Expand my Community achievements bar.

How to implement Attribute Based Access Control when you already have standard Data Governance Labels implemented

Avatar

Level 3

Hi,

 

Can someone provide details on implementing attribute based access control for restricting PII schema attributes when we have other Data Governance labels already implemented (e.g. I1, I2, S2, C2, C3 etc.) on other schema attributes?

 

We recently implemented Attribute based access control based on documentation on Experience league but after enabling the "Default-Label-Based-Access-Control-Policy" everything goes hay wired as this policy also impacted other attributes where we have set Data Governance attributes like I1, I2, S2, C2, C3 etc.

 

Thanks.

Prateek

2 Replies

Avatar

Level 6

@Prateek-Garg can you describe what was the issue you faced after apply and enabling ABAC?

 

Attribute based access control requires additional setup with proper roles and labels assigned to the roles. We are using ABAC with other labels without any problem. Do a thorough check if the labels and roles are properly assigned and they don't conflict and give unexpected access.

Avatar

Administrator

Hi @Prateek-Garg,

Were you able to resolve this query with the given solution or was this something you were able to figure out on your own or do you still need help here? Do let us know.

Thanks!



Sukrity Wadhwa