<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security role problem in Management &amp; Governance</title>
    <link>https://community.qlik.com/t5/Management-Governance/Security-role-problem/m-p/1654637#M15260</link>
    <description>&lt;P&gt;Thanks for your reply. Screen shots have been uploaded&lt;/P&gt;</description>
    <pubDate>Thu, 05 Dec 2019 15:14:27 GMT</pubDate>
    <dc:creator>Jeffrey_Li</dc:creator>
    <dc:date>2019-12-05T15:14:27Z</dc:date>
    <item>
      <title>Security role problem</title>
      <link>https://community.qlik.com/t5/Management-Governance/Security-role-problem/m-p/1654586#M15256</link>
      <description>&lt;P&gt;Hi, All,&lt;/P&gt;&lt;P&gt;I created the following two security roles.&amp;nbsp;&lt;/P&gt;&lt;P&gt;CustomizedContentadmin&lt;BR /&gt;Resources:Stream_*,App*,ReloadTask_*,UserSyncTask_*,SchemaEvent_*,User*,CustomProperty*,Tag_*,DataConnection_*,CompositeEvent_*,Extension_*,ContentLibrary_*,FileExtension_*,FileExtensionWhiteList_*,SystemNotification_*,FileReference*&lt;/P&gt;&lt;P&gt;CustomizedDeveloper&lt;BR /&gt;Resources:App*,ReloadTask_*,SchemaEvent_*,Tag_*,DataConnection_*,CompositeEvent_*,Extension_*,ContentLibrary_*,FileExtension_*,FileExtensionWhiteList_*,SystemNotification_*,FileReference*,Scheduler*&lt;/P&gt;&lt;P&gt;Comparing with&amp;nbsp;CustomizedContentadmin,&amp;nbsp;CustomizedDeveloper role has Scheduler* added, and has&amp;nbsp;Stream_*,UserSyncTask_*,User*,CustomProperty* removed. So basically CustomizedContentadmin role has more resources access than CustomizedDeveloper except Scheduler.&amp;nbsp; That means for data connections, when users with these two roles log into hub site, they should be able to see the same data connections listed there.&amp;nbsp;However, when roles are applied, users with&amp;nbsp;CustomizedDeveloper role are able to see all data connections in hub, including those connection created by other users. But Users with&amp;nbsp;CustomizedContentadmin role can only see a few data connections. I cannot find what the cause is, and need second eyes on it. Could you help?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Bo&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2019 13:46:38 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Security-role-problem/m-p/1654586#M15256</guid>
      <dc:creator>Jeffrey_Li</dc:creator>
      <dc:date>2019-12-05T13:46:38Z</dc:date>
    </item>
    <item>
      <title>Re: Security role problem</title>
      <link>https://community.qlik.com/t5/Management-Governance/Security-role-problem/m-p/1654623#M15257</link>
      <description>&lt;P&gt;Can you please post a screenshot of each of your security roles with all of the configured properties?&amp;nbsp; Just the resource filter is not enough to diagnose this issue.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2019 14:46:03 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Security-role-problem/m-p/1654623#M15257</guid>
      <dc:creator>andoryuu</dc:creator>
      <dc:date>2019-12-05T14:46:03Z</dc:date>
    </item>
    <item>
      <title>Re: Security role problem</title>
      <link>https://community.qlik.com/t5/Management-Governance/Security-role-problem/m-p/1654635#M15258</link>
      <description>&lt;P&gt;Customized_developer role screen shot&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2019 15:12:58 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Security-role-problem/m-p/1654635#M15258</guid>
      <dc:creator>Jeffrey_Li</dc:creator>
      <dc:date>2019-12-05T15:12:58Z</dc:date>
    </item>
    <item>
      <title>Re: Security role problem</title>
      <link>https://community.qlik.com/t5/Management-Governance/Security-role-problem/m-p/1654636#M15259</link>
      <description>&lt;P&gt;Customized_contentadmin role screen shot&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2019 15:13:38 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Security-role-problem/m-p/1654636#M15259</guid>
      <dc:creator>Jeffrey_Li</dc:creator>
      <dc:date>2019-12-05T15:13:38Z</dc:date>
    </item>
    <item>
      <title>Re: Security role problem</title>
      <link>https://community.qlik.com/t5/Management-Governance/Security-role-problem/m-p/1654637#M15260</link>
      <description>&lt;P&gt;Thanks for your reply. Screen shots have been uploaded&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2019 15:14:27 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Security-role-problem/m-p/1654637#M15260</guid>
      <dc:creator>Jeffrey_Li</dc:creator>
      <dc:date>2019-12-05T15:14:27Z</dc:date>
    </item>
    <item>
      <title>Re: Security role problem</title>
      <link>https://community.qlik.com/t5/Management-Governance/Security-role-problem/m-p/1654676#M15262</link>
