Security Guide

16 FileMaker Security Guide
If your organization uses centrally managed authentication for users and groups such as Apple
OpenDirectory or a Windows Domain, you can set up accounts that authenticate users based on
your authentication server. This allows you to use your existing authentication server to control
access to databases without having to manage an independent list of accounts in each FileMaker
Pro database file. For more information on authenticating accounts with external servers, see the
FileMaker Server Help.
Important When a database file contains one or more External Server accounts, make sure you
use operating system security settings to limit direct access to the file. Otherwise, it might be
possible for an unauthorized user to move the file to another system that replicates your
authentication server environment and gain access to the file. Group names for accounts
authenticated with the external server feature are stored as text strings. If the group name is
reproduced on another system, the copied file can be accessed with the privilege set assigned to
the members of the group, which might expose data inappropriately.
Enable log files and file backup features for effective, easy database maintenance.