SSAS Security : Avoid Proliferation of AD Groups & SSAS Roles
hi, investigating requirement client implement fine grained ssas security roles, have 10 cubes bound global active directory groups.
for example, current ad groups
bi_sales, bi_orders, bi_inventory (and on). these bound ssas cubes (sales, orders, inventory), each group holding data @ global level (across around 10 countries).
i need implement security country , business vertical, , have dimensions set these, , coding users dimension also.
however, concerned sustainability of security model, have 10 countries , 7 verticals. if grows, there sharp increase in number of ad groups. concerned sheer number of ad groups individual user allocated to, potentially slow down user access network, or @ best provide headache dba need support security model in future.
i looking ideas can improve flexibility , sustainability of model, if 1 has experienced type of architecture please let me know !
thanks in advance, david
are users in sql table, along countries , verticals permitted see? if so, hold security information in cube, dynamically updating, inline sql table. see http://richardlees.blogspot.com.au/2010/10/ssas-dynamic-security.html more information.
you create hybrid using ad groups, roles , dynamic ssas security.
hope helps,
richard
SQL Server > SQL Server Analysis Services
Comments
Post a Comment