Migrating SAP roles to EP

We are on NW1004s with Bex 3.5 latest patch. Now we are planning to migrate to new Bex front end tools and also planning to replace the Bex Browser with Portal functinality.
In BI, we have a menu roles with workboks attached to it. As part of test, we uploaded roles from SAP system to Portal system using "Role uplaod" functionality . Upload is successful. Roles appear under Portal contenet->Migrated Contenet -> SAP componenet system->Roles, in Conenet Administartion tab.
My questions :
1. Some of the workbooks are converted as " linked objects not available". Why this happens.
1. When we assign migrated role to particular user in portal, does it appear as new tab or in a tree structure in one of the iview.
Appreciate any help.
Regards
MB

Hello Madhukar,
Regarding your second question, by default the role will appear as new tab. You can also made them to get displayed under the detailed navigation under one tab. Refer to the note 762998.
Regards
Deb
[Reward Points for helpful answers]
Message was edited by:
        Debasish Sarkar

Similar Messages

  • Migrate SOFS Role between 2012 R2 Clusters

    I have a sofs role configured on a 2012R2 3 node cluster, and I need it moved to a different cluster so that the nodes on the current cluster can be rebuilt. Both clusters use a CSV. The share that is used by the sofs sits on a CSV (connected by iscsi on
    each node)
    Im trying to understand the advice here:
    http://technet.microsoft.com/en-us/library/dn659431.aspx
    Method 1 is confusing because it discusses migrating virtual machine storage with VMM but I dont see how this relates to a SOFS.
    Method 2 seems most applicable, however when I use the 'Copy Cluster Roles Wizard, and I select the source cluster, it brings up a list of role available to be migrated, and I cannot select the single SOFS I want to move. If I check one box, it automatically
    checks the box for every role on the cluster, and I dont want to move everything.
    Also, im confused about the process of the migration and what exactly migrates once I get past the first issue above.
    Should I be running this wizard to migrate the role to the new cluster, then connecting the iscsi for the lun to the 3 destination nodes and mounting as a csv ? and then disconnecting the csv from the source cluster ? or vice versa ? or?
    cant find a good guide for this. Any advice or pointers in the right direction much appreciated.
    tks

    Hi dfgsdfgf,
    Could you clarify “and I select the source cluster, it brings up a list of role available to be migrated, and I cannot select the single SOFS I want to move.” If I am not
    misunderstanding, are you trying to “migrate” one of the SOFS cluster node to new server? You must migrate the SOFS role, but can’t the node.
    More related information:
    How to Move Highly Available (Clustered) VMs to Windows Server 2012 with the Cluster Migration Wizard
    http://blogs.msdn.com/b/clustering/archive/2012/06/25/10323434.aspx
    Migration Paths for Migrating to a Failover Cluster Running Windows Server 2012 R2
    http://technet.microsoft.com/en-us/library/dn530781.aspx
    Migrate Cluster Roles to Windows Server 2012 R2
    http://technet.microsoft.com/en-us/library/dn530779.aspx
    Hope this helps.
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • User does not appear in group created from SAP role

    Hello --
    I have a user that has logged into InfoView successfully with SAP authentication and is showing in the CMC under the "User List." When I view the list of users in the group that was created from the SAP role he was a part of, he is not there.   When I go to the user account and view "Member of," the group IS shown in the list. 
    Any idea?  Any way I can "refresh" the group or anything like that?
    Thanks
    Casey

    Thanks for the replies.
    We are on XI 3.1 FP1.8 and we do have a CMS cluster.  Server reboots this weekend seem to have resolved the problem. I am curious why this question was asked, though:
    "Did you reassign the user to another SAP role after the user has already logged at least once in the InfoView?"
    Is this something that could have caused the problem or is it a possible workaround if we run into the issue again? 
    Thanks again...
    Casey

  • How to synchronize Identity System Roles with SAP Roles?

