Restricting access to the data directory
Using your network file system security, you should always protect the data directory so it is invisible to everyone but the network login used by the server itself.
No matter how elaborate the security on the server, if users can see the data directory, they can view data using TM1® directly from the disk, without connecting to the TM1 Server.