User Schema's and default access

Hi,
I noticed that my schema A and B can create tables , etc. for each other. When I log in as A I should only see and have access to schema A. When I log in as B only for B.
Why is that not happening?

(1) CREATE USER fountain WITH DEFAULT_SCHEMA A
   -- Assuming that there already is a login A.
GRANT CREATE TABLE TO fountain
go
CREATE SCHEMA fountain AUHTORIZATION fountain
I get an error that there is the wrong syntax near "fountain". No idea why.
(2) Secondly, what about all the other rights like alter table, insert, delete, drop..do I need to restrict access to all those operations manually? I thought it would be easier to create a user that has only access to his/her schema.
(1)
It's simply a typo.
It should be ..."AUTHORIZATION"...
(2)
Well, if you want a user to have FULL permissions on a certain schema you can make him the owner of that schema as you did, or give him CONTROL permission on the schema.
I don't see where this is not "simple"
it GETS more complicated when you want to grant only CERTAIN permissions for sure.
Andreas Wolter (Blog |
Twitter)
MCSM: Microsoft Certified Solutions Master Data Platform, MCM, MVP
www.SarpedonQualityLab.com |
www.SQL-Server-Master-Class.com

Similar Messages

  • Protected access and Default access

    hi all,
    Can you tell exact difference between protected access and default access.
    Thanks in advance.

    default (for classes*), also known as "package" or "package private": accessible from within that class and other classes in the same package.
    protected: accessible from within that class, other classes in the same package, and subclasses.
    *Note that for interfaces, the "default" access is pubic, not "package private".                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       

  • E61i worldmate problems and default access point

    I cannot get Worldmate to connect without error. Worldmate support tell me to ensure that the "device default access point" is correct. However, I have not been able to find a global default access point setting anywhere, including the help doc!
    Once into worldmate, you can apparently change your access point, but the first time it looks for a global default. So I cant even get in!
    My phone is working fine with GPRS and WLAN, as long as the application allows me to select the access point.
    Perhaps this is a change between e61 and e61i?
    Anybody have the same problem?
    Chris

    05-Aug-200708:01 PM
    gtach43 wrote:
    I have the same problem.
    Both WorldMate and GolfPro2 workd when I first installed them. Now when I try to open them nothing happens.
    I redownloaded WorldMate and re-installed, then both worked. After shutting down, neither work again.
    How do you resolve this? Is it based on the access point?
    Glenn
    The exact same thing happens to me when I install other programs, like Nokia Maps or 3D pool. When I install them and reboot, both worldmate and the new installed program doesn't work. This doesn't happen with other programs that I've installed so far, like Gmail or google maps.

  • Lotus Notes and Network access slow

    I'm new to this environment and when I arrived I notices that all switches are trunk to one 6509 core switch, which is fine. The 6513 switch is the server farm switch and also the aggregation switch. the issue is sometimes sme users Lotus Notes and Network access is really slow, uer need spend to 5 min to log in Lotus Notes. this problem is not always happen. lots of times whne i arrive users office, everytinh is fine. i check my network, i found the root of spanning tree is not 6509 core switch. is this the reason for network slow ?
    please help me
    thanks

    You will need to ensure that spanning-tree is not
    re-converging. You can do this by monitoring the logging on your switches and or syslogging. You could make the 6509 root bridge by giving it a
    lower bridge value.
    Spanning tree should converge and be stable, if it isn't then you need to make sure links are not coming up and down and that there are not deeper problems like loops etc. Make sure all your server links are switchport mode access and bpduguard. Things like that.
    Check the links to the notes server for errors, ensure that they are the correct speed and duplex.
    Use tools like ping to check round trip times to your notes server from the switch, then from an end
    user.
    Use a traffic sniffer like ethereal to ensure that the tcp conversations on port 1352 are timely)
    A badly written view can cause big delays for your notes users.

  • User accounts, directory structures and selective access privileges

    Bought a new MacBook Pro back in April and only now am I getting down to using it. I was thinking of creating the following user accounts in the hope of creating a scheme that allows selective access to certain folders:
    Root -a super user account
    Admin - I don’t think I should be logged in as the administrator all the time
    Jai Gill - my main account with all my work files including client information that is organised in a Workflow folder containing a Projects folder and a Clients folder (within which, each of my clients has a folder)
    Show Time - a secure Simple Finder type account for when I am running a client specific presentation or workshop to ensure all data for other clients is kept secure and away from prying eyes.
    When using the Show Time account, I would like to set it up so that only those files relating to the client in question are available for use. For instance, if I am running a workshop for Client G, I only want the folder for Client G available for use in this account and not any other clients. A few hours or days later, this could change to Client B or F or J etc so I need a way to easily secure the current client’s data and switch over to the other client’s data i.e., put away work and pull up new work.
    Would it be possible to create a scheme using aliases placed in Show Time’s Documents folder pointing at a client folder in my documents folder to allow this to happen? Would I have to create a group with the right access privileges to enable this to happen? Or is there an alternative method based on using the Shared files folder and some sort of script or application to create a duplicate of a client folder and use a scheme to synchronise it with the original client folder?
    Is this possible in Mac OSX? Any thoughts? Ideas? Applications/utilities that already enable this to happen?
    MacBook Pro   Mac OS X (10.4.9)  

