Need suggestion to configure role in CRM in a particular scenario.

Dear All,
There are 2 business units under root business unit let say B1 and B2. A user (U1) belongs to business unit B1 and other user (U2) belongs to business unit B2. Both users (U1 and U2) are associated to a security role “Branch Users”.
The scenario is users can assigned record (Lead) to the users belongs to their business unit only but can share the record (Lead) to all the users of organization.
Now the problem is for “Branch Users” role if I am giving organization level read permission on “Users” entity then users (U1 and U2) can share lead to all users of the organization but the same time users(U1 and U2) also can assigned lead to all organization
users. If I am giving business unit level read permission on “Users” entity then users (U1 and U2) can only see users of their business unit at the time of assignment but they are not able to see all users of organization at the time of sharing a lead.
Please suggest how to implement this particular scenario to resolve this conflict of read permission on User entity.
Thanks
Sartaj

Hi,
    What you are trying to achieve contradicts each other. You will not be able to achieve both with OOTB security roles. Use the function which will be used most with OOTB roles and for other one, write custom code. Like plug-in to restrict
the change if it is outside the default business unit.
Hope this helps.
 Minal Dahiya
 blog : http://minaldahiya.blogspot.com.au/
 If this post answers your question, please click "Mark As Answer" on the post and "Vote as Helpful"

Similar Messages

  • Need suggestion regarding configuring listener.ora

    I have a prolem with External proceduere uses C as language
    i placed the dll file in oracle_home/bin directory
    and run the procedure, then i got an error which is given below
    SQL> exec shell('dir')
    BEGIN shell('dir'); END;
    ERROR at line 1:
    ORA-28595: Extproc agent : Invalid DLL Path
    ORA-06512: at "ENCORA.SHELL", line 0
    ORA-06512: at line 1
    Then,
    i configured the listener.ora with (ENVS="EXTPROC_DLLS=ANY")
    then i got the following error
    .SQL> exec shell('dir')
    BEGIN shell('dir'); END;
    ERROR at line 1:
    ORA-06520: PL/SQL: Error loading external library
    ORA-06522: Unable to load DLL
    ORA-06512: at "ENCORA.SHELL", line 0
    ORA-06512: at line 1
    if,i tried with out setting (ENVS="EXTPROC_DLLS=ANY") then got Extproc agent : Invalid DLL Path.
    if, i set the environment variable , then got unable to load the external library.
    can any one suggest me how can i solve this?

    I have a prolem with External proceduere uses C as language
    i placed the dll file in oracle_home/bin directory
    and run the procedure, then i got an error which is given below
    SQL> exec shell('dir')
    BEGIN shell('dir'); END;
    ERROR at line 1:
    ORA-28595: Extproc agent : Invalid DLL Path
    ORA-06512: at "ENCORA.SHELL", line 0
    ORA-06512: at line 1
    Then,
    i configured the listener.ora with (ENVS="EXTPROC_DLLS=ANY")
    then i got the following error
    .SQL> exec shell('dir')
    BEGIN shell('dir'); END;
    ERROR at line 1:
    ORA-06520: PL/SQL: Error loading external library
    ORA-06522: Unable to load DLL
    ORA-06512: at "ENCORA.SHELL", line 0
    ORA-06512: at line 1
    if,i tried with out setting (ENVS="EXTPROC_DLLS=ANY") then got Extproc agent : Invalid DLL Path.
    if, i set the environment variable , then got unable to load the external library.
    can any one suggest me how can i solve this?

  • I want to set up the Time Machine and I would love to use the Time  Capsule but since I already have a wireless router I need suggestions on  what other external disks Apple could recommend to use with the Time Machine and  how to configure that disk

    I want to set up the Time Machine and I would love to use the Time
    Capsule but since I already have a wireless router I need suggestions on
    what other
    external disks Apple could recommend to use with the Time Machine and
    how to configure that disk.
    A complication that I need to resolve is the fact that I am using Vmware
    Fusion to be able to use Windows on my Mac. Now it seems that Time
    Machine is not backing up my files
    on that virtual Windows without additional configuration and my question
    is whether you can advise me here or whether this is only a matter for
    the Fusion virtual machine.

