cancel
Showing results for 
Search instead for 
Did you mean: 

Data Services - Security

former_member196240
Participant
0 Kudos

Hello,

          We have a requirement where a certain users repository is not accessible even to administrators. Since administrator are from different country and there is sensitive data available in the source tables.

Can you please advise.

Thanks,

Vinay

Accepted Solutions (1)

Accepted Solutions (1)

former_member187605
Active Contributor
0 Kudos

Revoke access to all repositories from the Administrators group. You can then grant individual access at a repository level. Cf. for detailed instructions.

former_member196240
Participant
0 Kudos

Thanks Dirk. I'll try and let you know how it goes.

former_member196240
Participant
0 Kudos

Dirk, I looked at your approach little closer. And got a question could an admin not simply be able to grant themselves again the ability to access the repo?

As I said the administrators are from other country and we want certain local repositories to be lock down to them.

How about  locking down at database level with windows auth? An administrators can still access the CMC and Designer, however they will never be able to actually log into local repo because they will not have the Windows Authentication.

Appreciate your response.

former_member187605
Active Contributor
0 Kudos

After login to the IPS, you can select any repository you are granted access to. The credentials arre picked up from the CMS database. As an extra security feature you may be requested to enter the database password. But again, as an Administrator you can disable that feature.

Have you considered auditing? Then you cannot prevent unwanted access, but you can monitor it. And take necessary actions.

former_member196240
Participant
0 Kudos

Thanks Dirk.  We did consider about the auditing but we could not convince the team. Hence, exploring the other options.

Appreciate if you can advise any other suggestions.

former_member196240
Participant
0 Kudos

Dirk, We decided to consider the auditing functionality. Can you please help me to understand how we can utilize Auditing to aid our requirement.


Appreciate your response. 

former_member187605
Active Contributor
0 Kudos

This is fully documented in section 22 Auditing of the Information platform services Administrator Guide.

Answers (0)