    Hello, experts!
    Could you give me an advice?
    I'm trying to perform role syncronization between SAP R/3 and Identity Manager, but the default task definition (Resource Role Synchronizer) can't find a
    SAP resource (for example method getResourcesSupportingObjectTypes can't find resource with attribute type activityGroups (SAP Roles)).
    Do you have an experience with syncronization SAP and IDM Roles ?
    How it is possible?
    Thank you!

    May be somebody knows what odjectType attributes like Roles (activityGroups) or Profiles has?

  • GRC - SOD Conflict Management (SAP Role Substitution)

    Hi,
    I am looking to see how others handle SAP Role Substitution and SOD conflicts.
    For example, a person is going to be out on vacation for a few day and assigns their roles to another employees to continue with daily tasks....SOD risks result because of the temporary assignment and role combinations....what are you guys doing to manage, and monitor this sort of activity?
    Your help and comments greatly appreciated!

    Hi
    As already stated by Martin, one of the option for handling adtional backup access to users could be through Superuser Privilage management(If GRC has been implemented with your client). This would allow detailed reporting at transaction level for audit purposes.
    If GRC is not implemented with your client then any additional access which is resulting in SoD, there has to a proper documentation of temporary access assignment to users(For Audit purpose). Mitigation control should be documented and submitted by the supervisor of the user to the SoD team to ensure proper compliance is in place for the additional access provided to the user.
    Thanks.
    Anjan

  • Duet Enterprise 1.0 SP2 - SAP Role based authantication

    Hi All,
    We have implemented Duet Enterprise 1.0 SP2 in our landscape. Now we try to implement SAP Role based authantication.
    But don't know which role to assign for which authorisation. In my scenario i have created 2 users. For one user i want to have only read access to all lists (Contact, Employee, etc) and for another user i want to have all acess (read, write, modify, delete) on all lists available at sharepoint.
    Can someone help me to tell what roles (template) need to assign for what operation.
    Which roles i do assign to user in SAP that which ristrict users access at Sharepoint.
    Thanks & Regards
    Virender Solanki
    09818316550

    Hi Binson,
    I want to ristrict the crude operation (create, update etc) by giving roles in backend system. i am able to apply restriction at sharepoint end but i don't want that. i want SAP role based security.
    So i want, according to given roles in backend system user is able to do operations at sharepoint.
    Thanks & Regards
    Virender Solanki

