 




<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: as400security administrator</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/itanswers/as400security-administrator/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/itanswers/as400security-administrator/</link>
	<description></description>
	<lastBuildDate>Fri, 24 May 2013 19:50:07 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: tomliotta</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/as400security-administrator/#comment-69125</link>
		<dc:creator>tomliotta</dc:creator>
		<pubDate>Fri, 16 Oct 2009 01:35:27 +0000</pubDate>
		<guid isPermaLink="false">#comment-69125</guid>
		<description><![CDATA[One minor note... Once *SECADM is available to your new security administrator, that administrator can create as many profiles as he/she wants. Those new profiles do not need to be created with any group membership. However, that administrator cannot give those new profiles authorities that the administrator does not have.

The administrator doesn&#039;t need to be a member of any group. The administrator only must have at least *CHANGE authority to a group profile before the new profile can be given membership into the group by the administrator. By granting the administrator authority to multiple group profiles, new users can be given membership into any of them.

If the administrator is made a member of a group, the authorities of that group become available to the administrator. Note that a group profile does not have to have *CHANGE authority to itself. (Which may seem strange, and it can have unexpected effects.)

Tom]]></description>
		<content:encoded><![CDATA[<p>One minor note&#8230; Once *SECADM is available to your new security administrator, that administrator can create as many profiles as he/she wants. Those new profiles do not need to be created with any group membership. However, that administrator cannot give those new profiles authorities that the administrator does not have.</p>
<p>The administrator doesn&#8217;t need to be a member of any group. The administrator only must have at least *CHANGE authority to a group profile before the new profile can be given membership into the group by the administrator. By granting the administrator authority to multiple group profiles, new users can be given membership into any of them.</p>
<p>If the administrator is made a member of a group, the authorities of that group become available to the administrator. Note that a group profile does not have to have *CHANGE authority to itself. (Which may seem strange, and it can have unexpected effects.)</p>
<p>Tom</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dand</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/as400security-administrator/#comment-64992</link>
		<dc:creator>dand</dc:creator>
		<pubDate>Tue, 30 Jun 2009 18:18:24 +0000</pubDate>
		<guid isPermaLink="false">#comment-64992</guid>
		<description><![CDATA[You can give admin profile *SECADM but do not give it *ALLOBJ and you can restrict that user from libraries.  Put the profile in a group that is *exclude to those libs or where it doesn&#039;t have authority and *PUBLIC is *exclude to the libraries and objects in them.  I reccomend using authorization list on the libs and objects and having lib/object owners different for each application or in your case, geographical area.   If your admin profile doesn&#039;t have *ALLOBJ it will only be able to create profiles for users in the same group that it is in or that it has authority to.  Make sure it is only authorized to the group for the region you want it to admin by making sure all other profiles and libs are *PUBLIC *EXCLUDE.]]></description>
		<content:encoded><![CDATA[<p>You can give admin profile *SECADM but do not give it *ALLOBJ and you can restrict that user from libraries.  Put the profile in a group that is *exclude to those libs or where it doesn&#8217;t have authority and *PUBLIC is *exclude to the libraries and objects in them.  I reccomend using authorization list on the libs and objects and having lib/object owners different for each application or in your case, geographical area.   If your admin profile doesn&#8217;t have *ALLOBJ it will only be able to create profiles for users in the same group that it is in or that it has authority to.  Make sure it is only authorized to the group for the region you want it to admin by making sure all other profiles and libs are *PUBLIC *EXCLUDE.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nikolai1960</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/as400security-administrator/#comment-64908</link>
		<dc:creator>nikolai1960</dc:creator>
		<pubDate>Sun, 28 Jun 2009 15:48:02 +0000</pubDate>
		<guid isPermaLink="false">#comment-64908</guid>
		<description><![CDATA[dear sir 

thanks a lot, what i need to do is to create a user profile who will only create,copy and delete 
user profiles for a select group of users  and have access to only a list of libraries with no
no authority to other libraries and other users in the system.

Basically we wanty to create a regional user profile for that area users only

Can you please let me know 

thanks]]></description>
		<content:encoded><![CDATA[<p>dear sir </p>
<p>thanks a lot, what i need to do is to create a user profile who will only create,copy and delete<br />
user profiles for a select group of users  and have access to only a list of libraries with no<br />
no authority to other libraries and other users in the system.</p>
<p>Basically we wanty to create a regional user profile for that area users only</p>
<p>Can you please let me know </p>
<p>thanks</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached
Database Caching 6/8 queries in 0.012 seconds using memcached
Object Caching 297/298 objects using memcached

Served from: itknowledgeexchange.techtarget.com @ 2013-05-24 22:35:29 -->