Welcome to MSDN Blogs Sign in | Join | Help

Shared Service Providers (SSPs) What Are They... How to's On Delegation

Shared Services (SSPs) are great.  What are these services?  Search/indexing, my site hosting, profiles (company directory), Audiences (for Targeting content), Portal Usage Reporting (enhanced Usage reports), Excel Services, Business Data Catalog Configuration. 

If you didn't know about them or use them in SPS 2003, it doesn't matter.  By default we've made it easier for you to do the right thing.  Out of the box, the SSP will be easy to create and configure and be managed by either the IT Staff or a group with expertise in areas that you may want to delegate.  Examples include Search and Index management, or maybe your company people (profiles) directory  is currently managed by an HR technical team.  With the SSP being a separate site or web application (IIS Virtual Servers) from central admin and your content, you can configure permissions on your SSP administration.  The next piece to understand is consolidation, you can manage a single set of shared services for your farm, or even multiple farms.  What this means is you can configure your search and indexing once and consume these from multiple web applications unrestricted by server topology. This service oriented architecture makes your life easier by managing these set of services in one place.  You don't have to give someone the keys to the farm (Terminal Services or otherwise)  to manage these services.

Here's a quick set of facts around SSPs (Shared Service Providers)

  • An SSP by default is a separate web app from the other web apps extended with SharePoint Technology
  •  An SSP can be consolidated with the a SharePoint Tech content web application
  • SSPs are for managing a set of service oriented architectures including, search/indexing, my site hosting, profiles (company directory), Audiences (for Targeting content), Portal Usage Reporting (enhanced Usage reports), Excel Services, Business Data Catalog Configuration
  • SSPs can be run on Port 80 or the high ports
  • SSP administration is available with Office SharePoint Server or Project Server
  • SSP administration is not available with WSS
  • The SSP administration interface is a Site
  • You have to have at least 1 SSP (You actually can create sites, but many features won't work (like Excel published spreadsheets) until the SSP is created and configured)
  • Consolidating SSPs allows you to scale to host more web applications
  • Multi-tenet or isolated departments can have different SSPs (Great for Hosted)
  • You can have an SSP on each content web application (similar to default in SPS 2003)
  • When you create the SSP you automatically have a content source that indexes all sites within the farm

Delegation Scenarios:

Add Users or Groups with Read Permissions to the SSP Admin Site Collection then add rights based on the rights you want to give them.  Site Actions, Site Settings, People and Groups, New Users/Group

You want to delegate Administration of Search/Index Management and Excel:

Grant contributor rights on the SSP Admin site.  (Site Actions, Site Settings, People and Groups, New Users/Group)  This will give them Search, Audiences, User Profiles and My Sites and Excel.  This will not grant them rights to BDC.

Any SSP Contributor can manage Search & Excel; but specific rights have to granted to manage people or BDC.

You want to delegate People Management - Profile Import, My Site, Audience Management **
Grant rights via a special personalization services permissions link from the SSP Admin UI. Specific rights can be granted to different components.  http://server:port/ssp/admin/_layouts/ManageServicePermissions.aspx

Permission Levels: Create Personal Site, Use Personal Features, Manage User Profiles, Manage Audiences, Manage Permissions, Manage Usage Analytics.


You want to delegate permissions to BDC - Business Data catalog
You can grant permissions by going to the SSP administration page and clicking BDC permissions in the Business Data Catalog section

Permission Levels: View, Edit-Import application definitions, Manage Permissions, Selectable in Clients, Copy selected permissions to applications

Summary 

In summary, if you want to give certain business units rights to manage your services you can easily do so by giving them rights to administer the SSP site then give them explicit permissions to administer the BDC.  You can accomplish this without having to give them any rights to the central admin web application/console.

For example at Microsoft the Search Service Owner who manages the content sources and indexing does not and should not have other rights to the content on the MSWeb Portal, and as well rights to the central admin or server admin.  They can't TS to the box, but they can manage the index and crawls.

 ** My experience in beta 2 and B2TR shows me that the granularity here doesn't work as expected.  For example, in beta 2 if I have read rights, then add all permissions levels under people, I can access all areas except for BDC and Usage Analytics.  In my tests, when I add a user to manage profiles without adding them to any rights to the site, they get access denied on any pages.  There's a new role of viewer in B2TR and my experience was I could manage everything except BDC as a viewer.  This post is based on my B2TR experience and is subject to change with RTM.

Published Tuesday, October 03, 2006 11:35 PM by joelo
Filed under:

Comment Notification

If you would like to receive an email when updates are made to this post, please register here

Subscribe to this post's comments using RSS

Comments

Thursday, October 19, 2006 4:24 PM by bstoll

# re: Shared Service Providers (SSPs) What Are They... How to's On Delegation

I would like to be able to control which site collections have access to a given content source collection in SP07. I don't want to have to create a seperate SSP for this task because that is an expensive option in terms of memory, etc. Otherwise content that isn't intended for the user will return in results, and even if they don't have access to it, they can still see that it is there and an initial line or two.  Any suggestions how I might go about doing this?

