We have a WIndowsx64 SAS 9.4 TS1M5 setup. Recently upgraded to M6. One of the IT person(user) who is a part of the SAS Administrator group keeps getting this error when trying to add/remove a new user in SAS Management Console
'The user does not have permission to perform this action.
- Not Authorized to add Login UserId=ataylor3, ObjId=A5OB9JNQ.AS0001QI, AuthDomain=OraAuth to Person Name=Ashley Taylor, ObjId=A5OB9JNQ.AP0000VD'.
Strangely this user has right access/perms to Server1 which is a duplicate of Server2 (the problematic one where she doesn't have permissions). We've checked on the server level, AD, done comparisons between Server1 and 2 where the user is setup exactly the same. Tried to add/remove the user in metadata - no luck.
Any ideas?
When the user opens the properties of the problematic user, is this person Read-Only, you can see this at the top of the user's properties when that window is open. Being a member of the SAS Administrators group will not give you the ability to modify users, you would need the Metadata Server: User Administration role.
If you already have that role and still are unable to modify the other user, check that user's Authorization tab while logged in as sasadm@saspw to see if any of the permissions are not inherited. The users and groups listed should all have grey boxes around the effective permissions to be inherited. If one is not inherited, click around the checkbox until it is shaded. I have seen issues with changing the permissions on this tab that can make a user Read-Only for themselves and others.
Thanks for your response. User already has the privileges that you mentioned below but continues to have the same issue.
The SAS Users Group for Administrators (SUGA) is open to all SAS administrators and architects who install, update, manage or maintain a SAS deployment.
Learn how to explore data assets, create new data discovery agents, schedule data discovery agents, and much more.
Find more tutorials on the SAS Users YouTube channel.