    If you want to use Time Capsule you can.. you simply bridge it and plug it into the existing router.. wireless can be either turned off or used to reinforce the existing wireless.. eg use 5ghz in the TC which is much faster than your 2.4ghz.
    You can also use a NAS.. many brands available but the top brands are synology, qnap and netgear readynas  series. These will all do Time Machine backups although how well always depends on Apple sticking to a standard. There are cheaper ones.. I bought a single disk zyxel which was rebadged and sold through my local supermarket. It actually works very well for TM at least on Snow Leopard. Major changes were made in Lion and again ML so do not instantly think it will work on later versions. I haven't tried it yet with those versions.
    Any external drive can be plugged into the mac. Use the one with the fastest connection or cheapest price according to your budget. USB2 drives are cheap and plentiful. But no where near as fast as USB3 or FW800. So just pick whichever suits the ports on your Mac. Interesting Apple finally moved to USB3 on their latest computers.
    TM should exclude the VM partition file.. it is useless backing it up from Mac OS side.. and will slow TM as it needs to backup that partition everyday for no purpose.. TM cannot see the files inside it to backup just the changes.
    You need to backup windows from windows. Use MSbackup to external drive.. if you have pro or ultimate versions you can backup to network drive. But MSbackup is a dog.. at least until the latest version it cannot restore the partition without first loading windows. There are about a zillion backup software versions for windows.. look up reviews and buy one which works for you. I use a free one Macrium Reflect which does full disk backups and is easy to restore.. to do incremental backups though you have to pay for it.

  • Configuration documents of CRM 2007 in Solution Manager

    Hi all,
    I have new version of CRM 2007 in our landscape and Solution manager as well.
    So we need to get/download configuration documents of CRM 2007 by Solution manager but not sure what configuration we need to do in Solution manager to get these CRM documents.
    So kindly suggest me the way to get this done, thanks.
    Regards,
    Himanshu chauhan.

    Hi,
    This link might not be sufficient but will let you know how powerful Solution Manager is.
    http://www.sap.info/index.php4?ACTION=noframe&url=http://www.sap.info/public/INT/int/index/PrintEdition-17873d3e79f60eb30-int/0/articleContainer-214343d5145200a438
    This link will be useful to you providing you how to create non SAP systems in your Solution Manager Landscape.
    http://help.sap.com/saphelp_sm40/helpdata/en/bc/0e90000e58f64fb184a4cba0323e39/content.htm
    This is one good guide for you.
    www.sappro.com/downloads/NonSAPsystems.pdf
    Meanwhile i will try for more indepth coverage of the subject.
    Feel free to revert back.
    --Ragu

  • Mapping Z account group in ERP to Z BP role in CRM

    Hi all,
    We have a scenario where we need to download customers created in custom account groups into CRM and map them to Business Partners in Custom BP Role. With PIDE settings, you can only map a Account Group to a CRM classification. This classification is mapped to a standard BP Role in CRM. We also tried to implement the note 914437. But the code given in this note doesn't work as desired. If anyone has implemented this scenario and/or used this SAP note, please advise me on the solution approach.
    Thanks & Regards,
    Karthik

    Hi Krishna,
    I have the same required as yours.
    I implemented the note 914437.
    I noticed two peculiar cases from the standard mapping i.e. (standard BP Role sold to party)
    1) In BP transaction, in Display in BP Role drop down list box there is no custom BP Role as shown above but if I select the detail Icon I can find it there as shown in below screen shot.
    2) I found in Tx BP there is only one BP Role as shown above but in CRM Web UI there are two BP Roles in the ROLEs assignment block.
    Could you please add your comments or solution for it.
    Thanks,
    Raja

  • Need Suggestion about Solman support & testing E CATT feature

    Hi Solman Experts .
    I need your Strong suggestion. Actually i am working in  ABAP module , I recently joined as a fresher in small company,  I got opportunity to  go Saudi for  "Solman support & testing ,E CATT"  in big MNC . Now i need suggestion , If i go and work there in these areas , If i return to India  will i get Good Job  and Salary here .
    Please suggest me. please it my career issue.

    hi Gafoor,
    I too had this kind of oppurtunity and now i am in abhudabi in crm and solman testing. No problem in this , So you can go to saudi as your wish and the future and scope for the solman is very good. So it s reasonable to go saudi .
    Regards,
    Prabhushankar

  • Need suggestion on Multi currency and Unicode character set use in ABAP

    Hi All,
    Need suggestion. In one of the requirement I saw 'multi-currency and Unicode character set experience in FICO'.
    Can you please elaborate me how ABAPers are invlolved in multi currency as I think this is FICO fuctional area.
    And also what is Unicode character set exp.? Please give me some document of you have any.
    Thanks
    Sreedevi
    Moderator message - This isn't the place to prepare for interviews - thread locked
    Edited by: Rob Burbank on Sep 17, 2009 4:45 PM

