The SYSTEM user is a
privileged account which means that it carries more privileges than
an administrator account. There is nothing on SAS Federation Server
that the system account cannot do because the account has implicit
privileges to all user and data objects. The operating system process
that invokes and runs SAS Federation Server is automatically
a system user. By default, the account used to install SAS Federation Server
is registered as a system user account. Other user accounts can also
be registered as system users in the
dfs_serv_common.xml configuration
file.
The system user should
identify users who will be administrators of SAS Federation Server,
and make them administrators by granting them the ADMINISTER privilege
on the server object. Like SYSTEM users, administrators are unconditionally
and implicitly granted all privileges on SAS Federation Server.
However, if these users are revoked their ADMINISTER privilege, then
they become standard users that have privileges granted to and denied
from them. A SYSTEM user can never be denied privileges.
If a Data Source Name
(DSN) is created by either the system user or an administrator, the
DSN is created using the AS ADMINISTRATOR clause, which means that
the ADMINISTRATOR role owns the DSN, not the individual creating it.
Therefore, if the administrator user is later removed from the system,
the DSN will not be deleted with the user.
Use the system user
account to define one or more administrators for SAS Federation Server.
As a best practice, all configuration and administration should
be performed by the administrator.