1. So you have more than one application server with SAS Token Authentication enabled? No, it is only one, but the logical workspace server has a workspace server for each Group of users. 2. Why did you create multiple UNIX service accounts? Because I need a workspace server foreach Group of users. 3. Have you had any specific reasons for that? Yes, the phisical data that you see in EG cannot be shared between groups. 4. Why can't you use sassrv user for all of them? Because, it is a tecnical service unix identity used by other processes and I cannot share the data between groups. 5. Where are you controlling access to the workspace server? In management console, with metadata restricted access using an Access Control Template. 6. On the workspace server object or somewhere else? On each workspace server. We applied this note: http://support.sas.com/documentation/cdl/en/bisecag/61133/HTML/default/viewer.htm#a003280630.htm It is for SAS 9.2 but I think it is good also for 9.4 M4 that is the version that we use.
... View more