), the other permissions should be denied.&lt;/P&gt;
&lt;P&gt;- Then, on the folders, SASUSERS and PUBLIC should have Denied all.&lt;/P&gt;
&lt;P&gt;- Ensure the SAS Administrators have full permissions on each folder.&lt;/P&gt;
&lt;P&gt;- Ensure the SAS System Services can have the required permissions:&amp;nbsp;&lt;SPAN&gt;SAS System Services group a grant of ReadMetadata permission on the folders.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- Then provide the required permissions to groups on the root folders.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- Deny the permissions to groups should not access on the root folders.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;And again, if you can implement this with ACTs, this is a bit more time in the begining, it requires some design, but afterwards your life will be easier &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="http://support.sas.com/documentation/cdl/en/bisecag/63082/HTML/default/viewer.htm#p0vhii6t8n64a0n154l3db92mp0w.htm" target="_blank"&gt;http://support.sas.com/documentation/cdl/en/bisecag/63082/HTML/default/viewer.htm#p0vhii6t8n64a0n154l3db92mp0w.htm&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="http://support.sas.com/documentation/cdl/en/bisecag/61133/HTML/default/viewer.htm#a003271263.htm" target="_blank"&gt;http://support.sas.com/documentation/cdl/en/bisecag/61133/HTML/default/viewer.htm#a003271263.htm&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I hope this can help you a bit.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2016 07:50:14 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Basic-User-Permissions-how-do-I-restrict-users-with-permissions/m-p/282360#M5397</guid>
      <dc:creator>JuanS_OCS</dc:creator>
      <dc:date>2016-07-06T07:50:14Z</dc:date>
    </item>
    <item>
      <title>Re: Basic User Permissions: how do I restrict users with permissions</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Basic-User-Permissions-how-do-I-restrict-users-with-permissions/m-p/282907#M5420</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/93300"&gt;@wjsnyder﻿&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like to follow up the progress of your question.&amp;nbsp;Was your question resolved ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you in advance,&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Juan&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2016 11:08:50 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Basic-User-Permissions-how-do-I-restrict-users-with-permissions/m-p/282907#M5420</guid>
      <dc:creator>JuanS_OCS</dc:creator>
      <dc:date>2016-07-08T11:08:50Z</dc:date>
    </item>
    <item>
      <title>Re: Basic User Permissions: how do I restrict users with permissions</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Basic-User-Permissions-how-do-I-restrict-users-with-permissions/m-p/282994#M5422</link>
      <description>&lt;P&gt;Juan,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It was these references pointed me to where I need to go to be able to get a sound foundational understanding of the environment in front of me. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Wayne&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2016 15:28:28 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Basic-User-Permissions-how-do-I-restrict-users-with-permissions/m-p/282994#M5422</guid>
      <dc:creator>wjsnyder</dc:creator>
      <dc:date>2016-07-08T15:28:28Z</dc:date>
    </item>
  </channel>
</rss>

