{"id":6633,"date":"2015-10-15T16:26:21","date_gmt":"2015-10-15T08:26:21","guid":{"rendered":"http:\/\/localhost\/help\/?page_id=6633"},"modified":"2024-11-22T14:04:06","modified_gmt":"2024-11-22T06:04:06","slug":"configuring-default-security","status":"publish","type":"page","link":"https:\/\/oihelp.corporate.ifs.com\/help\/p2-explorer\/security\/configuring-default-security\/","title":{"rendered":"Configuring Default Security in Explorer"},"content":{"rendered":"\n<p class=\"left-bar-yellow\">This article applies to P2 Explorer versions 4.3.0-4.5.5 ONLY. For the latest, see <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/\">Security<\/a>.<\/p>\n<p class=\"intro-text\">Security for P2 Explorer is managed by the P2 Security application.\u00a0<\/p>\n<h2 class=\"page-subheading\">Default Permission Levels<\/h2>\n<p class=\"intro-text\">When P2 Explorer is first installed, by default all users are in the \"Everyone\" global role, and the role\u00a0allows all users read and modify\u00a0access to all of Explorer.<\/p>\n<p class=\"intro-text\">The Everyone role is used by administrators to specify a global setting for anyone who accesses P2 Explorer. For example, the Everyone role can be used to allow all users to view specific pages in P2 Explorer, but not edit them.<\/p>\n<p class=\"intro-text\">Note: All users are automatically assigned to the \u201c<strong>Everyone<\/strong>\u201d global role, even if that role does not exist. If this role is deleted or otherwise does not exist, you can create the role manually so you can secure items and applications against it.<\/p>\n<p class=\"intro-text\">If you want to start restricting access to certain workspaces, pages, or trends, then you need to explicitly specify permissions for all roles for the workspace, page, or trend you are securing.<\/p>\n<p class=\"left-bar\">Related: <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-explorer\/security\/application-and-global-roles\/\">Application and Global Roles<\/a><\/p>\n<hr \/>\n<h2 class=\"page-subheading\">Access Levels<\/h2>\n<p class=\"intro-text\">In P2 Explorer, you can secure workspaces, pages, and trends for viewing and modifying.<\/p>\n<p class=\"intro-text\">Permissions cascade from higher to lower levels. For example, if you secure a workspace then only the users who are able to view the workspace will be able to view the pages and trends within that workspace.\u00a0<\/p>\n<p class=\"intro-text\">However, you can also apply further security to pages and trends within a secured workspace. For example, you may have a workspace that is only visible to managers, but you may then have pages within that workspace that are only visible to senior managers.\u00a0<\/p>\n<p class=\"left-bar\">Related: <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/security\/user-management\/\">User Management<\/a><\/p>\n<hr \/>\n<h2 class=\"page-subheading\">Launching P2 Security<\/h2>\n<p class=\"intro-text\">To open P2 Security, type the URL into the browser's address bar. The URL takes the following form:<\/p>\n<p class=\"intro-text\"><strong>https:\/\/servername.domainname.com\/P2.Security.Connect<\/strong><\/p>\n<p class=\"intro-text\">Note that the server name must be the fully qualified domain name. For example:<\/p>\n<p class=\"intro-text\"><em>https:\/\/cadrondemo01.petroleumplace.com\/P2.Security.Connect<\/em><\/p>\n<hr \/>\n<h2 class=\"page-subheading\">Tutorial: Restrict Access to a Workspace<\/h2>\n<p class=\"intro-text\">If you want to restrict access to a certain workspace, you will need to create an additional global role for those users who can access the restricted workspace. In this example, we'll restrict access to one workspace by creating\u00a0a global role, and only allowing\u00a0that users with that role to view the workspace. Let's assume there's a workspace in P2 Explorer called Managers - this is what we want to restrict.<\/p>\n<h3>Step 1. Create the\u00a0global role<\/h3>\n<p class=\"intro-text\">1. On the left, click <strong>Global Roles<\/strong> (under Administration).<\/p>\n<p class=\"intro-text\">2. In the top right of the blue toolbar, click the Add <img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-3222 size-full\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/04\/addbutton.png\" alt=\"addbutton\" width=\"18\" height=\"18\" \/>\u00a0button . \u00a0<\/p>\n<p class=\"intro-text\"><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/globalroles1.png\" rel=\"lightbox-0\"><img loading=\"lazy\" decoding=\"async\" class=\"border-image alignnone wp-image-6673 size-large\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/globalroles1-800x234.png\" alt=\"\" width=\"800\" height=\"234\" \/><\/a>\u00a0<\/p>\n<p class=\"intro-text\">3. In the <strong>Add Global Role<\/strong> dialog box, type a name and description for the new global role, and then click <strong>OK<\/strong>.<\/p>\n<p class=\"intro-text\">Note that Internal Name is required, and it must be unique and contain no spaces.<\/p>\n<p class=\"intro-text\"><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/addglobalrole.png\" rel=\"lightbox-1\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-6669\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/addglobalrole.png\" alt=\"addglobalrole\" width=\"500\" height=\"174\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/addglobalrole.png 500w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/addglobalrole-150x52.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/addglobalrole-24x8.png 24w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/addglobalrole-36x13.png 36w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/addglobalrole-48x17.png 48w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/a><\/p>\n<h3>Step 2. Restrict access\u00a0<\/h3>\n<p class=\"intro-text\">We'll look at adding users to the global role in the <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/security\/user-management\/\">User Management<\/a>\u00a0article.<\/p>\n<p class=\"intro-text\">Right now, let's focus on how to use the global role to restrict access.\u00a0Now that you've created your global role, we can use that to restrict access to certain workspaces in P2 Explorer.<\/p>\n<p class=\"intro-text\">1. On the left, under <strong>Access<\/strong>, click your P2 Explorer application. In this case, we're clicking <strong>P2.Explorer - cadrondemo01<\/strong>.<\/p>\n<p class=\"intro-text\"><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/application-security.png\" rel=\"lightbox-2\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-large wp-image-6697\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/application-security-800x512.png\" alt=\"application security\" width=\"800\" height=\"512\" \/><\/a><\/p>\n<p class=\"intro-text\">2. The next bit that you have to pay attention to is the <strong>Object Security<\/strong>. This is where you secure your workspaces, pages, and trends.