<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Securing REST folders/services by roles in ArcGIS Enterprise Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-questions/securing-rest-folders-services-by-roles/m-p/269834#M10371</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Venus,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;gt; We want to allow our users to publish and manage their "own" services, but not be allowed to manage any other ones. Is there any other method to achieve this?&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, this is possible if you federate your ArcGIS Server site with Portal for ArcGIS. After federation, the Server site will follow the security model of Portal - which means only item owners will be able to edit/manage their content. So, publishers will only be able to manage their own web services.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 07 Dec 2015 19:08:31 GMT</pubDate>
    <dc:creator>DerekLaw</dc:creator>
    <dc:date>2015-12-07T19:08:31Z</dc:date>
    <item>
      <title>Securing REST folders/services by roles</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/securing-rest-folders-services-by-roles/m-p/269832#M10369</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;According to the following page, users who have Publisher's role have access to all services and folders within the ArcGIS Server site.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV style="margin-left: 40px;"&gt;&lt;SPAN style="color: #4d4d4d;"&gt;"When a role has its role type set to Administrator or &lt;SPAN style="text-decoration: underline;"&gt;Publisher&lt;/SPAN&gt;, members of that role will have implicit permission to access &lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;all&lt;/STRONG&gt;&lt;/SPAN&gt; services hosted on an ArcGIS Server site. This implicit permission cannot be overridden by changing the permissions on a service or folder. "&lt;/SPAN&gt;&lt;BR /&gt; &lt;A href="http://server.arcgis.com/en/server/latest/administer/windows/editing-permissions-in-manager.htm" title="http://server.arcgis.com/en/server/latest/administer/windows/editing-permissions-in-manager.htm"&gt;http://server.arcgis.com/en/server/latest/administer/windows/editing-permissions-in-manager.htm&lt;/A&gt; &lt;/DIV&gt;&lt;DIV style="margin-left: 40px;"&gt;&lt;P&gt;&lt;/P&gt;That means, Publishers can stop or delete &lt;STRONG&gt;any&lt;/STRONG&gt; services hosted on the site.&lt;BR /&gt; &lt;BR /&gt; For example, if one organization is using ArcGIS 10.x for Server and wants to manage map services by departments, the OOTB ArcGIS Server does not have the capability to hide folders and services from publishers. We want to allow our users to publish and manage their "own" services, but not be allowed to manage any other ones.&lt;/DIV&gt;&lt;DIV style="margin-left: 40px;"&gt; &lt;/DIV&gt;&lt;DIV style="margin-left: 40px;"&gt;Is there any other method to achieve this?&lt;/DIV&gt;&lt;DIV style="margin-left: 40px;"&gt; &lt;/DIV&gt;&lt;DIV style="margin-left: 40px;"&gt; &lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Dec 2015 21:12:18 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/securing-rest-folders-services-by-roles/m-p/269832#M10369</guid>
      <dc:creator>VenusScott</dc:creator>
      <dc:date>2015-12-03T21:12:18Z</dc:date>
    </item>
    <item>
      <title>Re: Securing REST folders/services by roles</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/securing-rest-folders-services-by-roles/m-p/269833#M10370</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are right. Here's the list of dos and dont's that the Publisher role has capability for: &lt;/P&gt;&lt;P&gt;&lt;A href="http://server.arcgis.com/en/server/latest/administer/linux/publisher-role-support-in-manager.htm" title="http://server.arcgis.com/en/server/latest/administer/linux/publisher-role-support-in-manager.htm"&gt;Publisher role support in Manager—Documentation (10.3 and 10.3.1) | ArcGIS for Server&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; However, as you had asked for, there was an enhancement request asking for limiting Publisher's role to just publishing and modifying services: NIM086293: Restrict the access of Publisher Role in the ArcGIS Server 10.1 just to publishing and modifying the map services.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This idea was rejected because the role of Publisher was designed to create, delete and modify all services in Server Manager. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps! &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Dec 2015 23:35:26 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/securing-rest-folders-services-by-roles/m-p/269833#M10370</guid>
      <dc:creator>AravindatStoryMaps</dc:creator>
      <dc:date>2015-12-04T23:35:26Z</dc:date>
    </item>
    <item>
      <title>Re: Securing REST folders/services by roles</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/securing-rest-folders-services-by-roles/m-p/269834#M10371</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Venus,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;gt; We want to allow our users to publish and manage their "own" services, but not be allowed to manage any other ones. Is there any other method to achieve this?&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, this is possible if you federate your ArcGIS Server site with Portal for ArcGIS. After federation, the Server site will follow the security model of Portal - which means only item owners will be able to edit/manage their content. So, publishers will only be able to manage their own web services.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Dec 2015 19:08:31 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/securing-rest-folders-services-by-roles/m-p/269834#M10371</guid>
      <dc:creator>DerekLaw</dc:creator>
      <dc:date>2015-12-07T19:08:31Z</dc:date>
    </item>
    <item>
      <title>Re: Securing REST folders/services by roles</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/securing-rest-folders-services-by-roles/m-p/269835#M10372</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Derek, we are now looking into whether or not Portal is needed in our organization. This function makes a good case for it! Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Dec 2015 19:13:43 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/securing-rest-folders-services-by-roles/m-p/269835#M10372</guid>
      <dc:creator>VenusScott</dc:creator>
      <dc:date>2015-12-07T19:13:43Z</dc:date>
    </item>
  </channel>
</rss>

