<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: How to grant user access to create tag based policies in ranger? in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/How-to-grant-user-access-to-create-tag-based-policies-in/m-p/338585#M232862</link>
    <description>&lt;P&gt;Granting data steward role has fixed the issue. May be it was just a sync issue. However our requirement is to grant access to only tag based policies and not on resource based policies.&lt;/P&gt;</description>
    <pubDate>Mon, 14 Mar 2022 15:43:06 GMT</pubDate>
    <dc:creator>RajeshReddy</dc:creator>
    <dc:date>2022-03-14T15:43:06Z</dc:date>
    <item>
      <title>How to grant user access to create tag based policies in ranger?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/How-to-grant-user-access-to-create-tag-based-policies-in/m-p/338373#M232812</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to grant a set of users access to add tag based policies in ranger. I have adde the users to data steward role which grants ranger/atlas admin access but still they get a access denied when create a tag based access policy. Creating resource based policies is working for them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ideally we want to grant them permissions to add tag based policies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We use CDP public cloud 7.2.12 in AWS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any pointers are welcome. Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2022 16:48:25 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/How-to-grant-user-access-to-create-tag-based-policies-in/m-p/338373#M232812</guid>
      <dc:creator>RajeshReddy</dc:creator>
      <dc:date>2022-03-10T16:48:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to grant user access to create tag based policies in ranger?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/How-to-grant-user-access-to-create-tag-based-policies-in/m-p/338427#M232824</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/93738"&gt;@RajeshReddy&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;DataSteward role would usually grant “environments/adminRanger” permission which makes user Ranger and Atlas admin. This would suffice to create a tag based policy. Can we get more info on the error you are getting? Any screenshot or error messages would help us greatly to help you further.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 07:08:53 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/How-to-grant-user-access-to-create-tag-based-policies-in/m-p/338427#M232824</guid>
      <dc:creator>VR46</dc:creator>
      <dc:date>2022-03-11T07:08:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to grant user access to create tag based policies in ranger?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/How-to-grant-user-access-to-create-tag-based-policies-in/m-p/338441#M232826</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/33327"&gt;@VR46&lt;/a&gt;&amp;nbsp;Below is the error. The requirement is to grant the user access to only create tag based policies and deny creating resource based policies. But the result is opposite right now. Cant see any exception in ranger logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ranger-tag.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/33933iD7F6D8192AF6D3C2/image-size/large?v=v2&amp;amp;px=999" role="button" title="ranger-tag.PNG" alt="ranger-tag.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 09:03:28 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/How-to-grant-user-access-to-create-tag-based-policies-in/m-p/338441#M232826</guid>
      <dc:creator>RajeshReddy</dc:creator>
      <dc:date>2022-03-11T09:03:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to grant user access to create tag based policies in ranger?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/How-to-grant-user-access-to-create-tag-based-policies-in/m-p/338538#M232840</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/93738"&gt;@RajeshReddy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please give a try with changing the role to "environment admin"?&lt;/P&gt;</description>
      <pubDate>Sun, 13 Mar 2022 08:50:56 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/How-to-grant-user-access-to-create-tag-based-policies-in/m-p/338538#M232840</guid>
      <dc:creator>Azhar_Shaikh</dc:creator>
      <dc:date>2022-03-13T08:50:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to grant user access to create tag based policies in ranger?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/How-to-grant-user-access-to-create-tag-based-policies-in/m-p/338584#M232861</link>
      <description>&lt;P&gt;This is not what we want to do.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Mar 2022 15:42:04 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/How-to-grant-user-access-to-create-tag-based-policies-in/m-p/338584#M232861</guid>
      <dc:creator>RajeshReddy</dc:creator>
      <dc:date>2022-03-14T15:42:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to grant user access to create tag based policies in ranger?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/How-to-grant-user-access-to-create-tag-based-policies-in/m-p/338585#M232862</link>
      <description>&lt;P&gt;Granting data steward role has fixed the issue. May be it was just a sync issue. However our requirement is to grant access to only tag based policies and not on resource based policies.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Mar 2022 15:43:06 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/How-to-grant-user-access-to-create-tag-based-policies-in/m-p/338585#M232862</guid>
      <dc:creator>RajeshReddy</dc:creator>
      <dc:date>2022-03-14T15:43:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to grant user access to create tag based policies in ranger?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/How-to-grant-user-access-to-create-tag-based-policies-in/m-p/338589#M232864</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/93738"&gt;@RajeshReddy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for tag based policies you can refer to&amp;nbsp;&lt;A href="https://docs.cloudera.com/runtime/7.2.10/security-ranger-authorization/topics/security-ranger-tag-based-policies.html" target="_blank"&gt;https://docs.cloudera.com/runtime/7.2.10/security-ranger-authorization/topics/security-ranger-tag-based-policies.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Was your question answered? Make sure to mark the answer as the accepted solution.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;If you find a reply useful, say thanks by clicking on the thumbs up button.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Mar 2022 15:49:11 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/How-to-grant-user-access-to-create-tag-based-policies-in/m-p/338589#M232864</guid>
      <dc:creator>Azhar_Shaikh</dc:creator>
      <dc:date>2022-03-14T15:49:11Z</dc:date>
    </item>
  </channel>
</rss>

