Announcement

Migration of this forum

Dear users of this forum,

we are pleased to inform you that we will be updating the software behind this forum in the near future.

Existing posts, users and categories will remain untouched.

Important:

  • Each user will need to reset their password.
  • Please select "I forgot my password".
  • Enter the email address you used to register in this forum.
  • You will receive an email with a link to set a new password.
  • Please choose a new (secure) password and confirm the process.

We will keep you informed in the pinned thread.

Kind regards,
Your ReportServer Team


Migration des Forums

Liebe Nutzer dieses Forums,

wir freuen uns, euch mitteilen zu können, dass wir in naher Zukunft die Software hinter diesem Forum aktualisieren werden.

Existierende Beiträge, Nutzer und Kategorien bleiben weiterhin bestehen!

Wichtig:

  • Jeder Nutzer muss sein Passwort neu vergeben.
  • Wählt dazu einfach "Ich habe mein Passwort vergessen".
  • Gebt die E-Mail-Adresse ein, mit der ihr registriert seid.
  • Ihr erhaltet eine E-Mail mit einem Link zur Passwortvergabe.
  • Bitte wählt ein neues (sicheres) Passwort und bestätigt den Vorgang.

Wir halten euch im angepinnten Beitrag auf dem Laufenden!

Mit vielen Grüßen
Euer ReportServer Team

#1 2019-05-09 09:49:33

Patryx
Member
Registered: 2019-03-25

Create User in Administration without inherited Groups

Hi,
I want to create my exportuser with apikey and I want to just allow him to export report XX.
I can just create User under User Root folder what automatically causes that the user has Administators and User in "Inherited Access Control Entries"...
How can I create user which do not inderited from such groups automatically...?

Offline

#2 2019-05-13 07:24:13

IF_Eduardo
Administrator
Registered: 2016-11-01
Website

Re: Create User in Administration without inherited Groups

Hi Patryx,

if you create the user under User Root folder (organisational unit), all users/group that have rights on this folder will also have the same rights on children of this folder.
If you click on the parent folder (in this case User Root), you will see that the groups are defined here and which rights/permissions they have *on the given object*. In this case, all members of the Administrators and Users groups will have the rights defined *on the User Root*. So if these both groups have read permissions on the User Root folder, these will also have these permissions on children of User Root.

"what automatically causes that the user has Administators and User in "Inherited Access Control Entries""
Let's say the Group "Users" has read permission on "User Root" OU. If you create a new user under "User Root", this will mean, that the group "Users" will also have read permission on this new user.

If you want to remove the right of Users to read the new user, you may add a new Access Control Entry on the new user and prohibit read right. So it will override the parent' settings.

More information on permissions here: https://reportserver.net/en/tutorials/t … rmissions/ and https://reportserver.net/en/guides/admi … anagement/

Regards,
Eduardo

Offline

#3 2019-05-13 12:39:48

Patryx
Member
Registered: 2019-03-25

Re: Create User in Administration without inherited Groups

Thanks, I noticed that I can inherit permissions to disallow Administrator or Users group but I thought that there should be easiest way.
I understand that I am forced to create user only under User Root? I cannot create user under different (new Folder) using Administrator page of Report Server.

Offline

#4 2019-05-14 12:00:01

IF_Eduardo
Administrator
Registered: 2016-11-01
Website

Re: Create User in Administration without inherited Groups

Hi Patryx,

you can always change the permissions as you need. Please note that the permissions you see here are *on the respective object*. So if you click on user A and you see: group B with reading permission, this means that group B can read user A.

Regards,
Eduardo

Offline

Board footer

Powered by FluxBB