Granting authorities on a specific object
A user must have the correct authorities to perform operations on objects; for example, to browse the messages on a queue.
About this task
To grant a user or group of users authority to perform operations on a specific object, complete the following steps.
Procedure
- In the Content view, right-click the object, then click Object Authorities > Manage Authority Records. The Manage Authority Records dialog opens.
- Expand the Specific Profiles folder. Only one profile is displayed because only one specific profile can match one object. If you open the Manage Authority Records dialog from a folder in the Navigator view, a specific profile for each of the objects in the folder is displayed in the Specific Profiles folder.
- Click the profile that is displayed in the Specific Profiles folder. The authority records that have been granted on the object are displayed.
- Windows queue managers only: if we are granting the authority to an individual user, click the Users tab.
- Click New... The Add Authorities dialog opens.
- Enter the name of the group or user, as appropriate.
- Select the check boxes for the authorities that we want to grant on the object, then click OK.
Results
An authority record for the user or group is added to the table and the authorities that you granted are shown in the authority record.
If the user or group already has some authorities for the object, select the existing authority record and edit it. If you add a new authority record for a user or group that already has an authority record on the object, we are prompted to confirm that we want to overwrite the existing authority record.
Parent topic: Manage object authorities with an authorization service
Related concepts
- Generic and specific profiles
- Users and groups (entities) in the authorization service
- Authorities we can set on IBM MQ objects
Related tasks