Removing a Role Administrator from a Standalone Role

Remove a role administrator from an existing user-extended role.

Database Version Role Administrator Privileges
SAP Sybase IQ 15.3 and 15.4 Not supported.
SAP Sybase IQ 16.0 Requires one of:
  • Administrative rights over the role being managed.
  • MANAGE ROLES system privilege if the role being granted has a global role administrator.

By default, at least one role administrator or global role administrator with a login password must exist at all times for each role. This minimum requirement is validated before you can remove the global role administrator or role administrator from a role, or remove a role administrator's administrative rights on a role. The minimum requirement is a configurable database option (MIN_ROLE_ADMINS).

If revoking membership in a role would result in a failure to meet the minimum number of role administrators for the selected role, an error message appears, and the removal fails.

  1. In the Perspective Resources view, select the resource and select Resource > Administration Console.
  2. In the left pane, select IQ Servers > Security > Role-Based > Standalone Roles.
  3. Select a role from the right pane and do one of:
    • Click the arrow to the right of the name and select Manage Grantees, or
    • From the Administration Console menu bar, select Resource > Manage Grantees.
      Warning!  When adding a grantee which is also a role, be sure you select the correct menu option. Each option has different inheritance outcomes. To review the differences, see Security Implications of the Managing Grantees and Managing Roles Options.
    A list of users or roles currently granted to the role appears. Any user or role with Administrative only or Administrative and role in the Grant Option column is a role administrator.
  4. Select an administrator to be removed.
  5. Click Revoke.
    Note: The Revoke button is unavailable if you do not have administrative rights to the selected role.
  6. Click OK.
Related tasks
Adding a Role Administrator to an Existing Standalone Role
Modifying a Standalone Role Administrator's Administrative Rights
Authenticating a Login Account for a Managed Resource