LOCKDOWN System Option
Enables the ability to limit access to files and to specific SAS features for a SAS session executing in a batch or server processing mode.
| Valid in: | configuration file, SAS invocation |
|---|---|
| Category: | Environment Control: Initialization and Operation |
| PROC OPTIONS GROUP= | EXECMODES |
| Restriction: | cannot be used when XCMD or RLANG are enabled |
| See: | XCMD System Option |
| PROTOLIBS System Option | |
| LOCKDOWN Statement | |
| Configuration Guide for SAS Foundation for UNIX Environments |
Table of Contents
Syntax
LOCKDOWN
Syntax Description
LOCKDOWN
Enables the ability
to limit access to files and to specific SAS features for a SAS session
executing in a batch or server processing mode.
Details
The LOCKDOWN option
is intended for use in a multi-environment deployment. In addition
to LOCKDOWN, security administrators also rely on the NOXCMD system
option. For more information, see XCMD System Option: UNIX in SAS Companion for UNIX Environments, XCMD System Option: Windows in SAS Companion for Windows, and XCMD System Option: z/OS in SAS Companion for z/OS.
When the LOCKDOWN option
is specified for a SAS session, SAS enters a locked-down
state at a lockdown point. A SAS session in the locked-down
state has following restrictions:
-
limited file system accessAll access to local files and directories are validated through the lockdown path list.The lockdown path list specifies which host file resources are available when a SAS session is in the locked-down state. This list includes default system directories and user directories and files. For details about the lockdown path list, see LOCKDOWN Statement.
-
limited SAS language featuresThe following SAS language features are disabled:
-
DATA step Java Object "javaobj"Note: On z/OS, execute any of the DATA step functions that are part of the SAS Data Location Assist feature. For details, see SAS Data Location Assist for z/OS in SAS Companion for z/OS.
-
PROC JAVAINFO and PROC GROOVY
-
FUNCTIONS: ADDR, ADDRLONG, PEEK, PEEKLONG, PEEKC, PEEKCLONG, POKE, POKELONG, and MODULE
-
Some z/OS host procedures: PDS, PDSCOPY, RELEASE, SOURCE, TAPECOPY, and TAPELABEL
-
z/OS access method: VTOC
-
LOCKDOWN does not take
effect in a SAS session until after the
lockdown point.
The lockdown
point is the point during SAS execution when the following
tasks have completed to establish a user’s SAS environment:
-
SAS session initialization
-
AUTOEXEC execution
-
INITSTMT execution
-
metadata library pre-assignments
During initialization
of the user’s SAS environment, all paths and files are available
and work as designed (for example, SASUSER, SASHELP, WORK, LOG, and
so on). Metadata pre-assigned libraries and AUTOEXEC pre-assigned
libraries also work as designed. When initialization is complete,
SAS is put in the locked-down state with limited file system access.
When the server is locked
down and the PROTOLIBS system option is not set to NONE,
the lockdown path list will override the path list that is specified
by the PROTOLIBS system option. When PROTOLIBS system option is set
to NONE, the modules that are
specified by the LINK Statement cannot be loaded. For
more information, see PROTOLIBS
System Option.
Examples
Example 1: Autoexec Example
In this example, the
server invocation points to a SAS autoexec file in which specific
paths are added to the lockdown path list:
/usr/local/bin/SAS/SASFoundation/9.4/sas -objectserver -lockdown -autoexec sample-auto.sas
Example 2: z/OS Example
In this example, a SAS
autoexec file is used with LOCKDOWN in a z/OS batch job:
//SASSTEP EXEC SAS,OPTIONS='LOCKDOWN NOXCMD' //SASEXEC DD DISP=SHR,DSN=USER01.SAS.PGMLIB(LOCKAUTO) //SYSIN DD DISP=SHR,DSN=USER01.SAS.PGMLIB(PGM01)
See Also
System Options:
XCMD System Option: UNIX in SAS Companion for UNIX Environments
XCMD System Option: Windows in SAS Companion for Windows
XCMD System Option: z/OS in SAS Companion for z/OS
Other SAS Documents:
Locked-Down Servers in SAS Intelligence Platform: Security Administration Guide
Last updated: October 6, 2026