|
POST
|
Why do you want to update the sharing permissions on the caching controllers in the first place?
... View more
10-06-2020
06:26 AM
|
0
|
0
|
2760
|
|
POST
|
I'm thinking this could be a CORS issue. What messages, if any, do you get in the browser console?
... View more
09-17-2020
12:46 PM
|
1
|
1
|
1269
|
|
BLOG
|
The Esri Software Security and Privacy Team is proud to announce the newest in our white paper series: Discovering and Limiting Access to Public ArcGIS Survey123 Results! Written for Survey Authors, admins, and privacy professionals and specifically intended to provide targeted guidance for public health initiatives, this guidance highlights best practices, public survey layer discoverability, details specific scenarios, and provides contextual discussion around the various configuration options to be considered to protect your data prior to announcing a public survey where results are to remain secure. From the abstract: "Designing and configuring a Survey with an underlying survey layer can be tricky when the survey is intended to be completed by the public. Discovering insecure survey layers can be challenging for an organization administrator responsible for ensuring collected data is secure and configured to respect respondent privacy. This document provides guidance for GIS administrators, survey owners or users involved in implementing a public survey with respect to privacy and security." We partnered with the ArcGIS Survey123 team to provide this guidance, and we strongly feel that organizations see value in bookmarking this document for reference.
... View more
08-07-2020
09:00 AM
|
1
|
0
|
1268
|
|
POST
|
I don't see this in my reports in my federated environment, but makes sense to me. There's a difference between authenticated and authorized. Not every user that is authenticated should be authorized to this resource. Only publishers or higher should have rights to caching controllers. Otherwise an unauthorized user could potentially kick off a caching job on a service and cause resource consumption issues or fill up your disk with tiles.
... View more
07-28-2020
10:12 AM
|
0
|
0
|
2760
|
|
POST
|
Hi, There are a few ways to think about this: ArcGIS Enterprise and ArcGIS Online. For ArcGIS Enterprise, please review the automated scanning guidance here: https://trust.arcgis.com/en/customer-documents/ArcGIS%20Enterprise%20Vulnerability%20Scanning%20Guidance.pdf Esri does not recommend specific tools for pentesting. That's up to your discretion and the scope of testing defined by the customer. For ArcGIS Online, pentesting and automated scanners are prohibited for ArcGIS Online (ArcGIS.com) without Esri’s explicit consent under our terms of use. Use of automated tools may result in investigative action or your IP(s) being blocked. ArcGIS.com users who wish to perform this level of testing should first reach out to their account teams to obtain a Security Assessment Agreement (SAA).
... View more
07-28-2020
10:00 AM
|
1
|
0
|
2284
|
|
POST
|
Hi Colleen, All uploads submitted to ArcGIS Online are scanned for viruses and malware as required by our FedRAMP accreditation. You’ll find our attestation to this fact in our Cloud Security Alliance (CSA) Consensus Assessments Initiative Questionnaire (CAIQ). This document is one of many we provide in the documents tab in the ArcGIS Trust Center. We scan all uploaded files submitted to ArcGIS Online for viruses/malware. If malware or a virus is detected, the file is rejected and the event is logged in the customer’s organization in the activity log. Common Questions we answer here include: Where is my data hosted? Within AWS and MS Azure datacenters on US Soil by default, though starting in March 2020 new organizations will be able to choose to have their data stored in the US Region or the new EU Region. Is my data encrypted at rest and in transit? Yes, new organizations use HTTPS w/TLS 1.2 for in-transit and AES-256 at rest. Is my data backed up? Customers are responsible for backing up their datasets. Can I do security tests against ArcGIS Online? Yes, however a Security Assessment Agreement (SAA) must be completed first. Are my files scanned with Anti-virus? Yes – Files containing malicious code are rejected from upload. What privacy assurance is in place? ArcGIS Online is Privacy-Shield self-certified, and both GDPR/CCPA aligned.
... View more
05-11-2020
06:16 AM
|
4
|
1
|
3125
|
|
BLOG
|
A new Windows-based application has been created by a malicious individual or group that uses the the online map posted by John Hopkins University at https://coronavirus.jhu.edu/map.html as a decoy for installing Malware.Michael Young has written a blog describing this issue. Bottom-line, you are fine browsing the Coronavirus dashboard on the web with your browser as no software needs to be downloaded. If you come across someone offering a Coronavirus dashboard where you need to download software to view it, don’t use it! You'll find this blog titled "Coronavirus Downloadable Malware Map App Clarification" in the 'Alerts and Announcements' section on the front page of the ArcGIS Trust Center.