    Use the default parser.
    By default, WebLogic Server is configured to use the default parser and transformer to parse and transform XML documents. The default parser and transformer are those included in the JDK 5.0.
    The built-in WebLogic Server DOM factory implementation class is com.sun.org.apache.xerces.internal.jaxp.DocumentBuilderFactoryImpl.
    The DocumentBuilderFactory.newInstance method returns the built-in parser.
    DocumentBuilderFactory dbf = DocumentBuilderFactory.newInstance();

  • Need suggestion on security

    Hello,
    I need some suggestions on what might be the best way to handle security in my application.
    The application acts as a control panel with an initial login screen. When a user logs in it needs to be given access to certain menus and buttons based on the user group in which it belongs. The user groups need to be configurable (so policies will change over time).
    Is JAAS a viable solution? I am not concerned with the OS level of security. The application needs its own level of security. For example, user JohnDoe logs in to application. JohnDoe belongs to the GroupA user group. GroupA has AccessPrivsA, which currently allows him to view menus A B and C. Later on AccessPrivsA is changed by user Admin to only have access to menus A and B.
    Any ideas fellas?

    JAAS will allow you to authenticate the user and to obtain the users credentials via the OS or another source (depending on the LoginModule used) but it will not allow you to control access to various features in your application. For this you need to create an ACL (Access Control List) based framework within your application. An ACL is a list of groups/users that have a certain privileges. You would create an ACL for each of the features within your app that you want to control access to. The various classes within your app could check with the ACL management system to see if the current user has access to a specific feature. For example assume the following (not thread safe) code:
    public class AclMgr{
      private AclMgr _singleton;
      private HashMap _aclmap;
      private Subject _subject;
      private AclMgr(){
        _aclmap = new HashMap();
        // read in the ACLs and store in HashMap. This could be in a properties file.
        // e.g.
        // #My ACL property file
        // #format: feature=ACl
        // view.sensitve.data=ADMIN,SUPER
        // get a reference to the current Subject (which is essentially the user with credentials).
        // This assumes your using JAAS - you could also roll your own if you choose to.
        _subject = UserAuth.getInstance().getCurrentSubject();
      public static AclMgr getInstance(){
        if(_singleton == null){
          _singleton = new AclMgr();
        return _singleton;
      public boolean isAuthorized(String feature){
        boolean authorized = false;
        if(_aclmap.containsKey(feature)){
          // check the Subjects credentials (groups etc) against the ACL for this feature.
          // if the user is in a group that exists in this features ACL then set authorized=true .
        return authorized;
    public class MyJFrame extends JFrame{
      public MyJFrame (){
        super();
        // set up the UI
        // when we get ready to see if we add a feature then do something like this:
        if(AclMgr.getInstance().isAuthorized("view.sensitve.data")){
          // the user has access so add yer button!
    }Of course, this is overly simplified but gets the general idea across. We have implemented something similar in our Enterprise application and it works nicely. With a little more work you can probably provide an UI for authorized users (admins etc) to edit Access Control Lists for various features. Security will be increased if you store the ACL property file on a server somewhere so you can control access to its editing. Or even store it in a Database� lots of fun to be had here ;-)
    Hope this helps,
    Shane

  • Need suggestion on the entire hardware specs for running Oracle VM 2.2.2

    Hi,
    I need some suggestion on the preffered hardware specs which can be given to a customer, he wants to run Oracle VM 2.2.2 or Oracle VM 2.2.1.
    He has already used Cisco UCS with NetApp storage for OVM 2.2.2/2.2.1 and has being unsucessful with lots of issues creeping up. Thus now need suggestion on the hardware spec which is well tested and works fine with Oracle VM 2.2.2/2.2.1 and he wants to run Oracle Fusion Middleware on top of it.
    Any poniters to it will be highly appreciated.
    Regards,
    Sk

    887469 wrote:
    Hi Avi,
    thank you for that information !
    Yes. But only for the UCS gear that uses the converged FCoE adapters. If you have standard Ethernet/FC adapters, then it should be OK.We do use the "M71KR-Q QLogic Converged Network Adapter" with UCS. According to you this is an unsupported combination together with OVM 2.2.1, right ?
    Now the "Oracle VM 2.2 Validated Configuration Details" shows UCS B200 M1 with M71KR-Q as a valid configuration. Does 2.2 mean OVM 2.2.0 and this is supported, but 2.2.1 / 2.2.2 is not ?
    Please clarify since this confuses me.
    Best Regards and TIAAny news for me, please ?
    THX

  • How to configure roles at runtime without changing application code?