    Hi Kiraly
    I cracked it today. Took a couple of hours to figure out some idiosyncrasy but I'm now set.
    Here's what I did:
    1. Got a copies of Sharepoint, Workgroup Manager and ChronoSync.
    2. Logged into the MacBook Pro as myself, went into System Preferences and used the normal approach to set up an account for a user called Show Time
    3. Using Workgroup Manager, created an addition workgroup called macshow
    4. Made myself and Show Time members of macshow
    5. Attached the MBP to my G5 using my 2gen iPod's FireWire cable and cranked it up in target disk mode
    6. Using ChronoSync, did a 'bi-directional' synchronisation of my Workflow folder into a location in the MBP's Shared folder (going to do this all the time)
    7. Shut down, detached then restarted the MBP and logged on as myself.
    8. Located the Workflow folder in the Shared folder and by getting information, set that folder and all it's contents to be owned by me but accessible and R/W for the group macshow
    9. Went two levels into the Workflow folder [Workflow/4 Delivery/Client T] and using SharePoint, made the folder Client T accessible to the group macshow.
    10. Logged in as Show Time and accessed the Shared folder to find that my scheme had worked and I had access to the folder for Client T and all it's contents.
    11. Logged out and went back in under my ID and now using System Preferences, crippled the Show Time account down to Simple Finder with access limited to just a handful of applications like KeyNote, Word, Excel, Powerpoint and Safari.
    12. Went back in as Show Time and it went into Simple Finder and thereafter, everything works great. Workflow showed up as did the folder for Client T plus all its contents. Opened a few documents and presentations and they wrked great.
    New learning points for me:
    1. I had to log out then log back in to make the access privileges stick when using the Show Time accounts
    2. A number of locked Excel files prevented access privileges being set - had to locate and unlock each
    3. Using both SharePoint and Workgroup Manager may be seem to be overkill but it works as these two applications helped in getting the groups sorted out as well as access to a specific folder.
    The best part of the above scheme is that I can at anytime, using SharePoint, change the client folder being shared with the user Show Time through the use of the group macshow i.e., change Client T back to my group and then pick say Client J or any number of other client folders and assign them to the group macshow.
    Thanks to you and the others who have posted on this and all other threads on this topic, I have sorted this out in one go.
    Jai
    PS in case you're wondering why it took me so long to get down to do it, it is something called client work. And may there be more of it too!
    iMac G5 and MacBook Pro   Mac OS X (10.4.10)   MacUser since 1984

  • Change public share access to read only for public and full access to selected users

    Hi, new to the community just purchased a recertified WDMyCloud 2TB after my 2 years old MyBookLive 2TB HD died due to accidental power cable unplugging. I've got everything setup including MiniDLNA by following instructions on this forum and everything is working  exactly as I want it to except public share. I want public share to be set to read only access for public and full access to certain users (just myself at the moment) and having a "upload" folder within this share with full public access to everything in this folder would be a bonus. I tried login in to ftp with root user and removing write permission for public but that blocks me out as well. I'm sure it's possible by doing some majic on SSH but I wouldn't have a clue so hoping someone here would be able to help me out.

    Mr_Khan wrote:
    What i want is public to have read only access to file server. Public as in users who do not have a user account on mycloud. E.g someone who connects to to my home network for the first time and is able to browse and download content from public share. I'm aware of being able to set indivual access to shares for users like full access, read only and no access but public users won't have a user account.Through the My Cloud UI interface what you seek to do is not possible. The public share like all other share folders are an all or nothing affair when using the adminstration UI. When using the administration UI you do not have granular control on shared folders to limit non users to read only access or set permission levels for subfolders. The workaround to do what you seek and have the public folder set for read only is to change the folder settings via SSH. It may take some work to set the folder security so that users can read/write to the public folder while the guests only have read access. However, if you reboot the WD My Cloud or update the WD My Cloud firmware those settings may be reset back to the default settings where the entire public folder is read/write for all. There are way to prevent this but again it will take a bit of coding to do so via SSH. See this link (even though its for the WD My Book Live) for a starting point on how to use SSH to change the permission levels on the public folder. Another option if one doesn't go the SSH route is to turn off public sharing for the public folder then create a "guest" user account and give that "guest" account read only access to the public folder while all other user accounts have full read/write access.

