Categories
- All Categories
- 15 Oracle Analytics Sharing Center
- 15 Oracle Analytics Lounge
- 208 Oracle Analytics News
- 41 Oracle Analytics Videos
- 15.7K Oracle Analytics Forums
- 6.1K Oracle Analytics Idea Labs
- Oracle Analytics User Groups
- 76 Oracle Analytics Trainings
- 14 Oracle Analytics Data Visualizations Challenge
- Find Partners
- For Partners
Denied: Authenticated User meaning

Hi,
We are using OBIEE 12c. In the Administration --> Manage Privileges view, some privileges are "Denied: Authenticated User" by default. For example:
My question is does it mean all users (Including Administrators) will be denied this privilege? If so, why do I still see the Administration link along the header menu bar?
Answers
-
Means: Everybody having "Authenticated User" as an App Role will be denied that Permission. Even if you're an Administrator you will be denied it becuase DENY wins.
0 -
OK, thanks for the clarification. So if I'm denied access to the Administration menu, why do I still see it in the header?
0 -
No you won't see it. The GUI will automatically render without anything where you're not allowed to access.
0 -
The BI Administrator Role has an override ... for example this type of thing and row-level security doesn't apply to an admin.
An explicit deny to Authenticated User applies to everyone EXCEPT the Admins.
0 -
Thomas Are you sure that holds true for all optoins? Because we have already seen lockouts happening due to inconsistent security settings.
0 -
Good point it could be spotty in it's application!
Best to avoid that setting (explicit deny on auth user) in the first place.
0 -
Unfortunately, I don't have a system to potentially sacrifice during the experiment, but as a guess: browser cache.
0 -
DENY on AuthUser is something thats anyways reserved for things like writeback in an out of the box setup.
I agree one should be a lot more specific with security control.
0 -
The Denied AuthUser privileges are out of the box, so I didn't mess with it.
The "Access Administration Menu" in Home and Header category does not control the Administration link on header bar. That is actually controlled by "Access to Administration" in the Access category. Now it makes more sense.
0