<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does Scope Based Access Control (OV 4.0) really restrict resource visibility? in HPE OneView</title>
    <link>https://community.hpe.com/t5/hpe-oneview/does-scope-based-access-control-ov-4-0-really-restrict-resource/m-p/6995445#M2477</link>
    <description>SBAC is used for delegation of administration, not for multi-tenancy. The All Resources In Scope is a way to mimic the behavior of multi-tenancy. But as you saw, it doesn't stop anyone from changing it to All Resources. And doing that does NOT mean one has Use rights. This is called out in the User Guide.</description>
    <pubDate>Tue, 30 Jan 2018 23:37:34 GMT</pubDate>
    <dc:creator>ChrisLynch</dc:creator>
    <dc:date>2018-01-30T23:37:34Z</dc:date>
    <item>
      <title>Does Scope Based Access Control (OV 4.0) really restrict resource visibility?</title>
      <link>https://community.hpe.com/t5/hpe-oneview/does-scope-based-access-control-ov-4-0-really-restrict-resource/m-p/6995247#M2475</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;I am testing SCBA functionality on a successfully-upgraded OneView 4.0 system.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Page 78 of &lt;A title="HPE OneView 4.0 User Guide" href="https://support.hpe.com/hpsc/doc/public/display?docId=a00037746en_us" target="_blank"&gt;HPE OneView 4.0 User Guide&lt;/A&gt; states:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;When scopes are defined and resources assigned to them, you can:&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;• Restrict the resources displayed in the user interface (UI) to those assigned to the scope.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think that&amp;nbsp;sentence is not completely true. When the user logs in, the displayed information is filtered by "All resources in scope". However, the user is able to change the filter to "All resources", gaining visibility of them. Of course, the user cannot operate/manage them, but there is no restriction to display resources not assigned to the scope.&lt;/P&gt;&lt;P&gt;Is this the expected behaviour? Am I missing anything in SBAC configuration?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2018 09:58:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/does-scope-based-access-control-ov-4-0-really-restrict-resource/m-p/6995247#M2475</guid>
      <dc:creator>Marcos Olmos</dc:creator>
      <dc:date>2018-01-30T09:58:06Z</dc:date>
    </item>
    <item>
      <title>Re: Does Scope Based Access Control (OV 4.0) really restrict resource visibility?</title>
      <link>https://community.hpe.com/t5/hpe-oneview/does-scope-based-access-control-ov-4-0-really-restrict-resource/m-p/6995333#M2476</link>
      <description>&lt;P&gt;This&amp;nbsp;looks to be more of an individual&amp;nbsp;perception on interpreting what is written in the user guide.&lt;/P&gt;&lt;P&gt;What is seen is&amp;nbsp;as per design only unless it has any functional impacts on the environment.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2018 15:35:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/does-scope-based-access-control-ov-4-0-really-restrict-resource/m-p/6995333#M2476</guid>
      <dc:creator>RR33</dc:creator>
      <dc:date>2018-01-30T15:35:39Z</dc:date>
    </item>
    <item>
      <title>Re: Does Scope Based Access Control (OV 4.0) really restrict resource visibility?</title>
      <link>https://community.hpe.com/t5/hpe-oneview/does-scope-based-access-control-ov-4-0-really-restrict-resource/m-p/6995445#M2477</link>
      <description>SBAC is used for delegation of administration, not for multi-tenancy. The All Resources In Scope is a way to mimic the behavior of multi-tenancy. But as you saw, it doesn't stop anyone from changing it to All Resources. And doing that does NOT mean one has Use rights. This is called out in the User Guide.</description>
      <pubDate>Tue, 30 Jan 2018 23:37:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/does-scope-based-access-control-ov-4-0-really-restrict-resource/m-p/6995445#M2477</guid>
      <dc:creator>ChrisLynch</dc:creator>
      <dc:date>2018-01-30T23:37:34Z</dc:date>
    </item>
  </channel>
</rss>