  • Are Profiles and DBA Access to users required after MRCA is installed ?

    Customer has installed oracle B2B through MRCA .
    There are 4 questions that need to be answered.
    Question 1
    ===========
    We would like to know if the profiles and DBA access to users are required after MRCA is installed ?
    Question 2
    ==========
    If we remove these privileges will there be any impact to future Application Server upgrades, applying of patches ?
    Question 3
    ============
    There is a schema called BASEDEF with the two roles BASEAPP_ADMIN and BASEAPP_INSTANCE_ADMIN .
    Please could you let us know the purpose of this schema and its usage ?
    Question 4
    ============
    Does the schema BASEDEF affects b2b in any manner ?
    Regards,
    Suresh

    Hi Suresh,
    Please find below answer of your questions-
    1. Profiles are created automatically during installation and they are required for maintaining the functionality of B2B. DBA access to these profiles are not required.
    2. If you revoke DBA access from the profiles, then it should not affect the functionality of B2B. Generally Patch scripts are run on account "b2b" and this account does not have dba access so there should be no problem due to access revoke.
    Any DBA can answer your 3rd and 4th question.
    Regards,
    Anuj

  • [SOLVED]change default access creation rights for the users

    Hi!
    When a user creating folders or files it will allow full access to all users who are in the same group.
    How can I make the changes to be default instead of using chmod always?
    Last edited by Andy_Crowd (2014-06-11 14:47:29)

    Here is an example with some entries from my smb.conf
    security = share
    guest account = windowstools
    [WT]
    path = /home/Windows/Win-tools
    public = yes
    writeable = yes
    create mask = 0000
    guest ok = yes
    browseable = yes
    read only = no
    Windows XP is connected to my Linux share. I want be able to create folders and have access within Linux and Windows with rwx rights for the group. For now files created from Windows getting default rights 755 (rwx,xr,xr).
    windowstools:andy = is XP username/group
    andy:andy = Arch Linux username/group
    Windows XP is full updated (got problem once with connection to samba after update, got wait until next updates will come -.- , when new windows updates came XP could be connected to samba again, was a bug as I hoped).
    I am starting/restarting samba with script like
    #!/bin/bash
    systemctl stop smbd
    sleep 2
    systemctl status smbd | head -1
    systemctl status smbd | grep 'Active:' | awk -F')' '{print $1}' | sed 's/(//m'
    systemctl stop nmbd
    sleep 1
    systemctl status nmbd | head -1
    systemctl status nmbd | grep 'Active:' | awk -F')' '{print $1}' | sed 's/(//m'
    systemctl start smbd
    sleep 2
    systemctl status smbd | head -1
    systemctl status smbd | grep 'Active:' | awk -F')' '{print $1}' | sed 's/(//m'
    systemctl start nmbd
    sleep 1
    systemctl status nmbd | head -1
    systemctl status nmbd | grep 'Active:' | awk -F')' '{print $1}' | sed 's/(//m'
    and not automatically on boot.
    Windows XP is running in VMware Player on the same PC with Arch Linux.
    Last edited by Andy_Crowd (2014-06-11 12:42:52)

  • How to find out list of users and their access on Sharepoint

    Hello Everyone
    How can i find out list of users and what access they have on SharePoint site? I want to create table with list of the users and their access?
    Thanks

    you can get the report using below powershell scripts. first one gives list of users in a site collection level.
    The second link generates the permissions reports for each user.
    http://techtrainingnotes.blogspot.com/2010/12/sharepoint-powershell-script-to-list.html
    https://sp2010userperm.codeplex.com/
    My Blog- http://www.sharepoint-journey.com|
    If a post answers your question, please click Mark As Answer on that post and Vote as Helpful

  • HT1923 I have a Vista Operating system with 2 users.  Somehow I got two different play lists each with one user.  One is too big for the storage and has a vast amount of duplicates.  Can I delete the one that is twice as large and then access the other li

    I have a Vista operating system with 2 users.  Somehow I got two diffent libraries for the users.  How can I delete the one and then access the correct library on the other users profile?

    Use the trackpad to scroll, thats what it was designed for. The scroll bars automatically disappear when not being used and will appear if you scroll up or down using the trackpad.
    This is a user-to-user forum and most people will post on here if they have problems. You very rarely get people posting to say there update went smooth. The fact is the vast majority of Mountain Lion users will not be experiencing any major problems with the OS, or maybe with apps which are not compatible, but thats hardly Apple's fault if developers don't update their apps.

  • HT1527 I have windows 8.1 and cannot access itunes store even creating a new apple id. With other users on the same computer I can access itunes store. How can I solve this?