... View more
03-12-2020
08:48 AM
|
7
|
0
|
2230
|
|
BLOG
|
Esri’s Software Security and Privacy team is often called by both current and prospective customers to provide assurance as to the kinds of controls we’ve implemented to help keep your data and our infrastructure safe. Esri has provided a detailed list of answers to questions related to the security of the ArcGIS Online platform for security professionals in the form of the CAIQ Answers document. Esri’s CAIQ response document provides a set of 295 yes or no questions a cloud consumer or cloud auditor may wish to ask of a cloud provider. You’ll find this document (along with many others) in the Documents tab in the ArcGIS Trust Center. The CAIQ is a survey provided by the Cloud Security Alliance (CSA) for cloud solution consumers and auditors to assess the security capabilities of a cloud service provider like ArcGIS Online. The CAIQ was developed to create commonly accepted industry standards to document how service providers like Esri implement security controls in infrastructure-as-a-service (IaaS), platform-as-a-service and (PaaS)/or software-as-a service (SaaS) applications. The CAIQ questionnaire is designed to support organizations when interacting with cloud provider during the cloud provider assessment process by giving organizations specific questions to ask about provider operations and processes. The CAIQ is part of the CSA governance, risk management and compliance stack. The CSA is a “not-for-profit organization with a mission to promote the use of best practices for providing security assurance within Cloud Computing, and to provide education on the uses of Cloud Computing to help secure all other forms of computing”. A wide range of industry security practitioners, corporations, and associations participate in this organization to achieve its mission. Esri began providing answers for the CSA CCM (133 questions) in 2013, and in 2019 shifted to utilizing the more extensive (CAIQ) with 295 questions/answers. ArcGIS Online is audited annually by a 3rd party assessor to ensure alignment with its Federal Risk and Authorization Management Program (FedRAMP) Tailored Low Authority to Operate (ATO) by the United States Department of Interior. For more information concerning the security, privacy and compliance of ArcGIS Online please see the Trust Center at: https://Trust.ArcGIS.com. ArcGIS Online utilizes the World-Class Cloud Infrastructure of Microsoft Azure and Amazon Web Services, both of which have completed the CSA questionnaires for their capabilities and may be downloaded from the CSA Registry located at: https://cloudsecurityalliance.org/star/#_registry Our responses to these questions meet Level 1 self-assessment requirements for the CSA’s Security Trust Assurance and Risk (STAR) Program. For a more lightweight set of answers, a basic overview of ArcGIS Online security (2-page flyer) is available within the Trust Center documents. Some basic, recurring customers questions include: Where is my data hosted? Within AWS and MS Azure datacenters on US Soil. (CAIQ ID: BCR-032.2, DSI-01.1) Is my data encrypted at rest and in transit? Yes, new organizations use HTTPS w/TLS 1.2 for in-transit and AES-256 at rest. (CAIQ ID: EKM-03.1) Is my data backed up? Customers are responsible for backing up their datasets. (CAIQ ID: DSI-04.1) Can I do security tests against ArcGIS Online? Yes, however a Security Assessment Agreement (SAA) must be completed first. Are my files scanned with Anti-virus? Yes – Files containing malicious code are rejected from upload. (CAIQ ID: CCC-04.1) What privacy assurance is in place? ArcGIS Online is Privacy-Shield self-certified, and both GDPR/CCPA aligned. (CAIQ ID: GRM-06.4) For any questions/concerns/feedback please contact Esri’s Software Security & Privacy Team at: SoftwareSecurity@Esri.com References: https://cloudsecurityalliance.org/ https://searchcloudsecurity.techtarget.com/definition/CAIQ-Consensus-Assessments-Initiative-Questionnaire https://blog.whistic.com/5-of-the-top-questionnaires-for-it-vendor-assessments-e1fc5b927eb9
... View more
03-12-2020
08:42 AM
|
1
|
0
|
2055
|
|
POST
|
See: Is there a way to track concurrent license usage and lockouts? also: GitHub - jmitz/ArcGISLicenseMonitor: Aids in monitoring licenses managed by ESRI's ArcGIS License Manager. Python script… There are likely others. You'll probably get better responses in the ArcGIS Desktop installation space, so I'll move this question there.
