EducationSoftwareStrategy.com
StrategyCommunity

Knowledge Base

Product

Community

Knowledge Base

TopicsBrowse ArticlesDeveloper Zone

Product

Download SoftwareProduct DocumentationSecurity Hub

Education

Tutorial VideosSolution GalleryEducation courses

Community

GuidelinesGrandmastersEvents
x_social-icon_white.svglinkedin_social-icon_white.svg
Strategy logoCommunity

© Strategy Inc. All Rights Reserved.

LegalTerms of UsePrivacy Policy
  1. Home
  2. Topics

KB442542: Users that are Authenticated with SSO Authentication inherit privileges from 3rd Party Users group when not part of the group


Darren Burns

Senior Cloud Support Engineer III • MicroStrategy


This knowledge base article describes a behavior for users that authenticate via 3rd party login where they will always inherit privileges from the “3rd Party Users” user group in MicroStrategy even if that users are not visibly a part of that group.

Symptom
Users that authenticate with a 3rd party login (ie: Trusted, SAML authentication, etc) inherit privileges from the "3rd Party Users" group even when the users are not a part of the 3rd Party Users group.
 
Steps to Reproduce

  1. Configure Trusted Authentication or SAML Authentication for Strategy Web
  2. Create a Strategy User
  3. Edit the user and remove all Privileges at the user level (Edit User > Project Access > Uncheck all Privileges)
  4. Remove the user from all groups (Edit User > Groups > Uncheck all groups)
  5. Remove all the Privileges for the "3rd Party Users" group
  6. Login to Strategy Web via Trusted Authentication
  7. Note that user will not see any projects
  8. Logout
  9. Add Privileges to the "3rd Party Users" group
  10. Login to Strategy Web via Trusted Authentication
  11. Note that user has inherited privileges from "3rd Party Users" group


 
Cause
This is working as designed in Strategy Web. Any successful 3rd party login, except LDAP login, will have "3rd Party users" group in the User Runtime for the login session whether there is an MSTR user that links to that 3rd party user or not.
 
Action
To accommodate for this behavior in the best interest of your environment and your users, amend and restrict the privileges on the '3rd Party Users' group so that your users are not inheriting any unexpected or unintentional privileges from that group.
 
THIRD PARTY SOFTWARE INSTALLATION WARNING:
The third-party product(s) discussed in this technical note is manufactured by vendors independent of Strategy. Strategy makes no warranty, express, implied or otherwise, regarding this product, including its performance or reliability.
 
  KB442542


Comment

0 comments

Details

Knowledge Article

Published:

December 31, 2018

Last Updated:

March 17, 2022