Internet MIS security technology includes mainly: Authentication, Encryption, Access Control, Auditing and so on. Role-based access control (RBAC) is an access control method that has been widely used in Internet, operation system and relation database many years. Though RBAC is already relatively mature in the above fields, new problems occur when it is used in XML properties. By means of enterprise office automation system (EOA), the enterprise can easily migrate the release of information and communication functions to the Internet, which makes people convenience. The EOA system also provided a combination of enterprise management process reengineering, construction and optimization of the internal management information systems, decision support systems, and office automation systems. The system can get high level technical and advisory support for the management of enterprise information to fulfill the needs of specific business, affairs, and the conferences. This paper introduces EOA system strategy based on role-based access control (RBAC). The system centers in day-to-day office management service, achieves division of authority between different departments and staff through the introduction of data rights and function rights, so as to achieve the office management platform with the coordination of information, management, and service. This paper provides the method of realizing the work flow through RBAC management, the concept of authority is broken down to each operating procedures; realization of user operational procedures are reflected in the achievement of right-matching and right-series, office processes are standardized, the management level and quality are improved; the goal of improving office efficiency is achieved.