<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Into Visual Studio Team System &#187; Security</title>
	<atom:link href="http://intovsts.net/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://intovsts.net</link>
	<description>blogging about the current and upcoming release(s) of Visual Studio Team System</description>
	<lastBuildDate>Mon, 06 Feb 2012 18:54:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='intovsts.net' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Into Visual Studio Team System &#187; Security</title>
		<link>http://intovsts.net</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://intovsts.net/osd.xml" title="Into Visual Studio Team System" />
	<atom:link rel='hub' href='http://intovsts.net/?pushpress=hub'/>
		<item>
		<title>TFS 2010 Team Project Security Management</title>
		<link>http://intovsts.net/2011/01/26/tfs-2010-team-project-security-management/</link>
		<comments>http://intovsts.net/2011/01/26/tfs-2010-team-project-security-management/#comments</comments>
		<pubDate>Tue, 25 Jan 2011 23:22:45 +0000</pubDate>
		<dc:creator>pietergheysens</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[TFS2010]]></category>

		<guid isPermaLink="false">https://intovsts.wordpress.com/2011/01/26/tfs-2010-team-project-security-management/</guid>
		<description><![CDATA[Setting up security for all Team Projects on all involved TFS Components (TFS, SharePoint and SQL Reporting Services) for all individual users might be quite frustrating and error-prone from time to time. I have seen this type of mismanagement once too many now. About time to publish some basic guidelines on how to manage Team [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=intovsts.net&amp;blog=5586949&amp;post=568&amp;subd=intovsts&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Setting up security for all Team Projects on all involved TFS Components (TFS, SharePoint and SQL Reporting Services) for all individual users might be quite frustrating and error-prone from time to time.</p>
<p>I have seen this type of <em>mismanagement</em> once too many now. About time to publish some basic guidelines on how to manage Team Project security rights and permissions across all involved TFS components.</p>
<p>Download my recommended strategy for getting rid of the familiar red crosses in Team Explorer and manage TFS security wisely.</p>
<p>Download <a href="http://www.sparkles.be/documents/tfs2010teamprojectsecuritymanagement.pdf" target="_blank">TFS2010TeamProjectSecurityManagement.pdf</a>. </p>
<p>Content:</p>
<ul>
<li>New Team Project </li>
<li>Group Membership for Team Project </li>
<li>What about security for SharePoint and SQL Reporting Services </li>
<li>Welcoming the TFS Administration Tool (v2.1) </li>
<li>Make use of Active Directory groups </li>
</ul>
<p>References used in the recommendation:</p>
<ul>
<li><a href="http://msdn.microsoft.com/en-us/library/dd236915(VS.100).aspx" target="_blank">Organizing your Team Foundation Server with Team Project Collections</a> </li>
<li><a href="http://intovsts.net/2009/09/03/more-fine-grained-permissions-in-tfs2010/" target="_blank">Fine-grained permissions in TFS 2010</a> </li>
<li><a href="http://msdn.microsoft.com/en-us/library/dd236915.aspx" target="_blank">Organizing Your Server with Team Project Collections</a> </li>
<li><a href="http://msdn.microsoft.com/en-us/library/ms252587(VS.100).aspx" target="_blank">Team Foundation Server 2010 Permissions</a> </li>
<li><a href="http://tfsadmin.codeplex.com/" target="_blank">Team Foundation Server Administration Tool&#160; v2.1 (Codeplex)</a> </li>
</ul>
<p>A final note to conclude: the explained <em>Team Project</em> permission sets are not the only available permission sets in the Team Project. Read my previous blogpost on <a href="http://intovsts.net/2009/09/03/more-fine-grained-permissions-in-tfs2010/" target="_blank">fine-grained permissions in TFS 2010</a> for more information.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/intovsts.wordpress.com/568/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/intovsts.wordpress.com/568/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/intovsts.wordpress.com/568/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/intovsts.wordpress.com/568/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/intovsts.wordpress.com/568/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/intovsts.wordpress.com/568/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/intovsts.wordpress.com/568/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/intovsts.wordpress.com/568/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/intovsts.wordpress.com/568/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/intovsts.wordpress.com/568/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/intovsts.wordpress.com/568/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/intovsts.wordpress.com/568/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/intovsts.wordpress.com/568/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/intovsts.wordpress.com/568/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=intovsts.net&amp;blog=5586949&amp;post=568&amp;subd=intovsts&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://intovsts.net/2011/01/26/tfs-2010-team-project-security-management/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/518b6f63e450a759ae797ff3b2ad664f?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96" medium="image">
			<media:title type="html">pietergheysens</media:title>
		</media:content>
	</item>
		<item>
		<title>More fine-grained permissions in TFS2010</title>
		<link>http://intovsts.net/2009/09/03/more-fine-grained-permissions-in-tfs2010/</link>
		<comments>http://intovsts.net/2009/09/03/more-fine-grained-permissions-in-tfs2010/#comments</comments>
		<pubDate>Thu, 03 Sep 2009 20:15:11 +0000</pubDate>
		<dc:creator>pietergheysens</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Team Build]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://intovsts.net/?p=260</guid>
