<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Library authorization at the table level in SAS Enterprise Guide</title>
    <link>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/462746#M29856</link>
    <description>&lt;P&gt;Did you deny globally, for SASUSERS?&lt;/P&gt;</description>
    <pubDate>Wed, 16 May 2018 15:26:38 GMT</pubDate>
    <dc:creator>Kurt_Bremser</dc:creator>
    <dc:date>2018-05-16T15:26:38Z</dc:date>
    <item>
      <title>Library authorization at the table level</title>
      <link>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/462742#M29855</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Working with Sas Management Console (SAS 9.4). We have a Library of 20 data sets that are used by two different Groups.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.- We want Group A to have access to ALL of them, which works fine&lt;/P&gt;&lt;P&gt;2.- We want Group B to only see 2 tables&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately this seems impossible to set with SMC, even when we REMOVE all permissions (RM/WM/CIMD/R/W/C/D) are set to Deny, users of Group B still have access to ALL tables.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What are we missing???&lt;/P&gt;</description>
      <pubDate>Wed, 16 May 2018 15:18:36 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/462742#M29855</guid>
      <dc:creator>RexDeus9</dc:creator>
      <dc:date>2018-05-16T15:18:36Z</dc:date>
    </item>
    <item>
      <title>Re: Library authorization at the table level</title>
      <link>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/462746#M29856</link>
      <description>&lt;P&gt;Did you deny globally, for SASUSERS?&lt;/P&gt;</description>
      <pubDate>Wed, 16 May 2018 15:26:38 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/462746#M29856</guid>
      <dc:creator>Kurt_Bremser</dc:creator>
      <dc:date>2018-05-16T15:26:38Z</dc:date>
    </item>
    <item>
      <title>Re: Library authorization at the table level</title>
      <link>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/462760#M29858</link>
      <description>&lt;P&gt;Hi Kurt,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No, just that group.&lt;/P&gt;</description>
      <pubDate>Wed, 16 May 2018 16:03:18 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/462760#M29858</guid>
      <dc:creator>RexDeus9</dc:creator>
      <dc:date>2018-05-16T16:03:18Z</dc:date>
    </item>
    <item>
      <title>Re: Library authorization at the table level</title>
      <link>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/462765#M29859</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/67233"&gt;@RexDeus9&lt;/a&gt; wrote:&lt;BR /&gt;
&lt;P&gt;Hi Kurt,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No, just that group.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;That's your problem. Deny for SASUSERS (PUBLIC should already be denied), and then allow selectively for your groups.&lt;/P&gt;</description>
      <pubDate>Wed, 16 May 2018 16:32:20 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/462765#M29859</guid>
      <dc:creator>Kurt_Bremser</dc:creator>
      <dc:date>2018-05-16T16:32:20Z</dc:date>
    </item>
    <item>
      <title>Re: Library authorization at the table level</title>
      <link>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/462767#M29860</link>
      <description>&lt;P&gt;Hi Kurt,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry, I was wrong in my first reply, SASUsers are DENIED everything.&lt;/P&gt;</description>
      <pubDate>Wed, 16 May 2018 16:40:04 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/462767#M29860</guid>
      <dc:creator>RexDeus9</dc:creator>
      <dc:date>2018-05-16T16:40:04Z</dc:date>
    </item>
    <item>
      <title>Re: Library authorization at the table level</title>
      <link>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/462769#M29862</link>
      <description>&lt;P&gt;Have you made sure that the users in group B are not in group A also?&lt;/P&gt;</description>
      <pubDate>Wed, 16 May 2018 16:52:22 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/462769#M29862</guid>
      <dc:creator>Kurt_Bremser</dc:creator>
      <dc:date>2018-05-16T16:52:22Z</dc:date>
    </item>
    <item>
      <title>Re: Library authorization at the table level</title>
      <link>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/462773#M29864</link>
      <description>&lt;P&gt;Yes, they are totally different.&lt;/P&gt;</description>
      <pubDate>Wed, 16 May 2018 17:04:47 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/462773#M29864</guid>
      <dc:creator>RexDeus9</dc:creator>
      <dc:date>2018-05-16T17:04:47Z</dc:date>
    </item>
    <item>
