SAP Knowledge Base Article - Public

2963309 - How to deny user sharing file, folder, story in SAP Analytics Cloud ?

Symptom

  • How to deny user sharing file, folder, story in SAP Analytics Cloud ? 
  • How to prevent user with Private security only to share files to others ?

Images and data taken from SAP internal systems and demo environments. Any similarity to production data is purely coincidental.

Environment

SAP Analytics Cloud (SAC).

Reproducing the Issue

  1. Logon to SAC by BI Admin role user.
  2. Security -> Roles, Create a New Role by + . Assign a name to the role and select License TypeBusiness Intelligence.
  3. Select a Role template - BI Content Creator.
  4. Deselect Create / Delete security in the role.                                                                                                                                                                                                                                                                                                                                                                                                Private Roles.png
  5. Save the role.
  6. Assign Users to assign this new role a UserA without other roles assigned.
  7. Log out the BI Admin role user.
  8. Logon to SAC by UserA.
  9. Create a new story with any design. Save the Story.
  10. Click Share button.
  11. Observe the user can share private file to others by the Share feature.

Cause

In the newly created role, Read permission is enabled on User and Team, so the UserA can still read user and team list while sharing.

Read on team and user enable.png

Resolution

Disable the Read permission on User and Team in the newly created role. Then UserA will not be able to see the user/team list while sharing.

See Also

Keywords

Story, file, folder, table, crosstab, grant, forbidden, pervent, disable, denied, force, invisible, visible , KBA , LOD-ANA-DES , Story Design & Visualizations , Product Enhancement

Product

SAP Analytics Cloud 1.0