<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Permissions R and RW from different users on the same library in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/Permissions-R-and-RW-from-different-users-on-the-same-library/m-p/367835#M9039</link>
    <description>&lt;P&gt;You need to make your libraries metadata-bound, so they can only be used with the metadara engine.&lt;/P&gt;
&lt;P&gt;Or you invest the necessary time to design a proper group structure in the OS. And solve the extreme cases with access control lists.&lt;/P&gt;</description>
    <pubDate>Fri, 16 Jun 2017 18:01:17 GMT</pubDate>
    <dc:creator>Kurt_Bremser</dc:creator>
    <dc:date>2017-06-16T18:01:17Z</dc:date>
    <item>
      <title>Permissions R and RW from different users on the same library</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Permissions-R-and-RW-from-different-users-on-the-same-library/m-p/367782#M9034</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have to set up some users and libraries on a SAS system.&lt;/P&gt;&lt;P&gt;Let's say I have library LIB and user A and B&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want that A has read permissions to LIB&lt;/P&gt;&lt;P&gt;I want that B has read and write permissions to LIB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I set up those permissions explicitly on the Managemente Console user A has only Read Metadata allowed and all the rest denied&lt;/P&gt;&lt;P&gt;user B has all permissions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The result is that when I log on Enterprise Guide as user A, I can modify existing tables in LIB, create new ones, delete existing ones, even if the these permissions are denied.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How is this possible?&lt;/P&gt;&lt;P&gt;How can I implement this idea?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 16:11:56 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Permissions-R-and-RW-from-different-users-on-the-same-library/m-p/367782#M9034</guid>
      <dc:creator>Crysis85</dc:creator>
      <dc:date>2017-06-16T16:11:56Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions R and RW from different users on the same library</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Permissions-R-and-RW-from-different-users-on-the-same-library/m-p/367786#M9035</link>
      <description>&lt;P&gt;From a Unix perspective, you handle this by defining groups. &amp;nbsp;(You may not have the authority to set up and maintain a group, so you may need to get help on this.) &amp;nbsp;Add one user to the group, but not the other.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That's what the middle set of permissions controls ... group access. &amp;nbsp;Or in shorter terms, 774 = all for LIB owner, all for group, read only for the rest of the world.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After logging on, a user might have to switch from his default group over to your group to gain access.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 16:23:31 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Permissions-R-and-RW-from-different-users-on-the-same-library/m-p/367786#M9035</guid>
      <dc:creator>Astounding</dc:creator>
      <dc:date>2017-06-16T16:23:31Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions R and RW from different users on the same library</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Permissions-R-and-RW-from-different-users-on-the-same-library/m-p/367799#M9036</link>
      <description>&lt;P&gt;I thought of that but It's not feasible because there are many more users and many more libraries? Isn't possible to set this up on the management console? What's the point of the Management Console with all the fine grained permissions if they don't work?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 16:54:25 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Permissions-R-and-RW-from-different-users-on-the-same-library/m-p/367799#M9036</guid>
      <dc:creator>Crysis85</dc:creator>
      <dc:date>2017-06-16T16:54:25Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions R and RW from different users on the same library</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Permissions-R-and-RW-from-different-users-on-the-same-library/m-p/367833#M9037</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;permissions / metadata security works well, lets see if we can figure out the problem.&lt;/P&gt;
&lt;P&gt;What version of SAS are you using, and what's the EG version?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you familiar with this info:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Use and Enforcement of Permissions:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://support.sas.com/documentation/cdl/en/bisecag/69827/HTML/default/viewer.htm#p1b2lkywlgefxcn14v68kok29w1b.htm" target="_blank"&gt;http://support.sas.com/documentation/cdl/en/bisecag/69827/HTML/default/viewer.htm#p1b2lkywlgefxcn14v68kok29w1b.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Permissions by Object&lt;/P&gt;
