cancel
Showing results for 
Search instead for 
Did you mean: 

Security Groups

Ibrahim_Oweidat
Champ on-the-rise
Champ on-the-rise

Hi,

 

one user has assigned into two security groups, one security group with print privilege and one without. each security group is assigned to a different document type group and document  type.

 

the issue is the user can print the documents in both document types which is wrong. 

 

any solution.

1 ACCEPTED ANSWER

George_Sialmas
Elite Collaborator
Elite Collaborator

@Ibrahim Oweidat If you are referring to OnBase, then this is expected behaviour. When a user is a member of more than one User Group, they inherent combined privileges from all the User Groups they are a member of. If you do not want the user to print documents assigned to one of the document types, then you need to configure override privileges on that document type to explicitly configure it to not allow printing. 

 

Good luck

George

View answer in original post

7 REPLIES 7

George_Sialmas
Elite Collaborator
Elite Collaborator

@Ibrahim Oweidat If you are referring to OnBase, then this is expected behaviour. When a user is a member of more than one User Group, they inherent combined privileges from all the User Groups they are a member of. If you do not want the user to print documents assigned to one of the document types, then you need to configure override privileges on that document type to explicitly configure it to not allow printing. 

 

Good luck

George

@George Sialmas Please link me to OnBase documentation explaining how user group security works with examples please, such that someone wanting to configure security as @Ibrahim Oweidat desired it to work can actually implement it.  We have apparently had user group security set up incorrectly for 24 years.  It would help if Hyland made this clear in the documentation and provided detailed information on how best to implement it.

 

Thank you,

Ray Colbert

@Ray Colbert I don't know if there are examples, however what I can share with you is that the SecurityBestPractices_XX.pdf MRG has a dedicated chapter called Security Model Overview which explains the concept of least privilege and the behaviour of when a user is a member of multiple User Groups. If you are after information on how to configure override privileges then this can be found in the System Administration MRG. 

 

Respectfully,

George

@Ray Colbert , we went through the conversion from default security to least privileged access (adding overrides).  It is a time-consuming process to ensure that people do not lose the access that they need to do their jobs. 

 

We ended up creating 2 or 3 user groups per Document Type Group (depending on business need).  One for Read, one for Create/Modify/ReIndex, and one for Create/Delete. 

Note: delete is required for splitting documents if you want to remove the pages from the original document.  

 

I would advise researching the current security that's being applied to your users and work with the business to determine what they actually need the members of the groups to receive.  Some of my business units didn't realize what they actually had access to, and it took a bit for everyone to switch the thought processes.