dbTalk Databases Forums  

Re: How to Force Domain Administrators from Overriding Defined Roles?

microsoft.public.sqlserver.olap microsoft.public.sqlserver.olap


Discuss Re: How to Force Domain Administrators from Overriding Defined Roles? in the microsoft.public.sqlserver.olap forum.



Reply
 
Thread Tools Display Modes
  #1  
Old   
Dave Wickert [MSFT]
 
Posts: n/a

Default Re: How to Force Domain Administrators from Overriding Defined Roles? - 08-23-2004 , 05:09 PM






Sorry. Domain adminstrators are part of the Administrators role and, as with
most products, when you are a machine administrator you are able to see
everything.
The idea is that you just as easily add yourself to any role manually. There
is no workaround without limiting domain administration on your machine.
--
Dave Wickert [MSFT]
dwickert (AT) online (DOT) microsoft.com
Program Manager
BI SystemsTeam
SQL BI Product Unit (Analysis Services)
--
This posting is provided "AS IS" with no warranties, and confers no rights.

"cgi1" <cgi1 (AT) newsgroup (DOT) nospam> wrote

Quote:
I'm using Analysis Service 8.0.760. We have built applications that
utilizes
dynamic role (using NT domain aunthenticated user name) to drive what the
user sees in one dimension. However this role is always overriden if a
domain
administrator accesses the cube. It seems like that the role is bypassed
altogether and the domain administrator can see everything.
I've tried messing around with local machine permission (of the AS server)
but it still doesn't work.

Any workaround?

thanks
cgi1



Reply With Quote
  #2  
Old   
Mosha Pasumansky [MS]
 
Posts: n/a

Default Re: How to Force Domain Administrators from Overriding Defined Roles? - 08-23-2004 , 09:27 PM






Dave is right that machine administrator can always add himself as part of
OLAP Administrators group. So there is no security solution against this.
However, if you trust the machine administrator, and simply want him not to
see accidently the data - you can exclude him from the OLAP Administrators
by applying the following KB article:

http://support.microsoft.com/default...b;en-us;834419

(note that you will need post SP3 hotfix in order to do that)

--
==================================================
Mosha Pasumansky - http://www.mosha.com/msolap
Yukon information at http://www.mosha.com/msolap/yukon.htm
Development Lead in the Analysis Server team
All you need is love (John Lennon)
Disclaimer : This posting is provided "AS IS" with no warranties, and
confers no rights.
==================================================

"Dave Wickert [MSFT]" <dwickert (AT) online (DOT) microsoft.com> wrote

Quote:
Sorry. Domain adminstrators are part of the Administrators role and, as
with
most products, when you are a machine administrator you are able to see
everything.
The idea is that you just as easily add yourself to any role manually.
There
is no workaround without limiting domain administration on your machine.
--
Dave Wickert [MSFT]
dwickert (AT) online (DOT) microsoft.com
Program Manager
BI SystemsTeam
SQL BI Product Unit (Analysis Services)
--
This posting is provided "AS IS" with no warranties, and confers no
rights.

"cgi1" <cgi1 (AT) newsgroup (DOT) nospam> wrote in message
news:81ADBDF4-4E08-4D50-BB96-5E778742D87C (AT) microsoft (DOT) com...
I'm using Analysis Service 8.0.760. We have built applications that
utilizes
dynamic role (using NT domain aunthenticated user name) to drive what
the
user sees in one dimension. However this role is always overriden if a
domain
administrator accesses the cube. It seems like that the role is bypassed
altogether and the domain administrator can see everything.
I've tried messing around with local machine permission (of the AS
server)
but it still doesn't work.

Any workaround?

thanks
cgi1





Reply With Quote
Reply




Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Powered by vBulletin Version 3.5.3
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.