17.20 - Characteristics of Directory Users Mapped to EXTUSER - Analytics Database - Teradata Vantage

Teradata Vantage™ - Analytics Database Security Administration - 17.20

Deployment
VantageCloud
VantageCore
Edition
Enterprise
IntelliFlex
VMware
Product
Analytics Database
Teradata Vantage
Release Number
17.20
Published
June 2022
Language
English (United States)
Last Update
2023-03-07
dita:mapPath
hjo1628096075471.ditamap
dita:ditavalPath
qkf1628213546010.ditaval
dita:id
zuy1472246340572
Teradata Vantage automatically generates the default user EXTUSER. You can map directory users to EXTUSER to provide limited database access in the same way that PUBLIC provides limited access to permanent database users.
  • EXTUSER has privileges similar to PUBLIC by default.

    For information on PUBLIC privileges, see Default PUBLIC Privileges.

  • Mapping a directory user to any Vantage object also gives the user EXTUSER privileges.
  • EXTUSER has no PERM space, default database, default role, or profile.
  • EXTUSER has the same default spool and temp space allocations as user DBC. The allocations apply collectively to all users mapped to EXTUSER. You can create profiles that set lower spool and temp limits and map them to directory users mapped to EXTUSER.
  • Although the system creates an entry for EXTUSER in DBC.Dbase, it is not a valid user or database, and you cannot reference it in a logon string or SQL statement.
  • A user mapped only to EXTUSER can set the default database using a SET SESSION DATABASE statement.
  • You cannot configure workload management rules for users mapped only to EXTUSER.
  • If a directory user is mapped to EXTUSER or there is a role or profile mapping for a directory user, the directory user is logged on to the database as EXTUSER. If the DBSControl AutoProvision parameter is enabled, a database account is automatically provisioned for the user and they are logged on to the database as that user.