  • Migrate Application Role from uat to prod in 11.1.1.6.10

    Hi All,
    We have to migrate the UAT Application Roles to Prod instance. I followed Rittman Mead policy store migration. servers  in LINUX
    http://www.rittmanmead.com/2011/04/oracle-bi-ee-11g-migrating-security-policy-store-part-2/
    But at MigrateSecurityStore step, I am facing an issue with the wlst script which is throwing below error.
    I am getting bellow error
    wls:/offline> migrateSecurityStore(type="appPolicies",srcApp="obi",configFile="/ usr/app/MW/SecurityMigration/jps-config-policy.xml",src="sourceFileStore",dst="t                                                                                                         argetFileStore",overWrite="false")
    Oct 17, 2013 11:41:27 AM oracle.security.jps.internal.config.xml.XmlConfigurationFactory initDefaultConfiguration
    SEVERE: org.xml.sax.SAXParseException: The XML declaration must end with "?>".
    Command FAILED, Reason: The XML declaration must end with "?>".
    Traceback (innermost last):
      File "<console>", line 1, in ?
      File "/usr/app/MW/oracle_common/common/wlst/jpsWlstCmd.py", line 955, in migrateSecurityStore
      File "/usr/app/MW/oracle_common/common/wlst/jpsWlstCmd.py", line 927, in migrateSecurityStoreImpl
            at oracle.security.jps.internal.tools.utility.source.JpsInitializerSource.getSources(JpsInitializerSource.java:155)
            at oracle.security.jps.internal.tools.utility.JpsUtility.<init>(JpsUtilty.java:62)
            at oracle.security.jps.internal.tools.utility.JpsUtilMigrationPolicyImpl.migrateAppPolicyData(JpsUtilMigrationPolicyImpl.java:151)
            at oracle.security.jps.tools.utility.JpsUtilMigrationTool.executeCommand(JpsUtilMigrationTool.java:231)
            at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
            at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:39)
            at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25)
            at java.lang.reflect.Method.invoke(Method.java:597)
    oracle.security.jps.JpsException: oracle.security.jps.JpsException: The XML declaration must end with "?>".
    This is config.xml file
    <?xml version='1.0' encoding='utf-8'? standalone='yes'?>
    <jpsConfig xmlns="http://xmlns.oracle.com/oracleas/schema/11/jps-config-11_1.xsd" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://xmlns.oracle.com/oracleas/schema/11/jps-config-11_1.xsd">
       <property name="oracle.security.jps.jaas.mode" value="Off"/>
       <propertySets>
    <propertySet name="sam1.trusted.issuers.1">
    <property name="name" value="www.oracle.com" />
    </propertySet>
    </propertySets>
       <serviceProviders>
          <serviceProvider type="POLICY_STORE" name="policystore.xml.provider" class="oracle.security.jps.internal.policystore.xml.XmlPolicyStoreProvider">
             <description>XML-based PolicyStore Provider</description>
          </serviceProvider>
       </serviceProviders>
       <serviceInstance name="srcpolicystore.xml" provider="policystore.xml.provider" location="/usr/app/MW/SecurityMigration/uat/system-jazn-data.xml">           
      <description>File Based Policy Store Service Instance</description>       
      </serviceInstance>
      <serviceInstance name="policystore.xml" provider="policystore.xml.provider" location="/usr/app/MW/SecurityMigration/prod/system-jazn-data.xml">           
    <description>File Based Policy Store Service Instance</description>       
    </serviceInstance>
       </serviceInstances>
        <jpsContexts default="default">       
    <!-- This is the default JPS context. All the mendatory services and Login Modules must be configured in this default context -->       
    <jpsContext name="sourceFileStore">           
    <serviceInstanceRef ref="srcpolicystore.xml"/>       
    </jpsContext> <jpsContext name="targetFileStore">           
    <serviceInstanceRef ref="policystore.xml"/>     
    </jpsContext>   
    </jpsContexts>
    </jpsConfig>
    Please let me know if i need to provide further inputs.Appreciate your help.

    make sure you are running the wlst.sh from this path /MWHOME/Oracle_BI1/common/bin/wlst.sh
    you can take a look at this too Migrating Security Policies from Development to Standalone WLS 11g
    http://ssssupport.blogspot.com/2013/02/obiee-11g-application-role-migration.html
    Obiee11g: Migrating application role from DEV to Prod server in obiee11g

  • BO authorization model with sap roles / access tot folders, functionalities

    Hi Specialists,
    As authorization cunsultant in BI, I have little knowledge of the security setup in Business Objects.
    I have to setup an authorization model were the authorizations are assigned via sap roles in the backend BI system. These roles are imported in BO were they can serv as 'user groups' and access to folders, functionalities.
    Can anyone provide me a overview, guide, training document... on how the authorizations are managed in BO and best practice when they are linked to sap backend roles.
    The goal will be to user the sap BI backend roles and user them to grant users in BO specific access to specific folders. Eg; User A can access folders 1 as "refresher only", User B is able to publish reports in folder 2, User C has only view access in folder 2...
    Any help would be great!
    Thanks very much in advance.
    rgrds
    Kristof

    Hello,
    this is the best approach you mentioned here.
    I prefer to create roles serverd as functionalities in the Backend. For Example you have a "View" role, a "Refresh" role and so on.
    On the other hand i saw some setups where there is only on role in the Backend with all the BO Users. Then you have to create you functional groups in BO and have to assign the Users there to the Groups.
    Check the Adminguide of BO XI 3.1 for more Informations.
    Regards
    -Seb.

