<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic sde superuser role on PostgreSQL in Geodatabase Questions</title>
    <link>https://community.esri.com/t5/geodatabase-questions/sde-superuser-role-on-postgresql/m-p/1071566#M7242</link>
    <description>&lt;P&gt;We have a PostgreSQL server that is shared between departments. As there are non-GIS related tables in other databases on the same server, we'd like to limit the team working with ArcSDE from accessing or potentially impacting other data in other databases.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In order to do so and to adhere to the principle of least privilege, we'd like to maintain an "sde" account without superuser privileges. We can make the sde account owner off the associated GIS databases, but would want to restrict the account from seeing the non-GIS databases. Is this possible? It would be acceptable if the majority of GIS tasks could still be completed but the tasks like kicking users fails.&lt;/P&gt;&lt;P&gt;Are there any issues with restricting the sde account by removing the superuser role?&lt;/P&gt;</description>
    <pubDate>Wed, 23 Jun 2021 16:27:34 GMT</pubDate>
    <dc:creator>JohnReiser</dc:creator>
    <dc:date>2021-06-23T16:27:34Z</dc:date>
    <item>
      <title>sde superuser role on PostgreSQL</title>
      <link>https://community.esri.com/t5/geodatabase-questions/sde-superuser-role-on-postgresql/m-p/1071566#M7242</link>
      <description>&lt;P&gt;We have a PostgreSQL server that is shared between departments. As there are non-GIS related tables in other databases on the same server, we'd like to limit the team working with ArcSDE from accessing or potentially impacting other data in other databases.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In order to do so and to adhere to the principle of least privilege, we'd like to maintain an "sde" account without superuser privileges. We can make the sde account owner off the associated GIS databases, but would want to restrict the account from seeing the non-GIS databases. Is this possible? It would be acceptable if the majority of GIS tasks could still be completed but the tasks like kicking users fails.&lt;/P&gt;&lt;P&gt;Are there any issues with restricting the sde account by removing the superuser role?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 16:27:34 GMT</pubDate>
      <guid>https://community.esri.com/t5/geodatabase-questions/sde-superuser-role-on-postgresql/m-p/1071566#M7242</guid>
      <dc:creator>JohnReiser</dc:creator>
      <dc:date>2021-06-23T16:27:34Z</dc:date>
    </item>
    <item>
      <title>Re: sde superuser role on PostgreSQL</title>
      <link>https://community.esri.com/t5/geodatabase-questions/sde-superuser-role-on-postgresql/m-p/1071591#M7243</link>
      <description>&lt;P&gt;There are some times when the 'sde' login needs advanced privileges (install/upgrade on other than RDS), but other than that, there shouldn't be any problem with plain vanilla user privs.&lt;/P&gt;&lt;P&gt;- V&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 17:28:22 GMT</pubDate>
      <guid>https://community.esri.com/t5/geodatabase-questions/sde-superuser-role-on-postgresql/m-p/1071591#M7243</guid>
      <dc:creator>VinceAngelo</dc:creator>
      <dc:date>2021-06-23T17:28:22Z</dc:date>
    </item>
  </channel>
</rss>

