Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Problems with user rights or authentication?

Status
Not open for further replies.

HCSOBOXI

Technical User
May 6, 2008
23
US
Hello All,

Have you had many problems with managing the user rights and what is the authentication that you use?

Thank you!
 
My internal users use Windows AD authentication while my external users use the Enterprise authentication.

As far as managing rights, I do that at the group level.
 
Hi,
One of the best features of BOE ( in my opinion) is the flexibility of rights assignment - the hierarchical method allow you to set access rights ( by Group or Individual or multiple groups or individuals) at a top folder level and as you progress down through the sub-folders those rights can be changed to a more restrictive set of access rights, right down to an individual report which can be set to allow only one user or group to access it.

Just remember that it is top-down so the restriction set at the topmost level must be the least restrictive needed in the entire folder/subfolder set.

( The method: AD, NT (windows local), Enterprise, whatever) does not matter but having a centralized system ( Like AD) make maintenance/updates much easier..


Enjoy ( just be sure the administrator account has full and unlimited access to all areas.)




[profile]

To Paraphrase:"The Help you get is proportional to the Help you give.."
 
kskid,

Thank you for your response. I am using AD authentication too.

You said "...while my external users use the Enterprise authentication." Do you mean users that are not on the domain? If so, how do they access the application? Did you use another product to give this functionality?

Thank you!

 
Turkbear,

Thank you for your response, this is great information.

Question: You mentioned that NT is windows local. Does that mean I can set up NT authentication for the local machine that enterprise is on or? I'm still learning the differences with AD and NT. It has been explained to me but the lightbulb just hasn't turned on yet.

Thank you!
 
Hi,
Yes..The NT authentication uses the same Security settings as on the server itself..It uses whatever permissions/rights, etc that the NT user has been granted through Windows.

Its disadvantage is that all users must then have an account on the server and that may not be the best way to handle things...

AD, with its central administration, is, in my opinion, the easiest to manage and to update when needed - BOE will update its 'knowledge' of the change usually within 15-20 minutes ( depending on the complexity of your AD structure) and you can also, using the CMC, 'force' an update if needed.

[profile]

To Paraphrase:"The Help you get is proportional to the Help you give.."
 
Hi,
I was a little unclear in my last post..You would still have to set the BOE permissions ( just like with AD) but the user account is local to the server and, therefore, could log in directly to it, so its rights on the server have to be carefully restricted.



[profile]

To Paraphrase:"The Help you get is proportional to the Help you give.."
 
Rule of thumb that I follow for assigning access rights:

Assign users to groups, assign access rights to groups at the folder level.

BO allows you to assign rights to a specific report for a specific user, but that becomes a nightmare to maintain. You want to assign rights at the highest level possible. So, if you group reports by folders and then assign access to the folder instead of to individual reports, you've greatly simplified your security model.

When you assign rights by user group, not only does it simplify your security model even further, it also makes it MUCH simpler to say "give user B the same access as user A." I even have one or two user groups that only have a single user who needs special access to something so that we can follow this model.

-Dell

A computer only does what you actually told it to do - not what you thought you told it to do.
 
Turkbear,

Thank you for more information regarding NT and AD. Very good information regarding updating of AD users and a CMC force if neccessary.

Thank you!
 
Turkbear,

Helpful information regarding the server rights.

Thank you!
 
hilfy,

Thank you for your rule of thumb information. I went back into the CMC and re-evaluated how I had set some groups up. This was very useful and stamped in my memory to have an easier maintainence plan.

Thank you!
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top