<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Ranger policy for group not working...Checked all previous but no clue in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-for-group-not-working-Checked-all-previous-but/m-p/185508#M147615</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Verified various links but could not come up with solution.&lt;/P&gt;&lt;P&gt;Ranger policy is not applied to a user when policy has user group name but is successful when applied to user directly.&lt;/P&gt;&lt;P&gt;Here is the information:&lt;/P&gt;&lt;P&gt;a) HDP - 2.6.5; Ranger - 0.7.0; CentOS 6.5; Windows 2012 R2 is used as AD ( has full admin privileges on AD )&lt;/P&gt;&lt;P&gt;b) Settings:&lt;/P&gt;&lt;P&gt;Incremental Sync - Enabled&lt;/P&gt;&lt;P&gt;Username Attribute - sAMAccountName; User Object Class: user; User Search Filter: cn=*; user search scop: sub; User Group Name Attribute - memberOf,ismemberof; Group User Map Sync - False or disabled.&lt;/P&gt;&lt;P&gt;Enable Group Sync - Enabled; Group Member Attribute - member; Group Name Attribute - sAMAccountName; Group Object Class - group;Group Search Filter - CN=*; Enable Group Search First - False or disabled.&lt;/P&gt;&lt;P&gt;c) On OS side:&lt;/P&gt;&lt;P&gt;hdfs groups &amp;lt;username&amp;gt; gives the group name of the user and the same user name ( with exact case ) is present in Ranger Groups &lt;/P&gt;&lt;P&gt;Still the user is not able to access hive databases in spite of policy allowing members of group to which the user belongs to.&lt;/P&gt;&lt;P&gt;Can someone please help me on this.&lt;/P&gt;&lt;P&gt; &lt;A rel="user" href="https://community.cloudera.com/users/537/spolavarapu.html" nodeid="537"&gt;@spolavarapu&lt;/A&gt; &lt;A rel="user" href="https://community.cloudera.com/users/11048/falbani.html" nodeid="11048"&gt;@Felix Albani&lt;/A&gt; or anyone can help me on this.&lt;/P&gt;</description>
    <pubDate>Fri, 07 Sep 2018 07:04:29 GMT</pubDate>
    <dc:creator>sriramhadoop27</dc:creator>
    <dc:date>2018-09-07T07:04:29Z</dc:date>
  </channel>
</rss>