... View more
03-11-2020
09:21 AM
|
0
|
0
|
2023
|
|
BLOG
|
A new Tomcat CVE (CVE-2020-1938) referred to as 'Ghostcat' has a lot of users asking how Esri software is affected. Michael Young has written a blog describing how users may be impacted and offers guidance for customers who deploy the Java version of the ArcGIS Web Adaptor on Tomcat or use Apache httpd along with Tomcat in a reverse proxy solution. You'll find this blog titled "Don't get Bitten by GhostCat Tomcat Vulnerability"in the 'Alerts and Announcements' section on the front page of the ArcGIS Trust Center.
... View more
03-04-2020
06:12 AM
|
1
|
0
|
1181
|
|
POST
|
While I can't say I know what might cause this, I can state that others have fixed this kind of issue in the past by restarting the Portal for ArcGIS Windows service.
... View more
02-28-2020
07:29 AM
|
1
|
1
|
992
|
|
POST
|
In order for the community to answer this question, you'll need to provide more details. What error is the user seeing? How is the ArcGIS Server instance federated with the Portal? What data is the user attempting to download? How are they accessing the site - like, did you pass them a link, or are they browsing through?
... View more
02-28-2020
07:26 AM
|
0
|
1
|
5919
|
|
POST
|
At this point, I'd have to defer to Tableau support. I've never worked with their product so I'm unsure what it's expecting here.
... View more
02-19-2020
08:11 AM
|
0
|
2
|
5638
|
|
POST
|
hmmm 2 things: a. I think it should be /tiles/j75S08un0OPoEcHD/arcgis/rest/services/LSIB9_polygons/MapServer/WMTS/tile/1.0.0/LSIB9_polygons/{Style}/{TileMatrixSet}/{TileMatrix}/{TileRow}/{TileCol}.png Check out this link, there are good suggestions there: Documentation of Tableau Map Service Connections |Tableau Community Forums
... View more
02-18-2020
09:53 AM
|
1
|
4
|
5638
|
|
POST
|
Interesting. I've personally never used Tableau, but I can state: a. Ports 80 and 443 are the "standard" ports for http and https. That's why you don't need to qualify a port number in most web requests - like, a browser will know that a request to https://google.com will go to 443 on the remote server. b. However, in some cases the client must specify the port number - for instance, you may have a non-default site where a user must make a request to https://randall.com:8443/index.html - becuase :8443 isn't a standard https port. These resources might help: How to Use ArcGIS Data, Features and Basemaps in Tableau https://community.tableau.com/ideas/6756#comment-24519 I took a look at some example TMS files. Assuming this example is up-to-date, then the syntax "should" look like this: <?xml version="1.0" encoding="utf-8"?> <mapsource inline="<boolean>" version="8.1"> <connection class="OpenStreetMap" indicator-server="services.arcgisonline.com" intermediate-levels="0" layer separator="/" max-scale-level="16.0" max-stretch="1.0" min-shrink="1.0" offline="" port="443" server="services.arcgisonline.com" url-format="arcgis/rest/services/USA_Topo_Maps/MapServer/WMTS/tile/1.0.0/USA_Topo_Maps/default/default028mm/{Z}/{Y}/{X}.png"/> <layers> <layer display-name='Base' name='base' show-ui='false' type='features' request-string='/' /> </layers> </mapsource> You'd want to update the bold section with the name of the basemap you're consuming. The example above was pulled from the WMTS capabilities file for the USA_TOPO map here http://services.arcgisonline.com/arcgis/rest/services/USA_Topo_Maps/MapServer/WMTS/1.0.0/WMTSCapabilities.xml
... View more
02-18-2020
07:39 AM
|
1
|
1
|
5638
|
| Title | Kudos | Posted |
|---|---|---|
| 1 | 03-05-2026 06:49 AM | |
| 1 | 02-19-2026 07:09 AM | |
| 2 | 02-17-2026 02:27 PM | |
| 3 | 11-17-2025 07:06 AM | |
| 1 | 05-24-2018 07:28 AM |
| Online Status |
Offline
|
| Date Last Visited |
04-10-2026
06:56 AM
|