Custom Role to access all Federeated ArcGIS Server Services

727
4
03-12-2020 09:53 AM
NeelKumar
New Contributor III

We are running 10.7.1 federated Server and Portal. It's my understanding that by default, only the person who publishes data to ArcGIS Server and the server Administrator can view/modify/delete a particular services. What we're trying to accomplish is a system where anyone who is assigned to the Publisher (or custom?) role in Portal can view and modify all services within Server Manager. I set up a custom role in Portal that has View, Edit, Manage, Create privileges and a few Admin privileges

Great, now anyone assigned to that role can see all the Services in Server Manger. But they now have access to edit the Server security settings, such as editing the PSA account. Is there a way to give certain users access to view/edit Services within Server Manager without giving them the ability to edit Server Manager security settings?

0 Kudos
4 Replies
ThomasJones1
Esri Contributor

Hello Neel Kumar‌,

If you create a custom role with any administrative privileges, ArcGIS server grants that user full administrative access in ArcGIS Server Manager.    

Administer a federated server—Portal for ArcGIS (10.8) | Documentation for ArcGIS Enterprise 

*Detailed under customer role. 

If you want specific users to see all content you could create a group in portal. Share all the portal items with the new group. Then add the specific users to the new group.

Hope this helps!

Thanks,

Thomas.

0 Kudos
NeelKumar
New Contributor III

Thanks Thomas. I created a new group in Portal and shared an item with this group. I then added one Test user to the that group. The user is currently set to the Publisher role in Portal. The Test user can see the item in Portal but not in Server Manager.  Is there a way to set it up so Publisher roles can access/edit Services via Server Manager?

0 Kudos
ThomasJones1
Esri Contributor

Hello Neel Kumar‌,

What access/edit operations do you want users to able to do in ArcGIS Server manager? In general it's best practices to manage items from a federated server in portal (e.g. Sharing, Deletion). I also ran through the same test and got the same result.

Thanks,

Thomas.

0 Kudos
NeelKumar
New Contributor III

Start stop services, edit the service parameters, configure capabilities. Hoping this functionality isn't locked down to just admins and the data publisher..

Thanks.

Neel

0 Kudos