Assigning Profiles to Users | Teradata Vantage - Assigning Profiles to Users - Analytics Database - Teradata Vantage

Security Administration

Deployment
VantageCloud
VantageCore
Edition
Enterprise
IntelliFlex
VMware
Product
Analytics Database
Teradata Vantage
Release Number
17.20
Published
June 2022
Language
English (United States)
Last Update
2023-11-02
dita:mapPath
hjo1628096075471.ditamap
dita:ditavalPath
qkf1628213546010.ditaval
dita:id
zuy1472246340572
lifecycle
latest
Product Category
Teradata Vantage™

The user categories shown in the following table require differing strategies for assigning profiles.

For a description of each database user type, see the table in Database User Types.
Database User Type Profile Assignment Method
Permanent database users Specify the profile name in the CREATE USER or MODIFY USER statement for the user.
Directory users Assign profiles to directory users in one of the following ways:
  • Map the directory user to one or more profile objects. For directory users mapped to more than one profile, the user must set the profile using profile=profile_name in the .logdata portion of the logon string.

    For information on mapping directory users to database profiles, see Mapping Directory Users to Vantage Profiles.

  • Map the directory user object to a Vantage user to provide the following profile assignment options:
    • The directory user inherits the profile assigned to the database user.
    • If the database user does not have an assigned profile, the directory user inherits the default parameter values for the database user. See Default Values for the CREATE PROFILE Statement.
    • For directory users mapped to a Vantage profile and a database user, the mapped profile takes precedent by default.

    For information mapping directory users to database users, see Mapping Directory Users to Database Users.

Application logon users or trusted users Specify the profile name in the CREATE or MODIFY USER statement for the user name under which the application logs on to the database. The application user profile applies to all users that log on through the application.
Proxy users Proxy users who are also permanent database users, and for whom queries are sent to the database through a trusted user application, are subject to any row level security constraints that appear in the profile assigned to the corresponding permanent user.

All other profile-based privileges are taken from the profile assigned to the trusted user application.

For information on options for end users logging on through middle-tier applications, see Working with Middle-Tier Application Users.

For information on row level security constraints, see Implementing Row Level Security.

For information about the types of users that exist when you use secure zones, see Implementing Teradata Secure Zones.