<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User Administration Team? in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/User-Administration-Team/m-p/94129#M786</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you create the new role to limit access to the User Manager plug-in, watch out for the "Management Console: Content Management" role which has SASUSERS as a member by default.&amp;nbsp; Unless you remove the SASUSERS membership from that role, your restricted user administrators will still get access to the User Manager, Authorization Manager, Data Library Manager, Folder tab &amp;amp; Search tab. I did a &lt;A href="http://platformadmin.com/blogs/paul/2011/04/capability-reviewer-preview/"&gt;blog post&lt;/A&gt; a while back which discussed multiple access paths to a capability. However, removing SASUSERS from the content management role will also impact any existing non-administrative users of SAS Management Console (maybe DI developers), so you may want to add those user's group(s) back as members of the role to ensure continued access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will your restricted user administrators be managing Portal &lt;A href="http://support.sas.com/documentation/cdl/en/biwaag/64769/HTML/default/viewer.htm#ag_grant_groupadmin.htm"&gt;Group Content Administrators&lt;/A&gt;?&amp;nbsp; If so then they will also need access to the Authorization Manager plug-in to be able to set appropriate permissions on portal permission trees.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm assuming you have also considered &lt;A href="http://support.sas.com/documentation/cdl/en/bisecag/63082/HTML/default/viewer.htm#n0l2hp5m00a1z2n1b598q4pknfih.htm"&gt;identity synchronization&lt;/A&gt; with Active Directory, LDAP or other sources of user, group and membership information.&amp;nbsp; That can significantly reduce the requirement for manual identity management in SAS Management Console by help desk staff.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you haven't already seen them, I'd recommend reading the follow resources too:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="http://support.sas.com/documentation/cdl/en/mcsecug/63190/HTML/default/viewer.htm#titlepage.htm"&gt;SAS® Management Console: Guide to Users and Permissions&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="http://support.sas.com/documentation/cdl/en/bisecag/63082/HTML/default/viewer.htm#titlepage.htm"&gt;SAS® Intelligence Platform: Security Administration Guide&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;SAS Global Forum 2010 Paper 324-2010 "&lt;A href="http://support.sas.com/resources/papers/proceedings10/324-2010.pdf"&gt;Be All That You Can Be: Best Practices in Using Roles to Control Functionality in SAS® 9.2&lt;/A&gt;" by Kathy Wisniewski&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 28 Jun 2012 02:43:02 GMT</pubDate>
    <dc:creator>PaulHomes</dc:creator>
    <dc:date>2012-06-28T02:43:02Z</dc:date>
    <item>
      <title>User Administration Team?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/User-Administration-Team/m-p/94128#M785</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm a brand new SAS administrator who's been thrust into the middle of my company's fledgling SAS implementation, and I'm slowly getting up to speed with the environment.&amp;nbsp; I have a quick question regarding setting up user administration.&amp;nbsp; We have a team of help desk employees that are focused on security administration (things like fileshare access, user account activations/deactivations, etc.)&amp;nbsp; I want to look into giving them rights to do basic user administration (account creation/deletion, role/group membership) in SAS without (at least initially) giving them the ability to modify other things.&amp;nbsp; It looks like this is the basic process:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Add a SAS group for the users&lt;/P&gt;&lt;P&gt;2) Give the SAS group the "Metadata Server: User Administration" role.&amp;nbsp; Also create a new role that gives them access only to the User Manager plugin in Management Console, and assign that role to the SAS group.&lt;/P&gt;&lt;P&gt;3) Add SAS user accounts for the help desk users, and put those SAS user accounts into the new SAS group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I missing anything here, or am I on the right track?&amp;nbsp; Any tips or best practices would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2012 19:02:33 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/User-Administration-Team/m-p/94128#M785</guid>
      <dc:creator>JohnMay</dc:creator>
      <dc:date>2012-06-27T19:02:33Z</dc:date>
    </item>
    <item>
      <title>Re: User Administration Team?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/User-Administration-Team/m-p/94129#M786</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you create the new role to limit access to the User Manager plug-in, watch out for the "Management Console: Content Management" role which has SASUSERS as a member by default.&amp;nbsp; Unless you remove the SASUSERS membership from that role, your restricted user administrators will still get access to the User Manager, Authorization Manager, Data Library Manager, Folder tab &amp;amp; Search tab. I did a &lt;A href="http://platformadmin.com/blogs/paul/2011/04/capability-reviewer-preview/"&gt;blog post&lt;/A&gt; a while back which discussed multiple access paths to a capability. However, removing SASUSERS from the content management role will also impact any existing non-administrative users of SAS Management Console (maybe DI developers), so you may want to add those user's group(s) back as members of the role to ensure continued access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will your restricted user administrators be managing Portal &lt;A href="http://support.sas.com/documentation/cdl/en/biwaag/64769/HTML/default/viewer.htm#ag_grant_groupadmin.htm"&gt;Group Content Administrators&lt;/A&gt;?&amp;nbsp; If so then they will also need access to the Authorization Manager plug-in to be able to set appropriate permissions on portal permission trees.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm assuming you have also considered &lt;A href="http://support.sas.com/documentation/cdl/en/bisecag/63082/HTML/default/viewer.htm#n0l2hp5m00a1z2n1b598q4pknfih.htm"&gt;identity synchronization&lt;/A&gt; with Active Directory, LDAP or other sources of user, group and membership information.&amp;nbsp; That can significantly reduce the requirement for manual identity management in SAS Management Console by help desk staff.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you haven't already seen them, I'd recommend reading the follow resources too:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="http://support.sas.com/documentation/cdl/en/mcsecug/63190/HTML/default/viewer.htm#titlepage.htm"&gt;SAS® Management Console: Guide to Users and Permissions&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="http://support.sas.com/documentation/cdl/en/bisecag/63082/HTML/default/viewer.htm#titlepage.htm"&gt;SAS® Intelligence Platform: Security Administration Guide&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;SAS Global Forum 2010 Paper 324-2010 "&lt;A href="http://support.sas.com/resources/papers/proceedings10/324-2010.pdf"&gt;Be All That You Can Be: Best Practices in Using Roles to Control Functionality in SAS® 9.2&lt;/A&gt;" by Kathy Wisniewski&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2012 02:43:02 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/User-Administration-Team/m-p/94129#M786</guid>
      <dc:creator>PaulHomes</dc:creator>
      <dc:date>2012-06-28T02:43:02Z</dc:date>
    </item>
    <item>
      <title>Re: User Administration Team?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/User-Administration-Team/m-p/94130#M787</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Paul,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you so much for the detailed and informative response!&amp;nbsp; I have read a couple of the linked documents, but there's definitely some more information in there that I haven't seen yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as managing Group Content Administrators, I don't think they'll be responsible for that yet, but it's a possibility as use of SAS grows within our company.&amp;nbsp; Right now it's only 5 or so users, but we anticipate that to grow pretty rapidly once we really start using it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hadn't seen the bit about identity sync, I will definitely have to look at that.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I plan on taking SAS Platform Administration training very soon, so hopefully that will help fill in some of the blanks as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for helping a SAS newbie!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2012 13:10:30 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/User-Administration-Team/m-p/94130#M787</guid>
      <dc:creator>JohnMay</dc:creator>
      <dc:date>2012-06-28T13:10:30Z</dc:date>
    </item>
  </channel>
</rss>