&lt;P&gt;&lt;A href="http://support.sas.com/documentation/cdl/en/bisecag/69827/HTML/default/viewer.htm#n0pt0r7u55rqu2n1cdu2wvt47j78.htm" target="_blank"&gt;http://support.sas.com/documentation/cdl/en/bisecag/69827/HTML/default/viewer.htm#n0pt0r7u55rqu2n1cdu2wvt47j78.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Permissions by Tasks&lt;/P&gt;
&lt;P&gt;&lt;A href="http://support.sas.com/documentation/cdl/en/bisecag/69827/HTML/default/viewer.htm#n0bxpw0fyk4srkn1xp0yhc2gvq4g.htm" target="_blank"&gt;http://support.sas.com/documentation/cdl/en/bisecag/69827/HTML/default/viewer.htm#n0bxpw0fyk4srkn1xp0yhc2gvq4g.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Anja&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 17:58:07 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Permissions-R-and-RW-from-different-users-on-the-same-library/m-p/367833#M9037</guid>
      <dc:creator>anja</dc:creator>
      <dc:date>2017-06-16T17:58:07Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions R and RW from different users on the same library</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Permissions-R-and-RW-from-different-users-on-the-same-library/m-p/367834#M9038</link>
      <description>&lt;P&gt;P.S. where did you apply the permissions, via Lib Manager or the SAS Folders?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 17:59:49 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Permissions-R-and-RW-from-different-users-on-the-same-library/m-p/367834#M9038</guid>
      <dc:creator>anja</dc:creator>
      <dc:date>2017-06-16T17:59:49Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions R and RW from different users on the same library</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Permissions-R-and-RW-from-different-users-on-the-same-library/m-p/367835#M9039</link>
      <description>&lt;P&gt;You need to make your libraries metadata-bound, so they can only be used with the metadara engine.&lt;/P&gt;
&lt;P&gt;Or you invest the necessary time to design a proper group structure in the OS. And solve the extreme cases with access control lists.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 18:01:17 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Permissions-R-and-RW-from-different-users-on-the-same-library/m-p/367835#M9039</guid>
      <dc:creator>Kurt_Bremser</dc:creator>
      <dc:date>2017-06-16T18:01:17Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions R and RW from different users on the same library</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Permissions-R-and-RW-from-different-users-on-the-same-library/m-p/367861#M9040</link>
      <description>&lt;P&gt;... and don't forget that table objects in metadata inherit permissions from the metadata folder in which they are contained and not the metadata library in which they are registered. For consistency you can assign permissions to a metadata folder containing both the library and the tables. Also keep in mind &lt;A href="https://communities.sas.com/t5/SAS-Communities-Library/Five-papers-on-Recommended-SAS-9-4-Security-Model-Design-part-1/ta-p/361569" target="_self"&gt;metadata security recommended practices&lt;/A&gt; and assign permissions, ideally via ACTs, on the folder, for groups (not users), only denying permissions broadly (to PUBLIC or SASUSERS) and then granting back to appropriate groups.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You will also want&amp;nbsp;to consider how the library is being assigned: which engine: native or Metadata Libname Engine (MLE), and where&amp;nbsp;necessary the MLE &lt;A href="https://support.sas.com/documentation/cdl/en/lrmeta/70119/HTML/default/viewer.htm#n16hsug0xiczidn141ezc7rlz8rb.htm" target="_self"&gt;metaout&lt;/A&gt; value, and&amp;nbsp;the &lt;A href="https://support.sas.com/documentation/cdl/en/bidaag/69847/HTML/default/viewer.htm#n0q2tcajzroq94n1710lh703n1ue.htm" target="_self"&gt;AssignMode&lt;/A&gt; extended attribute value.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 19:26:36 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Permissions-R-and-RW-from-different-users-on-the-same-library/m-p/367861#M9040</guid>
      <dc:creator>PaulHomes</dc:creator>
      <dc:date>2017-06-16T19:26:36Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions R and RW from different users on the same library</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Permissions-R-and-RW-from-different-users-on-the-same-library/m-p/367931#M9043</link>
