Do not input private or sensitive data. View Qlik Privacy & Cookie Policy.
Skip to main content

Announcements
Join us in NYC Sept 4th for Qlik's AI Reality Tour! Register Now
cancel
Showing results for 
Search instead for 
Did you mean: 
ali_hijazi
Partner - Master II
Partner - Master II

restrict the creation of a folder data connection on a specific network path

Hello
I'm working on Qlik sense enterprise
I want to restrict developers from creating a folder data connection to a network path
I know this can be accomplished via security rules
I created a security rule as follows:


Resource Filter: DataConnection_*
Actions: Create
Conditions: resource.resourcetype = "DataConnection"
and
( (resource.type = "folder" and !(resource.Path like "*\\\\qliksenseprd\\QlikSense\\Technical STORE QVDs\\QDF_FIN*")))

however when I go to the load editor, the create-new-connection button at the top right is disabled as if the security rule failed

I can walk on water when it freezes
Labels (3)
11 Replies
Kaushik2020
Creator III
Creator III

Hi @ali_hijazi , Are you planning to restrict the create connection option or only the folder creation ?

ali_hijazi
Partner - Master II
Partner - Master II
Author

Hi @Kaushik2020 

Yes mainly folder data connection creation

Regards,

I can walk on water when it freezes
Kaushik2020
Creator III
Creator III

.

ali_hijazi
Partner - Master II
Partner - Master II
Author

I don't want to restrict reading the folder data connection
I want to allow developers to create a folder data connection except for the specified location
Please read my question fully before throwing hap-hazard answers

I can walk on water when it freezes
Kaushik2020
Creator III
Creator III

you can modify the security rule to add your conditions. In our environment we have defined on who can create a folder in folder lever security. Not from Qlik Sense.

ali_hijazi
Partner - Master II
Partner - Master II
Author

Hello @Kaushik2020 
in the company we have several Teams of developers
let's say Team1 and Team2
both teams are allowed to create any folder connection. However members of Team2 are not allowed to create a folder data connection to 
\\server_name\QlikSense\Technical STORE QVDs\QDF_FIN

I can walk on water when it freezes
Kaushik2020
Creator III
Creator III

In my case, I have restricted it via the folder security inside the Server user group. I hope same should be possible with QMC Security rules. 

ali_hijazi
Partner - Master II
Partner - Master II
Author

the thing is that the process behind the script is executed by the user account that runs the Qlik Sense engine. So even if you restrict users from accessing the folder via windows, the developer can still create a connection to that folder and even run the script successfully because it is ran by that service account.

I can walk on water when it freezes
Kaushik2020
Creator III
Creator III

The account which is used to login to Qlik Sense should be configured. When we reload the Qlik Sense user id is recognized in the server.