<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Permission Help in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/Permission-Help/m-p/341741#M7958</link>
    <description>This is where you got yourself into trouble.&lt;BR /&gt;"I have also changed the corporate permission which was inherited from the Corporate folder to deny RM so only users in the Accounting group can see the accounting folder"&lt;BR /&gt;Rather than doing the above "reapply" HIDE PUBLIC and SASUSER ACT to the individual sub folders and grant back only the group that you need.&lt;BR /&gt;Golden rule is to deny broadly (SASUSER/PUBLIC) and grant back narrow.  When you deny a group other than SASUSER/PUBLIC you end up in Bob's scenario and the "deny" wins because Bob is both a member of Corporate and Accounting.&lt;BR /&gt;Take a look at this paper you should find It useful.  You broke rule #3 &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; and what you need in your scenario is #4&lt;BR /&gt;&lt;A href="http://support.sas.com/resources/papers/proceedings11/376-2011.pdf" target="_blank"&gt;http://support.sas.com/resources/papers/proceedings11/376-2011.pdf&lt;/A&gt;&lt;BR /&gt;</description>
    <pubDate>Thu, 16 Mar 2017 19:49:19 GMT</pubDate>
    <dc:creator>angian</dc:creator>
    <dc:date>2017-03-16T19:49:19Z</dc:date>
    <item>
      <title>Permission Help</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Permission-Help/m-p/341589#M7944</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to set up a folder structure with permissions assigned and looking for some assistance.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is what I have and I don't understand why the permissions are being effective the way they are.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Folder structure is like so:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Corporate&lt;/P&gt;&lt;P&gt;-Accounting&lt;/P&gt;&lt;P&gt;-AML&lt;/P&gt;&lt;P&gt;-etc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a HIDE PUBLIC and SASUSER ACT applied &amp;nbsp;to the corporate folder - which only has SASUSER / PUBLIC ReadMetadata set to Deny applied&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Next I have a Corporate Group assigned to the Corporate folder with ReadMetadata set to Grant.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then I have individual groups for Accounting, AML, etc assigned to each of the sub folders of Corporate with RM, WM, WMM, CheckInMetaData, Read as Grant. I have also changed the corporate permission which was inherited from the Corporate folder to deny RM so only users in the Accounting group can see the accounting folder.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My scenario -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;User Bob is in the Corporate Group and AML Group. He is able to see the Corporate folder but not the AML folder.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I change the corporate group to RM on all the subfolder , User Bob is not only able to see the AML folder, but is able to see all the folders.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please instruct what I am doing wrong and how I can make happen what I'm trying to do.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2017 14:15:41 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Permission-Help/m-p/341589#M7944</guid>
      <dc:creator>ardobbins</dc:creator>
      <dc:date>2017-03-16T14:15:41Z</dc:date>
    </item>
    <item>
      <title>Re: Permission Help</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Permission-Help/m-p/341741#M7958</link>
      <description>This is where you got yourself into trouble.&lt;BR /&gt;"I have also changed the corporate permission which was inherited from the Corporate folder to deny RM so only users in the Accounting group can see the accounting folder"&lt;BR /&gt;Rather than doing the above "reapply" HIDE PUBLIC and SASUSER ACT to the individual sub folders and grant back only the group that you need.&lt;BR /&gt;Golden rule is to deny broadly (SASUSER/PUBLIC) and grant back narrow.  When you deny a group other than SASUSER/PUBLIC you end up in Bob's scenario and the "deny" wins because Bob is both a member of Corporate and Accounting.&lt;BR /&gt;Take a look at this paper you should find It useful.  You broke rule #3 &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; and what you need in your scenario is #4&lt;BR /&gt;&lt;A href="http://support.sas.com/resources/papers/proceedings11/376-2011.pdf" target="_blank"&gt;http://support.sas.com/resources/papers/proceedings11/376-2011.pdf&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 16 Mar 2017 19:49:19 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Permission-Help/m-p/341741#M7958</guid>
      <dc:creator>angian</dc:creator>
      <dc:date>2017-03-16T19:49:19Z</dc:date>
    </item>
  </channel>
</rss>