    I have windows 8.1 and cannot access itunes store even creating a new apple id. With other users on the same computer I can access itunes store. How can I solve this?

    i had the same problem before using a fresh install of Windows 8.1.  I have resolved this issue by running the program compatibility wizard.  This I did by right-clicking on the iTunes icon in the desktop, selecting Troubleshoot compatibility, waited for it to detect compatibility issues and when presented with the following options: 1.) Try recommended settings; 2.) Troubleshoot program, I chose the latter.  When asked what problems I noticed, I checked the following: "The program worked in earlier versions of Windows but won't install or run" and "The program requires additional permission"
    After that, it tired to resolve the issue, and provided the necessary settings to run iTunes.  Now it's running flawlessly.  I have Avast anti-virus installed though.
    HTH!

  • Grey startup screen on my profile, but I can access guest profile and my hardrive partition to windows?!?! I had a kernal panic after it was knocked off coffee table in my user account, now I cannot access it from safe mode or anything... :(

    My laptop fell off the coffee table, and slammed shut. It then produced a kernal Panic to restart, which I did. It the brings up the user icons, mine and guest, but will not go past the grey screen with spinner on mine. It does let me into the basic safari setting I had on the guest user, AND when i press option on start up, will let me access the windows partition I have set up and all works fine.
    I have tried safe mode, safe mode with display screen and the NVRAM/PRAM restarts, and nothing!
    I have let the battery run completely, restarted, filled up the battery before starting.... everything.... anybody have any ideas? else I am going to have to visit a genius! grrrrrrr....
    Thanks in advance!
    Vix

    Dreamyqueeny wrote:
    My laptop fell off the coffee table, and slammed shut. I
    anybody have any ideas? else I am going to have to visit a genius! grrrrrrr....
    Thanks in advance!
    Vix
    Looks like that is what you are going to end up doing.  No telling what was damaged internally.

  • I want to uninstall and then reinstall Firefox but I can't uninstall it. Nothing happens when I click remove in program access and defaults and the helper.exe file in the firefox uninstall dir doesn't do anything either.

    I want to uninstall and then reinstall Firefox but I can't uninstall it. Nothing happens when I click remove in program access and defaults and the helper.exe file in the firefox uninstall dir doesn't do anything either.

    "program access and defaults" is not the place to remove programs in Windows. You need to go to the control panel and click on Add and Remove programs. For instructions on how to uninstall Firefox, see [[Uninstalling Firefox]]

  • File structure access and default settings issues

    Hello there,
    I have a MBP running 10.6.6
    I noticed that, in the get info window for all my folders and files on the mac, at the bottom it has three users: me, staff, and everyone. And by default it seems to grant all users read rights.
    I have only two users set up on my mac, me and my daughter. My mac does connect to my business network but i have never set up a "staff" user.
    I would like all of my files, anything I create or import or otherwise manage while logged in as me to be viewable only by me.
    Is there a way to set this as a default?
    thank you in advance
    Marc

    Posix permissions have three entities that permissions are granted for, owner, group, and others.
    On those three entities, you can have read, write, and execute permissions. The Mac OS X GUI calls others everyone. Take a look at [this article|http://support.apple.com/kb/ht2963]
    Staff is the default group a user is placed into.
    Others can read your home folder so that they can read the Sites folder and the Public folder. All the other folders should only have read privileges for the owner (you). When you create a file/folder, it inherits the permissions of the enclosing folder. So, if you create a new folder inside your home folder, it will automatically have read permissions for others. If you create a folder inside one of the default folders in home, it will only be readable by you.
    You can change the permissions on those folders you create right inside the home folder so that others cannot read them.

  • Search script generator for all objects and data (!) from a user/schema ?

    Is there a way to create a script which (when run) creates all the existing
    TABLES; INDEXES, KEYS and DATA for a specified user/schema ?
    This (PL-)SQL script should contain all INSERTS for the currently existing rows of
    all the TABLEs.
    When I use e.g. export to Dumpfile I have at first find all TABLEs and components
    which I want to dump. This is rather uncomfortable.
    I just want to specify the user name similar to
    createscript user=karl@XE outfile=D:\mydata\myscript.sql
    Is this somehow possible ?

    So that I understand your requirements exactly, are you asking for your script to ...
    1/ export from database A the entire schema of a specified user
    2/ drop all objects owned by that user in database B
    3/ import the objects from database A into database B
    If so, it sounds to me that a shell script that does a schema level export as Nicholas suggested, and then drops the user from database B using the cascade keyword (e.g. drop user username cascade), recreates the user and then imports the export file into B should do the trick.
    I don't think searching for individual tables and creating the statements to recreate them is the best idea.
    Hope that helps
    Graham

Maybe you are looking for