		<description><![CDATA[Recently (in TFS2008) I was stuck with the fact that I could not split up the permission to create/modify builds and the permission to create/modify build agents. In certain enterprise environments it might be necessary to revoke the right from development teams to create/modify build agents. Build agents may be for instance controlled centrally by [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=intovsts.net&amp;blog=5586949&amp;post=260&amp;subd=intovsts&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Recently (in TFS2008) I was stuck with the fact that I could not split up the permission to create/modify builds and the permission to create/modify build agents. In certain enterprise environments it might be necessary to revoke the right from development teams to create/modify build agents. Build agents may be for instance controlled centrally by an operations team that manages all build servers. In TFS2008 both <i>tasks</i> belong to the &#8220;Administer a buid&#8221; permission. </p>
<p><img src="http://intovsts.files.wordpress.com/2009/09/tfs2008administerabuild.png?w=450" border="0" /></p>
<p>The good news is that TFS2010 will offer a lot more fine-grained permission sets! You will now have the possibility to set permissions on the <b>Team Project Collection</b>, on the <b>Team Project</b>, on the <b>Build Definition</b> level and on the <b>Version Control</b> repository!</p>
<ul>
<li><font color="Blue">Team Project Collection</font>
<ul>
<li>Administer shelved changes</li>
<li>Administer test controllers</li>
<li>Administer warehouse</li>
<li>Administer workspaces</li>
<li>Alter trace settings</li>
<li>Create a workspace</li>
<li>Create new projects</li>
<li>Delete a team project</li>
<li>Delete team project collection</li>
<li>Edit collection-level information</li>
<li>Make requests on behalf of others</li>
<li><font color="Red">Manage build resources</font></li>
<li>Manage process template</li>
<li>Manage work-item link types</li>
<li>Trigger events</li>
<li>Use build resources</li>
<li>View build resources</li>
<li>View collection-level information</li>
<li>View system synchronization information</li>
</ul>
</li>
<li><font color="Blue">Team Project</font>
<ul>
<li>Administer test environments</li>
<li>Create test runs</li>
<li>Create team project</li>
<li>Delete test runs</li>
<li>Edit project-level information</li>
<li>View project-level information</li>
<li>View test runs</li>
</ul>
</li>
<li><font color="Blue">Build Definition</font>
<ul>
<li>View Builds</li>
<li>Edit build quality</li>
<li>Retain indefinitely</li>
<li>Delete builds</li>
<li>Manage build qualities</li>
<li>Destroy builds</li>
<li>Update build information</li>
<li>Queue builds</li>
<li>Manage build queue</li>
<li>Stop builds</li>
<li>View build definition</li>
<li><font color="Red">Edit build definition</font></li>
<li>Delete build definition</li>
<li>Override check-in validation by build</li>
</ul>
</li>
<li><font color="Blue">Version Control</font>
<ul>
<li>Read</li>
<li>Check Out</li>
<li>Check In</li>
<li>Label</li>
<li>Lock</li>
<li>Revise other users&#8217; changes</li>
<li>Unlock other users&#8217; changes</li>
<li>Undo other users&#8217; changes</li>
<li>Administer labels</li>
<li>Manage permissions</li>
<li>Check-in other users&#8217; changes</li>
<li>Merge</li>
<li>Manage branch</li>
</ul>
</li>
</ul>
<p>Great! There are a few permission that are new and that I certainly want to look into a bit deeper &#8230; but now let&#8217;s go back to my problem in TFS2008 and how to fix it in TFS2010. Right clicking the Team Project Collection brings me to the permissions on the Project Collection level.</p>
<p><img src="http://intovsts.files.wordpress.com/2009/09/tfs2010pcsecurityrightclick1.png?w=450" border="0" /></p>
<p><img src="http://intovsts.files.wordpress.com/2009/09/tfs2010managebuildresources1.png?w=450" border="0" /></p>
<p>The permission to <i>Manage build resources</i> allows people to create and modify build controllers and agents.</p>
<p>Right clicking <i>Builds</i> brings you to the permissions on the build definition level.</p>
<p><img src="http://intovsts.files.wordpress.com/2009/09/tfs2010buildrightclick.png?w=450" border="0" /></p>
<p><img src="http://intovsts.files.wordpress.com/2009/09/tfs2010buildpermissions.png?w=450" border="0" /></p>
<p>The permission to <i>Edit build definition</i> allows people to create and modify new build defnitions.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/intovsts.wordpress.com/260/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/intovsts.wordpress.com/260/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/intovsts.wordpress.com/260/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/intovsts.wordpress.com/260/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/intovsts.wordpress.com/260/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/intovsts.wordpress.com/260/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/intovsts.wordpress.com/260/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/intovsts.wordpress.com/260/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/intovsts.wordpress.com/260/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/intovsts.wordpress.com/260/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/intovsts.wordpress.com/260/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/intovsts.wordpress.com/260/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/intovsts.wordpress.com/260/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/intovsts.wordpress.com/260/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=intovsts.net&amp;blog=5586949&amp;post=260&amp;subd=intovsts&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://intovsts.net/2009/09/03/more-fine-grained-permissions-in-tfs2010/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/518b6f63e450a759ae797ff3b2ad664f?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96" medium="image">
			<media:title type="html">pietergheysens</media:title>
		</media:content>

		<media:content url="http://intovsts.files.wordpress.com/2009/09/tfs2008administerabuild.png" medium="image" />

		<media:content url="http://intovsts.files.wordpress.com/2009/09/tfs2010pcsecurityrightclick1.png" medium="image" />

		<media:content url="http://intovsts.files.wordpress.com/2009/09/tfs2010managebuildresources1.png" medium="image" />

		<media:content url="http://intovsts.files.wordpress.com/2009/09/tfs2010buildrightclick.png" medium="image" />

		<media:content url="http://intovsts.files.wordpress.com/2009/09/tfs2010buildpermissions.png" medium="image" />
	</item>
	</channel>
</rss>
