<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Security rule that allows only setting/removing values for a custom property of users in Management &amp; Governance</title>
    <link>https://community.qlik.com/t5/Management-Governance/Security-rule-that-allows-only-setting-removing-values-for-a/m-p/2130302#M25857</link>
    <description>&lt;P&gt;We use security rules that give users access to streams and apps based on a custom property 'access_class' on the users, steams, and apps: If, for this property, the values on a resource (stream or app) matches the values on the user (value intersection is not empty), access is granted. Only problem: There are many users, and the root admin is the only one who can set property values for them.&lt;/P&gt;
&lt;P&gt;Thus, we would like to define a new admin role &lt;STRONG&gt;UserPropertyAdmin&lt;/STRONG&gt; for admins who can &lt;STRONG&gt;only set/remove property values on the users&lt;/STRONG&gt; - not the properties on other ressources, not other data of the user, and not defining/changing other existing or new properties (and optimally: setting/removing only values of the specific property 'access_class').&lt;/P&gt;
&lt;P&gt;Has somebody a hint for me, how to correctly set the resource filter and resource conditions? Or a hint to some kind of documentation for resources 'around' custom properties that I can target in a security rule?&lt;/P&gt;
&lt;P&gt;(I have already re-read the respective sections of the help for qlik sense for administrators, and the page&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/Collection-of-Specific-Rule-Scenarios-and-Customization-of-Qlik/ta-p/1716899" target="_self"&gt;Collection of Specific Rule Scenarios and Customization of Qlik&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
    <pubDate>Fri, 20 Oct 2023 10:01:35 GMT</pubDate>
    <dc:creator>hewemel1</dc:creator>
    <dc:date>2023-10-20T10:01:35Z</dc:date>
    <item>
      <title>Security rule that allows only setting/removing values for a custom property of users</title>
      <link>https://community.qlik.com/t5/Management-Governance/Security-rule-that-allows-only-setting-removing-values-for-a/m-p/2130302#M25857</link>
      <description>&lt;P&gt;We use security rules that give users access to streams and apps based on a custom property 'access_class' on the users, steams, and apps: If, for this property, the values on a resource (stream or app) matches the values on the user (value intersection is not empty), access is granted. Only problem: There are many users, and the root admin is the only one who can set property values for them.&lt;/P&gt;
&lt;P&gt;Thus, we would like to define a new admin role &lt;STRONG&gt;UserPropertyAdmin&lt;/STRONG&gt; for admins who can &lt;STRONG&gt;only set/remove property values on the users&lt;/STRONG&gt; - not the properties on other ressources, not other data of the user, and not defining/changing other existing or new properties (and optimally: setting/removing only values of the specific property 'access_class').&lt;/P&gt;
&lt;P&gt;Has somebody a hint for me, how to correctly set the resource filter and resource conditions? Or a hint to some kind of documentation for resources 'around' custom properties that I can target in a security rule?&lt;/P&gt;
&lt;P&gt;(I have already re-read the respective sections of the help for qlik sense for administrators, and the page&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/Collection-of-Specific-Rule-Scenarios-and-Customization-of-Qlik/ta-p/1716899" target="_self"&gt;Collection of Specific Rule Scenarios and Customization of Qlik&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 10:01:35 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Security-rule-that-allows-only-setting-removing-values-for-a/m-p/2130302#M25857</guid>
      <dc:creator>hewemel1</dc:creator>
      <dc:date>2023-10-20T10:01:35Z</dc:date>
    </item>
    <item>
      <title>Re: Security rule that allows only setting/removing values for a custom property of users</title>
      <link>https://community.qlik.com/t5/Management-Governance/Security-rule-that-allows-only-setting-removing-values-for-a/m-p/2486610#M28250</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Helmut, maybe this will help:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;To define a custom security role with restricted permissions for managing user properties, you can follow these steps:&lt;/P&gt;
&lt;P&gt;1. Create a new custom security role, for example "UserPropertyAdmin".&lt;BR /&gt;2. Grant this role the specific permissions needed to set and remove values for the "access_class" property on users.&lt;BR /&gt;3. Do not grant any additional permissions beyond managing the "access_class" property values for users.&lt;BR /&gt;4. Assign this "UserPropertyAdmin" role to the administrators who should have this restricted access.&lt;/P&gt;
&lt;P&gt;This approach allows you to create a custom security role with the precise permissions needed, limiting administrators to only set or remove values for the specific "access_class" property on users. They will not have permissions to modify other user data or manage properties on other resources.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2024 16:07:54 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Security-rule-that-allows-only-setting-removing-values-for-a/m-p/2486610#M28250</guid>
      <dc:creator>Alan_Slaughter</dc:creator>
      <dc:date>2024-10-11T16:07:54Z</dc:date>
    </item>
  </channel>
</rss>