  • SAP roles and BW

    I am new to SAP and BW.  A goal of mine, straight from my GEM form, is to "Increase my knowledge of the security in the SAP application by understanding SAP roles and how they apply to Business Warehousing".  Please point me to websites, books, white papers, etc.
    [email protected]

    Zip
    Please check these links and hope it helps
    http://help.sap.com/bp_biv235/BI_EN/documentation/Authorization_BW_Proj.pdf
    http://help.sap.com/saphelp_nw04/helpdata/en/52/671595439b11d1896f0000e8322d00/frameset.htm
    Thnaks
    Sat

  • Dynamiclly assign responsible agent based on SAP role

    Hello Experts,
    I have users set up in SAP and specific roles assigned to these users. for less maintenance purpose, I would like to know:
    Is it a way, we can use roles to find SAP users, then assign these users as workflow responsible agents?
    I do not want to maintain orgnizaion structure. just want to call sap role to assign the users.
    Is it a SAP standard way to do it? I did not find too much information on my question, can you please give me some insights on how to do it?
    I appreciate your time!
    Estell

    Hi,
    in agent definition for workflow steps you are allowed to use roles.
    So just try it out.
    Kind regards, Rob Dielemans

  • Importing SAP Roles in CMC

    HI
    when I importing SAP Roles in CMC  there is an error, following is the error information:
    CMALLC:rc=27>Connect from SAP
    gateway to RFC server failed Connect_PM GWHOST=192.168.1.66,
    GWSERV=sapgw00,SYSNR=00
    Location SAP-Gateway on host saptest/sapgw00
    Error   timeout during allocate
    Time   Tue Feb 22 15:25:58 2011
    Release  720
    Component SAP-Gateway
    Version  2
    RC      242
    Module  gwr3cpic.c
    Line     1911
    Detail    no connect of TP sapdp00 from host 192.168.1.66 after 20 sec
    Counter  2
    Thanks

    HI,
    are you using the details for an application server or for a message server ?
    Ingo

  • Mass Generation of standard SAP roles

    IS there a way to generate & Activate SAP standard roles in mass.  We want to generate and activate following standard SAP roles so that we do not have to go through them manually for authorization changes.
    SAP_PP_BD_RTG_DISPLAY
    SAP_PP_BD_RTG_MAINTAIN
    SAP_PP_BD_WKC_DISPLAY
    SAP_PP_BD_WKC_MAINTAIN
    SAP_PP_CAPA_PLAN
    SAP_PP_CAPA_PLAN_EVAL
    SAP_PP_KAB_CONTROL
    SAP_PP_KAB_REPORTING
    SAP_PP_MATERIAL_MANAGEMENT
    SAP_PP_MP_FORECAST
    SAP_PP_MP_LONG_TERM_PLANNING
    SAP_PP_MP_MPS_PLANNING
    SAP_PP_MRP_COORDINATION
    SAP_PP_MRP_EVALUATIONS
    SAP_PP_MRP_MASTER_DATA
    SAP_PP_MRP_PLANNED_ORDER
    SAP_PP_MRP_PLANNING
    SAP_PP_PI_ALERT_MGMT_STD
    SAP_PP_PI_BATCH_RECORD_EXP
    SAP_PP_PI_BATCH_RECORD_SUPER
    SAP_PP_PI_CAPA_EVAL_STD
    SAP_PP_PI_CAPACITY_EXP

    Dev,
    It is possible to generate roles using PFCG or PFUD up to a extent of choosing 8 per a time and it won't accept more than that. So please check with it before proceeding in this issue.
    It is advisable not to use SAP predefined roles, rather than using customized roles.
    Regards,
    VeerendraKumar.

  • What SAP roles can be imported?