Thursday, November 02, 2006 11:16 AM by Will D. Robinson

# re: Shared Service Providers (SSPs) What Are They... How to's On Delegation

We experienced something similar with BDC permissions in 2TR.  My account is a farm admin and was used to build the farm.  Second account was getting access denied on the bdc pages.  I gave a second account local admin, then farm admin, then ssp site collection admin.  They still could not get to the bdc app import page or the permissions page.  Only my accout could get to the permissions page to add the second account.  This was successful.  It is disturbing that this wasn't working as expected.  What if my account had been disabled or deleted?

Tuesday, November 07, 2006 9:17 AM by KGordon

# re: Shared Service Providers (SSPs) What Are They... How to's On Delegation

What permissions must I have to edit the BDC permissions page -- "You can grant permissions by going to the SSP administration page and clicking BDC permissions in the Business Data Catalog section" -- I am a site collection administrator, but I cannot add applications to the BDC or edit BDC Permissions....

Tuesday, December 12, 2006 9:41 PM by Joel Oleson's SharePoint Land

# Global & Multi Farm Deployments

There have been a bunch of questions lately around Global Deployments. Here are some essential resources

Wednesday, December 13, 2006 2:22 AM by joelo

# re: Shared Service Providers (SSPs) What Are They... How to's On Delegation

KGordon, To change anything on the BDC directly you have to have rights to administer the SSP.  If you ask the Central Admin to add you with rights to the SSP with the BDC then give you explicit permissions on the BDC to manage it, you can then manage the BDC.

Will, one option... you can create explicit policy permissions on the SSP web app to give you rights.  Not sure if this would have worked in your situation, but at least it's one more thing to try.

Wednesday, December 13, 2006 9:12 AM by Jeremy

# re: Shared Service Providers (SSPs) What Are They... How to's On Delegation

I cannot access the SSP. It gives me a 404. And yes I gave myself "Full Read" access to the SSP web app. Any ideas? By all indications the SSP exists and should be available to access. I'm at a loss.

Thursday, December 14, 2006 7:27 AM by The Mit's Blog

# SharePoint 2007 : soucis de déploiement ?

Bien souvent un des freins de gros projets est une peur du déploiement. Si déployer du SQL Server ou

Thursday, December 14, 2006 11:13 AM by ABates

# re: Shared Service Providers (SSPs) What Are They... How to's On Delegation

Above you said ....experience was I could manage everything except BDC as a viewer.  This post is based on my B2TR experience and is subject to change with RTM.

Still experiencing this in RTM, most disturbing is as a viewer I can access Personalization and BDC permissions links and just add the rights I want?

Any thoughts how to correct?

Thursday, December 28, 2006 2:05 PM by Shekhar

# re: Shared Service Providers (SSPs) What Are They... How to's On Delegation

We want to grant "Create Personal Site", "Use Personal Features" permissions through object model to portal users. However we have not been able to identify the classes that we coiuld use to do the same. It would be great if you could point me to any resources available.

Thursday, December 28, 2006 2:05 PM by Shekhar

# re: Shared Service Providers (SSPs) What Are They... How to's On Delegation

We want to grant "Create Personal Site", "Use Personal Features" permissions through object model to portal users. However we have not been able to identify the classes that we coiuld use to do the same. It would be great if you could point me to any resources available.

Sunday, January 14, 2007 3:29 PM by Johnwe's SharePoint WebLog

# A few of my favorite MOSS 2007 Links

Hi all, I will be posting this as an article as well, with a link available from the front page. That

Sunday, January 14, 2007 3:35 PM by Johnwe's SharePoint WebLog

# MOSS 2007 Links

Architecture, Installation, and Migration · Planning and Architecture for MOSS 2007 (large Whitepaper,

Monday, January 15, 2007 11:01 AM by Romeo Pruno

# Links utili per MOSS2007

VIA Johnwe Architecture, Installation, and Migration Planning and Architecture WhitePaper (Fairly...

Tuesday, June 26, 2007 11:15 AM by The Boiler Room - Mark Kruger, Microsoft SharePoint MVP

# 2007 MOSS Resource Links (Microsoft Office SharePoint Server)

2007 MOSS Resource Links (Microsoft Office SharePoint Server) Here is an assortment of various 2007 Microsoft

Tuesday, September 18, 2007 2:07 AM by Richard yanwei

# [转贴]SharePopint常用资源链接

SharePopint常用资源链接

Friday, August 01, 2008 1:20 AM by justguy's

# FBA in SharePoint – Everything you’ve ever wanted to do

Hi, Recently I’ve had an interesting challenge (yes, challenge): building a MOSS portal based on Form

Leave a Comment

(required) 
required 
(required) 
 
Page view tracker