<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Create App Security Rule in Management &amp; Governance</title>
    <link>https://community.qlik.com/t5/Management-Governance/Create-App-Security-Rule/m-p/1908973#M30285</link>
    <description>&lt;P&gt;Thank you Levi so much,&lt;/P&gt;
&lt;P&gt;I had default all the security rules except&amp;nbsp;ContentAdmin-DataConnections&lt;/P&gt;
&lt;P&gt;So I created that rule as well. Then I tested with some one as content admin and that person is able to edit and save existing connections. Can you please advice what might be wrong here?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jpjust_0-1648059395447.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/75191iB7992C8E9E7F39AD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jpjust_0-1648059395447.png" alt="jpjust_0-1648059395447.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 23 Mar 2022 18:18:45 GMT</pubDate>
    <dc:creator>jpjust</dc:creator>
    <dc:date>2022-03-23T18:18:45Z</dc:date>
    <item>
      <title>Create App Security Rule</title>
      <link>https://community.qlik.com/t5/Management-Governance/Create-App-Security-Rule/m-p/1904215#M30279</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have this createApp security rule in qliksense.&lt;/P&gt;
&lt;P&gt;I have users with professional and Analyst license users. Does this rule allows both professional and Analyst users allows to create App?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jpjust_0-1647019050389.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/74299i392310F4F7F1A5DB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jpjust_0-1647019050389.png" alt="jpjust_0-1647019050389.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 16:38:32 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Create-App-Security-Rule/m-p/1904215#M30279</guid>
      <dc:creator>jpjust</dc:creator>
      <dc:date>2025-01-29T16:38:32Z</dc:date>
    </item>
    <item>
      <title>Re: Create App Security Rule</title>
      <link>https://community.qlik.com/t5/Management-Governance/Create-App-Security-Rule/m-p/1904232#M30280</link>
      <description>&lt;P&gt;With the Professional / Analyzer based model, access control is first enforced by the license type&amp;nbsp;&lt;EM&gt;then&lt;/EM&gt; by security rules. So in your example, the analyzer users would&amp;nbsp;&lt;STRONG&gt;not&lt;/STRONG&gt; be able to create an app. The same goes for any other area where analyzer are restricted.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 17:56:42 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Create-App-Security-Rule/m-p/1904232#M30280</guid>
      <dc:creator>Levi_Turner</dc:creator>
      <dc:date>2022-03-11T17:56:42Z</dc:date>
    </item>
    <item>
      <title>Re: Create App Security Rule</title>
      <link>https://community.qlik.com/t5/Management-Governance/Create-App-Security-Rule/m-p/1904241#M30281</link>
      <description>&lt;P&gt;Thanks Levi..&lt;/P&gt;
&lt;P&gt;We have 5 users are root admin.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Out of that one user should not be able to modify existing connections. That user can create connections and edit connections that user has created.&lt;/P&gt;
&lt;P&gt;Is it possible to create an admin with less privilege's than an root admin?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 18:31:23 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Create-App-Security-Rule/m-p/1904241#M30281</guid>
      <dc:creator>jpjust</dc:creator>
      <dc:date>2022-03-11T18:31:23Z</dc:date>
    </item>
    <item>
      <title>Re: Create App Security Rule</title>
      <link>https://community.qlik.com/t5/Management-Governance/Create-App-Security-Rule/m-p/1904259#M30282</link>
      <description>&lt;P&gt;Sure. The default roles (AuditAdmin, ContentAdmin, DeploymentAdmin, RootAdmin, SecurityAdmin) are just the defaults. You can enter any value in the rule for roles like so:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Levi_Turner_0-1647028231985.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/74304i62E818B1BAD4FC70/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Levi_Turner_0-1647028231985.png" alt="Levi_Turner_0-1647028231985.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;And now it's an option for a role:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Levi_Turner_1-1647028265748.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/74305iFA5A0C37FDFFEA70/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Levi_Turner_1-1647028265748.png" alt="Levi_Turner_1-1647028265748.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It sounds like you're after a rule which is similar to ContentAdmin but only having read access to data connections.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 19:51:57 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Create-App-Security-Rule/m-p/1904259#M30282</guid>
      <dc:creator>Levi_Turner</dc:creator>
      <dc:date>2022-03-11T19:51:57Z</dc:date>
    </item>
    <item>
      <title>Re: Create App Security Rule</title>
      <link>https://community.qlik.com/t5/Management-Governance/Create-App-Security-Rule/m-p/1904268#M30283</link>
      <description>&lt;P&gt;So here is my content admin security rule and resource filter&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jpjust_0-1647029577712.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/74308i67118BE659B1A017/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jpjust_0-1647029577712.png" alt="jpjust_0-1647029577712.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Stream_*,App*,ReloadTask_*,UserSyncTask_*,SchemaEvent_*,User*,CustomProperty*,Tag_*,DataConnection_*,CompositeEvent_*,Extension_*,ContentLibrary_*,FileExtension_*,FileExtensionWhiteList_*,SystemNotification_*&lt;/P&gt;
&lt;P&gt;As long as I remove update and delete from the actions from the above content admin security rule and If I assign this content admin role to the admin user (remove root admin role) then that user won't be able to delete the existing connections? Does that work?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 20:16:22 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Create-App-Security-Rule/m-p/1904268#M30283</guid>
      <dc:creator>jpjust</dc:creator>
      <dc:date>2022-03-11T20:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: Create App Security Rule</title>
      <link>https://community.qlik.com/t5/Management-Governance/Create-App-Security-Rule/m-p/1905337#M30284</link>
      <description>&lt;P&gt;Assuming that you want the users to be able to change / remove / etc all content&amp;nbsp;&lt;EM&gt;except&lt;/EM&gt; for modifying data connections, I would do the following:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Name: ContentAdmin2-Content
Filters: Stream_*,App*,ReloadTask_*,ExternalProgramTask_*,UserSyncTask_*,SchemaEvent_*,User*,CustomProperty*,Tag_*,CompositeEvent_*,Extension_*,ContentLibrary_*,FileExtension_*,FileExtensionWhiteList_*,SystemNotification_*
Actions: Create+Read+Update+Delete+Export+Publish+ChangeOwner+Duplicate+Approve
Conditions: ((user.roles="ContentAdmin2"))
Context: QMC