      <title>Re: Library authorization at the table level</title>
      <link>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/462928#M29865</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;
&lt;P&gt;I think what you need to do is:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For EACH table:&lt;/P&gt;
&lt;P&gt;- Deny rm and r for SASUSERS.&lt;/P&gt;
&lt;P&gt;- Grant rm and r for group A&lt;/P&gt;
&lt;P&gt;- Grant rm and r for internal sas users (SAS Admins, SAS General servers...)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the 2 tables:&lt;/P&gt;
&lt;P&gt;- Deny rm and r for SASUSERS.&lt;/P&gt;
&lt;P&gt;- Grant rm and r for group A&lt;/P&gt;
&lt;P&gt;- Grant rm and r for group B&lt;/P&gt;
&lt;P&gt;- Grant rm and r for internal sas users (SAS Admins, SAS General servers...)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;//Fredrik&lt;/P&gt;</description>
      <pubDate>Thu, 17 May 2018 05:23:20 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/462928#M29865</guid>
      <dc:creator>FredrikE</dc:creator>
      <dc:date>2018-05-17T05:23:20Z</dc:date>
    </item>
    <item>
      <title>Re: Library authorization at the table level</title>
      <link>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/463097#M29879</link>
      <description>&lt;P&gt;Hi Fredrik,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your reply. Unfortunately it doesn't change anything. I removed ALL permissions to 'sasusers' and 'public' as well, on top of Group B.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Group B still has access to ALL tables for that Library. I really wonder why SAS even bothers providing the 'Authorization' tab at this level (Tables).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Getting pretty frustrated with this.:-(&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yvan&lt;/P&gt;</description>
      <pubDate>Thu, 17 May 2018 18:43:41 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/463097#M29879</guid>
      <dc:creator>RexDeus9</dc:creator>
      <dc:date>2018-05-17T18:43:41Z</dc:date>
    </item>
    <item>
      <title>Re: Library authorization at the table level</title>
      <link>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/463132#M29883</link>
      <description>&lt;P&gt;I assume you know that permissions at the metadata level can be bypassed by users assigning their own LIBNAMEs pointing at the table folders, unless you use metadata-bound libraries. Are you OK with that?&lt;/P&gt;</description>
      <pubDate>Thu, 17 May 2018 20:05:08 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/463132#M29883</guid>
      <dc:creator>SASKiwi</dc:creator>
      <dc:date>2018-05-17T20:05:08Z</dc:date>
    </item>
    <item>
      <title>Re: Library authorization at the table level</title>
      <link>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/463365#M29911</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I browsed the documentation, not sure it's worth the pain for a few tables, or maybe it's just me.&lt;/P&gt;</description>
      <pubDate>Fri, 18 May 2018 14:59:23 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/463365#M29911</guid>
      <dc:creator>RexDeus9</dc:creator>
      <dc:date>2018-05-18T14:59:23Z</dc:date>
    </item>
    <item>
      <title>Re: Library authorization at the table level</title>
      <link>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/463384#M29917</link>
      <description>&lt;P&gt;How do you access the tables in question? By browsing through the SAS metadata folders, or by opening them from the server list in Enterprise Guide, or in code?&lt;/P&gt;</description>
      <pubDate>Fri, 18 May 2018 16:03:52 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/463384#M29917</guid>
      <dc:creator>Kurt_Bremser</dc:creator>
      <dc:date>2018-05-18T16:03:52Z</dc:date>
    </item>
    <item>
      <title>Re: Library authorization at the table level</title>
      <link>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/463387#M29919</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Where are you setting that permissions, at libname level, folder level?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are the tables that you trying to grant and deny registered on metadata?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 May 2018 16:07:56 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/463387#M29919</guid>
      <dc:creator>NunoTGrunho</dc:creator>
      <dc:date>2018-05-18T16:07:56Z</dc:date>
    </item>
    <item>
      <title>Re: Library authorization at the table level</title>