      <description>&lt;P&gt;One more thing. CustomizedContentAdmin users also have DeploymentAdmin role.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2019 16:28:51 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Security-role-problem/m-p/1654676#M15262</guid>
      <dc:creator>Jeffrey_Li</dc:creator>
      <dc:date>2019-12-05T16:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: Security role problem</title>
      <link>https://community.qlik.com/t5/Management-Governance/Security-role-problem/m-p/1654761#M15264</link>
      <description>&lt;P&gt;Nothing looks obviously amiss there. On off-hours can you cycle services to see if it's some weird caching issue? That shouldn't be needed but I've seen it come up from time to time.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2019 19:28:17 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Security-role-problem/m-p/1654761#M15264</guid>
      <dc:creator>Levi_Turner</dc:creator>
      <dc:date>2019-12-05T19:28:17Z</dc:date>
    </item>
    <item>
      <title>Re: Security role problem</title>
      <link>https://community.qlik.com/t5/Management-Governance/Security-role-problem/m-p/1654763#M15265</link>
      <description>&lt;P&gt;Agreed&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/47469"&gt;@Levi_Turner&lt;/a&gt;&amp;nbsp;.&amp;nbsp; It's odd.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/16712"&gt;@Jeffrey_Li&lt;/a&gt;&amp;nbsp; when you are in the problematic security rule go into the audit pane on the right and filter on a single user that *should* have these read rights and select "Data Connection" as the resource.&amp;nbsp; Click "Preview" on the security rule to see what comes up.&amp;nbsp; Does the user show up with a blue block for "R" meaning the rule grants them read rights?&amp;nbsp; What about if you click audit?&amp;nbsp; Look for a data connection that they *should* have - what color is the box?&amp;nbsp; &amp;nbsp;Double click the "R" box - which security rules are displayed and can you provide a screenshot?&lt;/P&gt;&lt;P&gt;One thing that I've seen with security rules is that when trying to do certain security functions for hub activities you need to configure it "Only in Hub" even though you aren't trying to restrict it to hub, per se.&amp;nbsp; Try that and see if your test user can now see the data connections.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2019 19:38:37 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Security-role-problem/m-p/1654763#M15265</guid>
      <dc:creator>andoryuu</dc:creator>
      <dc:date>2019-12-05T19:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: Security role problem</title>
      <link>https://community.qlik.com/t5/Management-Governance/Security-role-problem/m-p/1654773#M15266</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/47469"&gt;@Levi_Turner&lt;/a&gt; &lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/3607"&gt;@andoryuu&lt;/a&gt; for your reply. I will find a time to restart the services and let users try again. Will let you know.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2019 20:14:40 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Security-role-problem/m-p/1654773#M15266</guid>
      <dc:creator>Jeffrey_Li</dc:creator>
      <dc:date>2019-12-05T20:14:40Z</dc:date>
    </item>
    <item>
      <title>Re: Security role problem</title>
      <link>https://community.qlik.com/t5/Management-Governance/Security-role-problem/m-p/1655021#M15269</link>
      <description>&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/16712"&gt;@Jeffrey_Li&lt;/a&gt;&amp;nbsp; You can also try my “only in hub” suggestion before having to cycle the services.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2019 13:31:51 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Security-role-problem/m-p/1655021#M15269</guid>
      <dc:creator>andoryuu</dc:creator>
      <dc:date>2019-12-06T13:31:51Z</dc:date>
    </item>
    <item>
      <title>Re: Security role problem</title>
      <link>https://community.qlik.com/t5/Management-Governance/Security-role-problem/m-p/1655119#M15270</link>
      <description>&lt;P&gt;The issue was solved after I restarted services. Thanks for &lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/47469"&gt;@Levi_Turner&lt;/a&gt; &lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/3607"&gt;@andoryuu&lt;/a&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2019 18:33:53 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Security-role-problem/m-p/1655119#M15270</guid>
      <dc:creator>Jeffrey_Li</dc:creator>
      <dc:date>2019-12-06T18:33:53Z</dc:date>
    </item>
  </channel>
</rss>

