#
Configuring Roles for Data Restrictions
Use this option to configure restrictions to users or groups in accessing or viewing the data through reports and dashboards.
#
Limitations
Note the following limitations when configuring object-level restrictions in the OLAP database:
The restrictions configured will not be applied to SQL Server Analysis Services server administrators.
The restrictions configured will NOT be applied to Analysis Server service account.
All the restricted users should not be included in roles with Full Permission.
These users have full privilege to access the OLAP database and server.
The Open iT Reporting Services data sources should use either:
Windows Integrated Security
Credentials supplied by the user running the report.
Analysis Server Administration: Configuring Role SSRS CredentialsThe restricted role must have at least Read permission to the OLAP Applications cube.
Avoid including users to multiple roles to avoid conflicts in restrictions. If a user belongs to multiple roles, all the allowed properties in each role will be visible to the user.
#
Configuring Data Restrictions
To set object-level roles in OLAP cube:
Choose the role to configure.
Click the Configure button.
A Configure Role dialog will appear.
Choose among the available Dimensions.
Choose among the available Attribute Hierarchy under the selected dimension.
Choose from the following options for selecting data:
Select All - to allow role members to access the dimension and attribute data.
Deselect All - to deny role members to access the dimension and attribute data.
Read the instructions provided under the option carefully.
Click Update to apply changes.
A confirmation message will appear.
Click OK.
#
Verifying Data Restrictions in Reporting
After configuration, the restrictions will immediately take effect to ad hoc reporting using the following tools:
SQL Server Reporting Services
Microsoft Excel
The reporting tool should be accessed by the restricted user to see the effect.
The configuration is not applicable in Analysis Server - Analysis page reporting.
#
Verifying Data Restrictions in Real-time Dashboard
Activate the role-based data display on the License Monitor Portal to apply the configuration in the real-time dashboard.
If the configuration did not immediately take effect, run the command OpeniT.Server.Etl.Console.exe UpdateRoleGroups using the Analysis Server console application. Please see the section UpdateRoleGroups for detailed instructions.