<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security Question SAS VA - designer and viewer in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/Security-Question-SAS-VA-designer-and-viewer/m-p/368317#M9057</link>
    <description>&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;Hi,&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;a few questions:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;Did you assign the permissions in VA or SAS Management Console, and, if the latter, did you assign&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;the permissions on the SAS Folders?&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;If a user is not allowed to access a data set, you would have to deny permissions on that data set,&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;for that user.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;The problem with that is, if there are several users that have access to some of the data sets&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;in domain A, B and C, but not to others, it can become hard to administer this.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;Would it maybe be possible to modify the domain A, B and C as such either the data sets the &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;users &lt;/FONT&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;have access to are in one lib/folder, and the ones not accessable in another.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;Or, would it maybe make sense to not have domains A, B and C and just one lib/folder, then&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;assigning permissions to the data sets? &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;It wouldnt be the best way as it is always recommended to assign permissions on the folders&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;rather than data sets. Yet in the described case where different folders and different data sets in&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;these folders are used, not sure that there is much you could do other than the permissions&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;on the lowest level (= tables).&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;Can you provide some more info on the data sets and folders and&amp;nbsp;the users that need to have access to?&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;As mentioned above, I'd be curious about whether this is one situation for one certain user,&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;or, if this is a general set up. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;Thanks&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;Anja&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 19 Jun 2017 13:31:11 GMT</pubDate>
    <dc:creator>anja</dc:creator>
    <dc:date>2017-06-19T13:31:11Z</dc:date>
    <item>
      <title>Security Question SAS VA - designer and viewer</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Security-Question-SAS-VA-designer-and-viewer/m-p/368284#M9055</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have the following problem&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a library for Domain A:&lt;/P&gt;
&lt;P&gt;Dataset 1&lt;/P&gt;
&lt;P&gt;Dataset 4&lt;/P&gt;
&lt;P&gt;Dataset 5&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;for Domain B:&lt;/P&gt;
&lt;P&gt;Dataset 2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;for domain C:&lt;/P&gt;
&lt;P&gt;dataset 3&lt;/P&gt;
&lt;P&gt;We have a report "Dashboard" which uses&lt;/P&gt;
&lt;P&gt;- Dataset 1 (Domain A)&lt;/P&gt;
&lt;P&gt;- Dataset 2 (Domain B)&lt;/P&gt;
&lt;P&gt;- Dataset 3 (Domain C)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This report is placed in a separate folder "Management Reports"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We want the "Management-user" to be able to see the report "Dashboard". He can create new reports on this datasets 1,2,3 but we don't want him to see/use datasets 4,5 in library A.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We also don't want to load the data twice in a separate library for the Management Dashboard.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If we give the rights for the Management user to library A,B,C and he has designer rights. He can create new reports on datasets 4,5.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2017 12:47:58 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Security-Question-SAS-VA-designer-and-viewer/m-p/368284#M9055</guid>
      <dc:creator>Filipvdr</dc:creator>
      <dc:date>2017-06-19T12:47:58Z</dc:date>
    </item>
    <item>
      <title>Re: Security Question SAS VA - designer and viewer</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Security-Question-SAS-VA-designer-and-viewer/m-p/368317#M9057</link>
      <description>&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;Hi,&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;a few questions:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;Did you assign the permissions in VA or SAS Management Console, and, if the latter, did you assign&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;the permissions on the SAS Folders?&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;If a user is not allowed to access a data set, you would have to deny permissions on that data set,&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;for that user.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;The problem with that is, if there are several users that have access to some of the data sets&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;in domain A, B and C, but not to others, it can become hard to administer this.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;Would it maybe be possible to modify the domain A, B and C as such either the data sets the &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;users &lt;/FONT&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;have access to are in one lib/folder, and the ones not accessable in another.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;Or, would it maybe make sense to not have domains A, B and C and just one lib/folder, then&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;assigning permissions to the data sets? &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;It wouldnt be the best way as it is always recommended to assign permissions on the folders&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;rather than data sets. Yet in the described case where different folders and different data sets in&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;these folders are used, not sure that there is much you could do other than the permissions&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;on the lowest level (= tables).&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;Can you provide some more info on the data sets and folders and&amp;nbsp;the users that need to have access to?&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;As mentioned above, I'd be curious about whether this is one situation for one certain user,&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;or, if this is a general set up. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;Thanks&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans" size="2"&gt;Anja&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2017 13:31:11 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Security-Question-SAS-VA-designer-and-viewer/m-p/368317#M9057</guid>
      <dc:creator>anja</dc:creator>
      <dc:date>2017-06-19T13:31:11Z</dc:date>
    </item>
    <item>
      <title>Re: Security Question SAS VA - designer and viewer</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Security-Question-SAS-VA-designer-and-viewer/m-p/368632#M9063</link>
      <description>&lt;P&gt;In Sas Management Console on folder level.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it not possible to arrange this with Designer and Viewer (SAS VA)?&lt;/P&gt;
&lt;P&gt;If the user only has viewer rights for the dataset, he can only view reports and not create reports himself/herself.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2017 08:14:51 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Security-Question-SAS-VA-designer-and-viewer/m-p/368632#M9063</guid>
      <dc:creator>Filipvdr</dc:creator>
      <dc:date>2017-06-20T08:14:51Z</dc:date>
    </item>
  </channel>
</rss>

