Select to view content in your preferred language

Privilege to publish publicly set default off

297
1
11-08-2023 05:32 AM
Status: Open
SusanvanderS
Occasional Contributor

The standard member roles that Esri sets up cannot be changed or deleted. Therefore I would like the default setting to be that members cannot publish their content publicly. A new, dedicated, member role could then be created to give certain members the right to publish content publicly.

In our organisation only administrators can publish data publicly. Members have to register a request with an end date and a person that will check the data (quality control) before they get their data published. The administrators can verify that no confidential data is shared publicly and that data is taken offline after the end date.

We see sharing data publicly as a serious process and we don't want members to inadvertently share their data publicly when all they wanted to do was share it with the organisation. We have covered this by creating custom member roles without the privilege to share publicly. But because the standard member roles cannot be deleted, it is still possible that a member might accidentally be assigned to a standard member role instead of our custom member role. Adjusting the default settings would add a layer of protection against data leaks.

Note: this applies to ArcGIS Enterprise as well as ArcGIS Online.

1 Comment
A_Wyn_Jones

This can be changed via Portal for ArcGIS Security settings. Please see the following:

https://enterprise.arcgis.com/en/portal/latest/administer/windows/configure-security.htm#:~:text=Mem...

I have tested this on 10.9.1 with a creator (Publisher role) and I'm unable to share items publicly:

A_Wyn_Jones_0-1699458894807.png

You still have the option to update to public as an administrator.

If you want to create a custom role that allows you to share items publicly, you must enable the following setting:

A_Wyn_Jones_1-1699459308399.png

https://enterprise.arcgis.com/en/portal/latest/administer/windows/privileges-for-roles-orgs.htm

 

If you want to be sure no items are being shared publicly from ArcGIS Server with editing capabilities, the ArcGIS Server Scan picks up on this and alerts you in a report. Please see: 

https://enterprise.arcgis.com/en/server/latest/administer/linux/scan-arcgis-server-for-security-best...

The warning would be SS12 if open layers are found.