You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何防止意外刷新Tableau Extract,仅允许Server Admins手动刷新

How to Restrict Manual Extract Refreshes to Server Admins Only in Tableau Server

Great question—this is a super common pain point when managing large, resource-heavy extracts that only need scheduled monthly refreshes. Let’s break down the steps to lock down manual refreshes so only Server Admins can trigger them, while blocking Site Admins and other users:

1. Understand Tableau’s Permission Hierarchy First

First, a quick recap: By default, Site Admins have broad management rights across their site, including the ability to refresh any extract. To override this, we need to use data-source-level permissions (since deny permissions always take precedence over allow permissions in Tableau).

2. Apply Granular Permissions to the Specific Extract

This is the most targeted approach—we’ll adjust permissions only for your large, monthly-refresh extract:

  • Navigate to the published data source in Tableau Server.
  • Click the Permissions tab (top-right corner of the data source page).
  • Remove or modify Site Admin group permissions:
    • Find the "Site Administrators" group in the permissions list.
    • For the Refresh Extract permission, set it to Deny. This will override their site-level admin rights specifically for this data source.
  • Grant Server Admins explicit refresh access:
    • Add the "Server Administrators" group to the permissions list.
    • Set the Refresh Extract permission to Allow.
  • For all other user groups/individuals, ensure their Refresh Extract permission is set to Deny or left unassigned (which defaults to no access).

3. Optional: Customize Site Admin Roles (Broad Restriction)

If you want to block Site Admins from refreshing all extracts across the site (not just this one), you can create a custom site role:

  • Go to Site Settings > Roles in Tableau Server.
  • Click Create Role, then select "Site Administrator" as the base role to copy permissions from.
  • Uncheck the Refresh Extracts permission in the list of capabilities.
  • Save the new role, then reassign all existing Site Admins to this custom role instead of the default Site Administrator role.

4. Verify the Setup

After making these changes, test with two accounts to confirm:

  • Log in as a Site Admin: Try to refresh the extract—you should see the refresh option grayed out or get a permission error.
  • Log in as a Server Admin: You should still be able to trigger manual refreshes and modify the scheduled refresh if needed.

Key Notes

  • Keep your embedded refresh credentials secure: Since only Server Admins can modify the data source, they’ll be the only ones who can update the embedded credentials if needed.
  • Document this setup: Make sure your team knows about this restricted extract to avoid confusion when trying to refresh it.

内容的提问来源于stack exchange,提问作者Tucker Moore

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 04:40:40