      <description>&lt;P&gt;I think I followed the best practices. I set up the folder structures like this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;General_Folder___Folder_GroupA&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;___Folder_GroupB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I set up 3 ACT: ACT_A has all the permissions for user A, and read only permission for user B, ACT_B the opposite and i set up a "Deny_SASuser" to deny permission on SASUSER&lt;/P&gt;&lt;P&gt;On Folder_GroupA (which will cointain tabs that userA should be able to write and read and userB read only) i assign ACT_A and Deny_SASUSER.&lt;/P&gt;&lt;P&gt;On Folder_GroupB ACT_B and Deny_SASUSER&lt;/P&gt;&lt;P&gt;I then create a library in Folder_GroupA (native library, preassigned). I check the permissions on the new library. User permissions are all inherited as I wanted (all the appropried "greens" and "greys"). UserA has all the permissions, UserB has only read metadata and read.&lt;/P&gt;&lt;P&gt;I then log as UserA on EG (7.1 by the way) and I can create all the tabs that I want. Problem is that, when I log as UserB I can do the same.&lt;/P&gt;&lt;P&gt;I'd like, if possible, more clarification on native/ML engine. I tried to set Metadata Libname Engine but then I couldn't manage to create any tables with any user.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Jun 2017 06:09:54 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Permissions-R-and-RW-from-different-users-on-the-same-library/m-p/367931#M9043</guid>
      <dc:creator>Crysis85</dc:creator>
      <dc:date>2017-06-17T06:09:54Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions R and RW from different users on the same library</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Permissions-R-and-RW-from-different-users-on-the-same-library/m-p/367990#M9046</link>
      <description>&lt;P&gt;What you have done sounds about right for ensuring appropriate metadata permissions but you will also need to consider file system&amp;nbsp;permissions too, being aware&amp;nbsp;of&amp;nbsp;the difference between creating physical tables (SAS datasets) in the physical directory in the file system and (optionally) registering those tables in metadata folders. You can create physical tables without registering the tables in metadata (and vice-versa). You might also want to submit a "libname _all_ list;"&amp;nbsp;in EG to see how all of the libraries have been assigned and what engines are being used.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You wont be able to create tables in a MLE library uless you use one of the metaout options that supports it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you have found, this is quite a complex area with all of the various considerations. I would suggest one of the best ways to get a handle on this is to attend the SAS Platform Administration Fast Track course which covers many of these concepts.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As has been suggested by others, the 2 main options&amp;nbsp;that admins use to control access to metadata and physical layers is to align metadata and file system access controls&amp;nbsp;or use metadata bound libraries (to enforce the use of the metadata authorization layer).&lt;/P&gt;</description>
      <pubDate>Sat, 17 Jun 2017 22:11:45 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Permissions-R-and-RW-from-different-users-on-the-same-library/m-p/367990#M9046</guid>
      <dc:creator>PaulHomes</dc:creator>
      <dc:date>2017-06-17T22:11:45Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions R and RW from different users on the same library</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Permissions-R-and-RW-from-different-users-on-the-same-library/m-p/368712#M9067</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Enclosed some info on metadata bound libraries:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A title="What is a metadata bound lib" href="http://support.sas.com/documentation/cdl/en/seclibag/66930/HTML/default/viewer.htm#n0tzurc8qfze0vn13z4n6j6mzz14.htm" target="_self"&gt;What is a metadata bound lib&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Great blog from Paul:&lt;/P&gt;
&lt;P&gt;&lt;A title="Creating metadata bound libs" href="https://platformadmin.com/blogs/paul/2013/10/sas94-metadata-bound-library/" target="_self"&gt;Creating metadata bound libs&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A title="Lockdown" href="http://www.sascommunity.org/planet/blog/category/metadata-bound-libraries/" target="_self"&gt;Lockdown&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Anja&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2017 13:50:56 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Permissions-R-and-RW-from-different-users-on-the-same-library/m-p/368712#M9067</guid>
      <dc:creator>anja</dc:creator>
      <dc:date>2017-06-20T13:50:56Z</dc:date>
    </item>
  </channel>
</rss>