    Hello all
    I installed SAP integration kit, JCO 2.1.9 is installed. In CMC I'm able to go to management -> authorization -> SAP and entered appropriate settings for our authorization system (SysID, client, application server, system number, user, password, ...). In the tab "role import" I see some roles... but not all the ones I would have expected.
    Can anyone tell me what makes a SAP role being visible / selectable for import? Does a SAP role in SAP system (transaction PFCG) need some special tweaking in order to make it available in CMC? Unfortunately I couldn't find any useful information on this.
    Thanks a lot
    Renaud

    Hi,
    roles which do contain assigned users.
    Ingo

  • Erro when importing SAP roles into BO Edge XI 3.1

    Hello,
    I'm currently setting up the SAP Best Practices on a BO Edge XI 3.1 system (32 bit) and trying to link up with an SAP ECC 6 EHP 4 system (64-bit).
    When getting to the authorisation step I go to the CMC > Authentication > SAP > Role IMport.
    There I receive following error: 
    JCO.classInitialize(): Could not load middleware layer 'com.sap.mw.jco.rfc.MiddlewareRFC' JCO.nativeInit(): Could not initialize dynamic link library sapjcorfc. Found version "2.1.9 (2010-01-28)" but required version "2.1.8 (2006-12-11)".
    After closing and re-entering the same tab I receive following message: org.apache.jasper.JasperException
    I have not even the possibility to enter the roles manually. The system doesn't allow me.
    There is no specific SNC security set up for my SAP system.
    I have been able to connect to the logical system of SAP because when I updated on the tab: "Entitlement Systems" it proposed my logical system name that I created in SAP.
    As I found on another SAP forum the version 2.1.9 should also be the good version.
    Can someone help me out with this one (does anyone has still the older SAP Java connector version 2.1.8)?
    thanks in advance
    Thierry

    Hello,
    That's what i did but didn't help.
    I finally managed to find the problem. I had also to install a file named librfc32.dll in the same directory. When installing the necessary files apparently the version of this file librfc32.dll was not the correct one because it didn't match with the version that is installed together with the Sap gui (I presume). So by re-installing the former version of this file librfc32.dll it finally worked.
    thanks anyway

  • Third party background ID requires standard SAP role

    We are connecting to a 3rd party through a background ID that we have created on the ABAP side.
    However, in testing this access, we notice that this connection does not work if we assign a custom role (or even SAP_ALL) to it.  It works ONLY if we assign a specific SAP-delivered role (SAP_XI_ADMINISTRATOR_J2EE) to it.
    We have logged into the J2EE UME and assigned our custom group (which corresponds to our ABAP role - ZSAP_BATCH_XI) TO the Administrator Role in the UME.  But this still doesn't seem to fix the problem, and it is still requiring the standard SAP role.
    Can you pls. let me know if there is another step I should do, to force my background ID to use my custom role, rather than the standard SAP role.
    Thank you,
    Ashish

    Hi,
    This is standard in SAP and you would only need to assign the WBS to the Sales Order for which the Material is being Procured for and the Cost / budgets can be tracked through this WBS element.
    This activity can be seen thru PS Reports
    Best regards
    Amit Bakshi

Maybe you are looking for

  • How do I save  a large font size in my google email?

    Every time I go to my google email the font size is small. So I use View > Zoom in to enlarge it. If I exit and return , I have to repeat the process. How do I save the settings? Dave

  • TAXINN OR TAXINJ  NOT IN IDES ECC 6.0

    Dear All, We are implementing IDES Ecc 6.0 but we are not able to find out any Tax procudure regarding INDIA . so system gives error "Country to calculation procedure" . Any one help on this topic , it is very urgent. Regards, Kaushal Shah +91 099247

  • How to e mail the revised and signed docs to the other w/o missing them.

    How can I e mail the docs I added some texts and signed over the original docs without missing them. I tried and I all missed the added part. It was sent the ordinal doc as is. Please give me some advice.

  • 3 or 4? Graphics cards with MPE acceleration!

    Being an experimenter with my new Asus X99-E WS motherboard after running about 50 runs of PPBM8 and having four x16 slots which theoretically can run simultaneously at 16 lanes, today I could not resist running a third GTX graphics card.  In slot 1,

  • Question on hooking time capsule up.

    I am looking to buy a time capsule, but first need to know a couple things, so anyone who could help me I would gladly appreciate it.  First question:  I currently have a modem and a wireless router hooked up at my house, which runs fine.  I was just