      <link>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/463411#M29923</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Permissions are set on he following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Library level (They will never see the library without this one)&lt;/P&gt;&lt;P&gt;- Folder of the Library&lt;/P&gt;&lt;P&gt;- Table in the Library folder&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, the tables are registered in the Metadata.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 May 2018 17:54:37 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/463411#M29923</guid>
      <dc:creator>RexDeus9</dc:creator>
      <dc:date>2018-05-18T17:54:37Z</dc:date>
    </item>
    <item>
      <title>Re: Library authorization at the table level</title>
      <link>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/463412#M29924</link>
      <description>&lt;P&gt;Hi Kurt,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Working with SAS EG.&lt;/P&gt;</description>
      <pubDate>Fri, 18 May 2018 17:55:30 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/463412#M29924</guid>
      <dc:creator>RexDeus9</dc:creator>
      <dc:date>2018-05-18T17:55:30Z</dc:date>
    </item>
    <item>
      <title>Re: Library authorization at the table level</title>
      <link>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/463440#M29927</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/67233"&gt;@RexDeus9&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Hi Kurt,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Working with SAS EG.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;If the libraries are assigned with a basic libname statement (and not with the meta engine), then the metadata access control will not be active.&lt;/P&gt;
&lt;P&gt;You can make sure that the access control works by converting to metadata bound libraries.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 May 2018 20:33:13 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/463440#M29927</guid>
      <dc:creator>Kurt_Bremser</dc:creator>
      <dc:date>2018-05-18T20:33:13Z</dc:date>
    </item>
    <item>
      <title>Re: Library authorization at the table level</title>
      <link>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/463462#M29930</link>
      <description>&lt;P&gt;You mean metadata-bound libraries? I agree totally&amp;nbsp; - you would have to have a much better reason to justify implementing MBLs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just pointing out, you can spend a lot of time getting metadata permissions right only for users to bypass them...&lt;/P&gt;</description>
      <pubDate>Fri, 18 May 2018 23:36:57 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/463462#M29930</guid>
      <dc:creator>SASKiwi</dc:creator>
      <dc:date>2018-05-18T23:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: Library authorization at the table level</title>
      <link>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/463468#M29931</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/67233"&gt;@RexDeus9&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;Alternatively to metadata bound libraries you can always secure tables on OS level and with a new SAS version you could also go for Sever Lockdown (but that requires quite a bit of planning/design to implement).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 19 May 2018 01:22:11 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/463468#M29931</guid>
      <dc:creator>Patrick</dc:creator>
      <dc:date>2018-05-19T01:22:11Z</dc:date>
    </item>
    <item>
      <title>Re: Library authorization at the table level</title>
      <link>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/463485#M29932</link>
      <description>&lt;P&gt;The ultima ratio is always the operating system. Once the permissions are properly set, no other user can bypass them.&lt;/P&gt;</description>
      <pubDate>Sat, 19 May 2018 04:55:08 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/463485#M29932</guid>
      <dc:creator>Kurt_Bremser</dc:creator>
      <dc:date>2018-05-19T04:55:08Z</dc:date>
    </item>
    <item>
      <title>Re: Library authorization at the table level</title>
      <link>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/463587#M29941</link>
      <description>&lt;P&gt;One option not mentioned is to do folder-level permissions where Group B have a separate folder / library with the two datasets they are allowed to see then another folder for Group A containing all of the datasets (2 being copies). Then it is easy to align OS and metadata permissions so users can't bypass them.&lt;/P&gt;</description>
      <pubDate>Sun, 20 May 2018 00:03:51 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Enterprise-Guide/Library-authorization-at-the-table-level/m-p/463587#M29941</guid>
      <dc:creator>SASKiwi</dc:creator>
      <dc:date>2018-05-20T00:03:51Z</dc:date>
    </item>
  </channel>
</rss>