Name: ContentAdmin2-DataConnections
Filters: DataConnection_*,
Actions: Create+Read
Conditions: ((user.roles="ContentAdmin2"))
Context: QMC

Name: ContentAdmin2QmcSections
Filters: License_*,TermsAcceptance_*,QmcSection_Stream,QmcSection_App,QmcSection_App.Object,QmcSection_AppDistributionStatus,QmcSection_CloudDistribution,QmcSection_DataConnection,QmcSection_Tag,QmcSection_User,QmcSection_CustomPropertyDefinition,QmcSection_Task,QmcSection_Event,QmcSection_SchemaEvent,QmcSection_CompositeEvent,QmcSection_Extension,QmcSection_ReloadTask,QmcSection_UserSyncTask,QmcSection_ContentLibrary,QmcSection_Audit,QmcSection_AnalyticConnection,QmcSection_SystemNotification,QmcSection_SystemNotificationPolicy,QmcSection_DeploymentSetup
Actions: Read
Conditions: ((user.roles="ContentAdmin2"))
Context: QMC

Name: ContentAdmin2RulesAccess
Filters: SystemRule_*
Actions: Create+Read+Update+Delete
Conditions: user.roles = "ContentAdmin2" and (resource.category = "Security" and (resource.resourcefilter matches "Stream_\w{8}-\w{4}-\w{4}-\w{4}-\w{12}" or resource.resourcefilter matches "DataConnection_\w{8}-\w{4}-\w{4}-\w{4}-\w{12}" or resource.resourcefilter matches "ContentLibrary_\w{8}-\w{4}-\w{4}-\w{4}-\w{12}" or resource.resourcefilter matches "Extension_\w{8}-\w{4}-\w{4}-\w{4}-\w{12}") or (resource.category = "Generic" and resource.subcategory = "SystemNotification"))
Context: QMC&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 15 Mar 2022 12:53:06 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Create-App-Security-Rule/m-p/1905337#M30284</guid>
      <dc:creator>Levi_Turner</dc:creator>
      <dc:date>2022-03-15T12:53:06Z</dc:date>
    </item>
    <item>
      <title>Re: Create App Security Rule</title>
      <link>https://community.qlik.com/t5/Management-Governance/Create-App-Security-Rule/m-p/1908973#M30285</link>
      <description>&lt;P&gt;Thank you Levi so much,&lt;/P&gt;
&lt;P&gt;I had default all the security rules except&amp;nbsp;ContentAdmin-DataConnections&lt;/P&gt;
&lt;P&gt;So I created that rule as well. Then I tested with some one as content admin and that person is able to edit and save existing connections. Can you please advice what might be wrong here?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jpjust_0-1648059395447.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/75191iB7992C8E9E7F39AD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jpjust_0-1648059395447.png" alt="jpjust_0-1648059395447.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2022 18:18:45 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Create-App-Security-Rule/m-p/1908973#M30285</guid>
      <dc:creator>jpjust</dc:creator>
      <dc:date>2022-03-23T18:18:45Z</dc:date>
    </item>
  </channel>
</rss>

