(2 OM) 10. Security Structure Flashcards
When deleting a user from Adaptive Planning, what items associated with that user also get deleted?
- Personal reports.
- Personal perspectives, dashboards, or charts shared with other users (versus those created in the company folder).
- The audit trail associated with that user.
- Cell and sheet notes created by the user.
- Any shared reports that the user created.
- Personal reports.
- Personal perspectives, dashboards, or charts shared with other users (versus those created in the company folder).
(The other 3 items remain).
Owned Levels do allow the user to view or edit data for the owned level. True or false?
False (You must grant access using Access Rules.)
What are some privileges related to owned levels?
- View and edit data at that owned level.
- Manage owned levels through Model Management > Levels.
- Approve levels in Workflow.
- Assign level ownership to other users.
- View and create journal entries on owned levels.
- Review intercompany elimination debits and credits for owned levels.
- Receive shared-by-level reports in the Shared Reports folder.
- Manage owned levels through Model Management > Levels.
- Approve levels in Workflow.
- Assign level ownership to other users.
- View and create journal entries on owned levels.
- Review intercompany elimination debits and credits for owned levels.
- Receive shared-by-level reports in the Shared Reports folder.
What are some use cases for Global User Groups?
- Grant specific Version access.
- Assign access rules to a group of users.
- Grant specific Time access.
- Assign Tasks.
- Share Perspectives.
- Share web reports and email reports to a group of users.
- Grant specific Version access
- Assign access rules.
- Assign Tasks.
- Share Perspectives.
- Share web reports and email reports to a group of users.
If you try to delete a user group that is assigned to a process task, Workday Adaptive Planning will alert you. True or false?
True
Access rules define specific intersections of ___ that users or groups can ___ or ___.
Data, edit, view
Some dimensions may not be available for selection from the Access Rules page. Why is this?
- The dimension has no values.
- You can only secure 3 custom dimensions max in access rules.
- The dimension has more than 10,000 values.
- The dimension settings “Use on Levels” and “Data import automatically creates dimension values” are turned on.
- The “Edit dimension on sheet” option is turned on.
- The dimension is a flat list dimension.
- You can only secure 3 custom dimensions max in access rules.
- The dimension has more than 10,000 values.
- The dimension settings “Use on Levels” and “Data import automatically creates dimension values” are turned on.
- The “Edit dimension on sheet” option is turned on.
What symbol is used to grant access to owned levels?
- (~)
- (+)
- +
- (+~)
- (~)
In addition to granting access to Levels in access rules, you can also grant access to ___, ___ and ___.
Accounts, dimensions, attributes
Owned levels are the same as access rules, but allow for certain extra privileges. True or false?
False (owned levels are different and separate to access rules).
Which areas in Adaptive Planning can you review a user’s Owned Levels?
- The User profile.
- The Associations page, under “View Details.”
- The Access Rules page.
- The Permissions Sets page.
- The User profile.
- The Associations page, under “View Details.”
In the case of multiple rules that conflict, each column defaults to the most ___ rule.
Permissive
What settings can expose data, regardless of the access rules set for that user/group?
- User-assigned sheets.
- Workflow approver role.
- Data privacy settings (turning on “Value of account is public at all levels” for an Account).
- User-assigned sheets.
- Data privacy settings (turning on “Value of account is public at all levels” for an Account).
Access rules secure data by working with other parts of the model including…
- Permission sets
- Owned Levels.
- Version Access Control (e.g. Hidden or Locked versions.)
- Model Integration role.
- Salary detail setting.
- Sheet settings.
- Cube sheet restrictions.
- Standard sheet restrictions.
- Permission sets
- Owned Levels.
- Version Access Control (e.g. Hidden or Locked versions.)
- Salary detail setting.
- Sheet settings.
- Cube sheet restrictions.
Associations allow administrators to create groups of ___ and dimension values for individual users. When you create an ___ ___, you can specify the association code instead of detailing individual dimension values.
Dimensions, access, rule
Access Rules best practice - Consider creating rules for Global User Groups if you have many users or add new users often. True or false?
True
Access Rules best practice - Be cautious when adding a user to ___ groups since it makes determining access difficult. There is no reporting functionality on groups.
Multiple
Access Rules best practice - Use ___ to create dimension value access to users, which you can use when creating access rules.
Associations
Access Rules template best practice - The only way to give access to an (Only) level is to give access to the parent and all descendants. True or false?
True
You can use other rules to remove access to descendants once you’ve granted access to parents. True or false?
False
To display any rollup value on a sheet, report, or chart, you need access to all descendants of all rollup. True or false?
True
The “User Access Calculator” allows administrators to view a user’s access control at a specific intersection. To check an intersection, you must specify a ___, a ___, an ___, and a ___.
User, Level, Account, Version.
What does SAML SSO (single sign on) stand for?
- System Access Markup Language.
- Security Assertion Markup Language.
- Security Access Matrices Lookup.
- Security Assertion Markup Language.
What are some examples of providers that work with SAML SSO?
- Microsoft Azure Active Directory.
- Okta.
- Sidecar.
- NetSuite.
- PingOne.
- Microsoft Azure Active Directory.
- Okta.
- PingOne.
You can only enable SAML SSO for users manually, one by one. True or false?
False (manually or by bulk import).