Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 
paputzback
Contributor III
Contributor III

Does anyone have a naming convention they use for AD Access

I was wondering if anyone had a naming convention they used for AD roles for maintaining both security to the Application folders and also for section access and loop and reduce.

e.g

Department access

All access role QV Professional Billing Executive RESOURCES

Limited section access role QV Professional Billing Manager RESOURCES

or access by area

QV Professional Billing Manager North Campus RESOURCES

QV Professional Billing Manager South Campus RESOURCES..

Does anyone maintain a separate OU for their QV Application Roles?

Who manages access? I am afraid since we used role based access I will have AD Roles blow up when security decided to give access to a ROLE instead of by users directly.

Thanks,

Phil

2 Replies
rwunderlich
Partner Ambassador/MVP
Partner Ambassador/MVP

I've seen customers set up different ways, but the one I like the best is:

Separate OU for Qlikview.

Group for every Document named: Qv Users - document name (eg Sales).

Group for developers that covers write access to the common development directories: QV Developers.

Group for restricted developer directories: QV Developers - Payroll

Group owner approves membership in group. AD security team does the update. The OU can be delegated to QV Admin if desired.

-Rob

paputzback
Contributor III
Contributor III
Author

That looks like a good plan. I will have to try to sell it up the chain.

Thank you.