<\/p>\n<p class=\"intro-text\">3. First, select your object type. In this case, we want to secure a <strong>Workspace<\/strong>, so select that.\u00a0<\/p>\n<p class=\"intro-text\">You will need to wait a few seconds for the names of the workspaces to load.<\/p>\n<p class=\"intro-text\"><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/objecttype.png\" rel=\"lightbox-3\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-6699\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/objecttype.png\" alt=\"objecttype\" width=\"710\" height=\"169\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/objecttype.png 710w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/objecttype-150x36.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/objecttype-24x6.png 24w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/objecttype-36x9.png 36w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/objecttype-48x11.png 48w\" sizes=\"auto, (max-width: 710px) 100vw, 710px\" \/><\/a><\/p>\n<p class=\"intro-text\">4. If you have a lot of workspaces, the one you are looking for may not appear in the list. In this case, \u00a0type the first few letters into the <strong>Name filter<\/strong>.<\/p>\n<p class=\"intro-text\"><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/managerobject.png\" rel=\"lightbox-4\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-large wp-image-6712\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/managerobject-800x159.png\" alt=\"managerobject\" width=\"800\" height=\"159\" \/><\/a><\/p>\n<p class=\"intro-text\">4. When the <strong>Managers<\/strong> workspace appears in the list, click it so that it's highlighted dark blue. The edit icon will then appear in the top right corner.<\/p>\n<p class=\"intro-text\"><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/namefilter.png\" rel=\"lightbox-5\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-large wp-image-6716\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/namefilter-800x157.png\" alt=\"namefilter\" width=\"800\" height=\"157\" \/><\/a><\/p>\n<p class=\"intro-text\">5. Click the Edit <img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-6717 size-full\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/securityediticon.png\" alt=\"securityediticon\" width=\"23\" height=\"21\" \/>\u00a0icon.<\/p>\n<p class=\"intro-text\">In the <strong>Edit Access<\/strong> dialog box, you can see that we're editing access for the Managers workspace on P2 Explorer - cadrondemo01.<\/p>\n<p class=\"intro-text\">By default, the <strong>Allow All<\/strong> option is selected, which means that all users are able to read and modify the workspace. As you can see, access depends on the permissions assigned to each\u00a0global role.<\/p>\n<p class=\"intro-text\"><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/editaccessdefault.png\" rel=\"lightbox-6\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-6720\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/editaccessdefault.png\" alt=\"editaccessdefault\" width=\"500\" height=\"388\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/editaccessdefault.png 500w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/editaccessdefault-150x116.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/editaccessdefault-24x19.png 24w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/editaccessdefault-36x28.png 36w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/editaccessdefault-48x37.png 48w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/a><\/p>\n<p class=\"intro-text\">6. We want to customise the permissions, so select the <strong>Custom<\/strong> access option.<\/p>\n<p class=\"intro-text\">Now, we only want people in the <strong>Managers<\/strong> role to view and modify the workspace, and we want to all <strong>Administrators<\/strong> to see it.<\/p>\n<p class=\"intro-text\">7. For <strong>Administrator<\/strong>, select <em>View<\/em>. And for <strong>Managers<\/strong>, select <em>View<\/em> and select <em>Modify<\/em>.\u00a0<\/p>\n<p class=\"intro-text\"><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/customaccess.png\" rel=\"lightbox-7\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-6725\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/customaccess.png\" alt=\"customaccess\" width=\"500\" height=\"388\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/customaccess.png 500w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/customaccess-150x116.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/customaccess-24x19.png 24w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/customaccess-36x28.png 36w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/10\/customaccess-48x37.png 48w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/a><\/p>\n<p class=\"intro-text\">\u00a08. Click <strong>OK<\/strong>.<\/p>\n<p class=\"intro-text\">Access permissions for the Managers workspace\u00a0have now been updated.<\/p>\n<p class=\"intro-text\">You should now <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/security\/user-management\/\">add users<\/a> to the Managers role.<\/p>\n<p class=\"intro-text\">\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The \"Everyone\" role in P2 Security allows administrators to specify a global setting for anyone who accesses an application. This article looks at how to configure default security for all users.<\/p>\n<p class=\"continue-reading-button\"> <a class=\"continue-reading-link\" href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-explorer\/security\/configuring-default-security\/\">Read more<i class=\"crycon-right-dir\"><\/i><\/a><\/p>\n","protected":false},"author":1,"featured_media":6641,"parent":26597,"menu_order":4,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":"","_members_access_role":[],"_members_access_error":""},"categories":[680],"tags":[196],"class_list":["post-6633","page","type-page","status-publish","has-post-thumbnail","hentry","category-security-4-3-0-4-5-5","tag-security","Product-ex"],"_links":{"self":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/6633","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/comments?post=6633"}],"version-history":[{"count":2,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/6633\/revisions"}],"predecessor-version":[{"id":67101,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/6633\/revisions\/67101"}],"up":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/26597"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/media\/6641"}],"wp:attachment":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/media?parent=6633"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/categories?post=6633"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/tags?post=6633"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}