Symptom
Users that authenticate with a 3rd party login (ie: Trusted, SAML authentication, etc) inherit privileges from the "3rd Party Users" group even when the users are not a part of the 3rd Party Users group.
Steps to Reproduce
Cause
This is working as designed in Strategy Web. Any successful 3rd party login, except LDAP login, will have "3rd Party users" group in the User Runtime for the login session whether there is an MSTR user that links to that 3rd party user or not.
Action
To accommodate for this behavior in the best interest of your environment and your users, amend and restrict the privileges on the '3rd Party Users' group so that your users are not inheriting any unexpected or unintentional privileges from that group.
THIRD PARTY SOFTWARE INSTALLATION WARNING:
The third-party product(s) discussed in this technical note is manufactured by vendors independent of Strategy. Strategy makes no warranty, express, implied or otherwise, regarding this product, including its performance or reliability.
KB442542