Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Intelligence (Analytics)
Deny access to one volume on multi-volume server for one user
jar
<p>Hello,</p>
<p> </p>
<p>We have a BI group in our LDAP in which all users are member. On our two volume iHub server (test and accept) there is one person who may have access to the accept volume but not to the test volume as the data on that is privacy sensitive. The accept volume has a small set of anonymous data.</p>
<p> </p>
<p>In the functionality-level.config file we have added the desired functionality to the BI group of which this person is also a member. </p>
<p> </p>
<p>I can off course make a seperate group in the ldap and add this person to this group, add it to the functionality-level.config file and give this group only access to the accept volume and not the test volume but for this I have to change the files on the iHub server. I have no rights to do so. </p>
<p> </p>
<p>Of course I can ask the system administrator to make these changes but I wander if there are other ways to achieve this. Without needing a system administrator. </p>
<p> </p>
<p>Any direction if this is possible would be nice ...</p>
<p> </p>
<p>Regards,</p>
<p>Jeroen</p>
Find more posts tagged with
Comments
Clement Wong
<p>If you're using out of the box LDAP/AD User Management set in System Console, then...</p>
<p> </p>
<p>In the System Console for each Volume, there is an property "Organization ID" if you Edit the volume. You can use this to filter out based on the LDAP setting "User Volume Filter Attribute".</p>
<p> </p>
<p>For example, two volumes: test and accept. You would set the "Organization ID" for test as "qa". And set the "Organization ID" for accept as "uat".</p>
<p> </p>
<p>Then in the Cluster > User Management, towards the bottom, you'll see "User Volume Filter Attribute" where you can add the LDAP group attribute. For example, "grp".</p>
<p> </p>
<p>Now, those who belong to the "qa" grp can only log into test volume, and those in the "uat" grp ac only log into the accept volume.</p>