    Hi,
    We have implemented Custom Login Module security for our application. Our requirement is to configure the roles without changing the application code.
    Our Authentication Type is 'JAAS With Custom Login Module' and Authorization Type is 'JAAS'.
    According to 10.1.3 section of JhsDevGuide1013.pdf, we need to configure the roles in web.xml and also need to give the role in the 'Authorized roles/permissions' section of the group.
    We dont want to change the application definition once we go live just for adding roles. That is overhead for us as we may need to configure more roles according to our business requirements, but each time we dont want to change the code and re-deploy the application.
    Please let us know the way to meet our requirement.
    Thanks in advance.
    Thanks & Regards,
    Ramakrishna. P

    Hello,
    The JHeadstart Developers Guide has an excellent chapter about security to answer questions like these.
    For example, you could use the JHeadstart based custom security, with datatables, that will enable you to add roles and users at runtime.
    Regards,
    Evert-Jan de Bruin
    JHeadstart Team

  • How to Configure PME in CRM 7

    Team,
    Greetings for the day..
    could any one please provide some lights on "how to configuring PME in CRM 7".
    currently we have installed CRM7 IDES (ABAP / JAVA stacks in 2 different instances under single Host).and need to configure PME.
    CRM functional team trying to configure PRODUCT and its giving "PME installation with Errors".
    Please help in this regard.
    Regards,
    Nagarjuna Gorantla

    Hi Naga,
    Please check the following links...
    http://help.sap.com/saphelp_crm60/helpdata/en/46/4a4296a9dc6a82e10000000a155369/content.htm
    http://help.sap.com/saphelp_crm60/helpdata/en/46/540b2405a05e40e10000000a11466f/content.htm
    As mentioned in the link PME was replaced with ebClient user interface...

  • I need to create a  Notification in CRM WebUI  When we create a new contract

    Hi Experts,
    I am working in Utility Industry and as per the business requirement I need to create a  Notification in CRM WebUI
    When we create a new contract & click on apply button.
    As per my knowledge we are not maintaining Notification information in CRM System. So could you please
    help me to call IW52 during the new contract creation when we click on apply button.
    Thanks
    Roli

    Hello Roli,
    If your requirement is to launch Transaction IW52 after clicking apply button then you can use Transaction Launcher tool in CRM to integrate to CRM WebClient UI.
    Calling Transaction Launcher on user action
    BOR object or ITS based Transaction Launcher
    Regards,
    Ashik

  • Regarding Business object roles in CRM

    Hello friends,
    What are the business object roles in CRM ?can any one can explain about this.
    Regards,
    Rajasekhar.

    Hi Rajasekhar,
    Did you mean "business roles" ?
    The concept of business roles is more used and important in WebUI. SAP CRM business roles are used to package the main business content needed to perform a specific job function. Defining a role influences the complete content visible to a user assigned to this role.
    Some examples of standard roles are:
    SALESPRO (Sales Professional)
    SERVICEPRO (Service Professional)
    IC_AGENT & IC_MANAGER (Standard Interaction Center Agent & Manager)
    Hope this is what you are looking for.
    Regards,
    L

  • Assign biz role through CRM -SU01 and display page at portal

    HI, SDN Fellows.
    I am creating some custom portal roles at portal and mapped it to the custom business roles for some PCUI screens at crmc_blueprint_c --> "Assign Portal Role to Single Role" ("Assignment of CRM Role to Portal Role").
    Currently, our portal UME data source is mapped to CRM system.
    Right now, I have to assign both the CRM Role through SU01(to have access the CRM Object Method at CRM-PCUI application) and Portal Role through User Admin of WAS/portal (to access/display the PCUI iView in the portal).
    My goal is to just assign role through CRM-SU01 and achieve the same output as I described above. Meaning can I just do the role assignment for the CRM role (through SU01) and able to access to the CRM-PCUI application through portal (able to see the pcui screen)?
    Thanks,
    Kent

    What I want is when I assign a role (Sales Manager) said user A in CRM system, userA should able to see the related workset/page/iviews in the portal (without the need to assign the same: Sales Manager role in portal).
    Now, what I have to do is assign the related objects into a single/composite roles in CRM (for backend data access), then I have to assign a portal role (through User Admin of Portal, so that they can see the portal content),
    is that a way we can do it in one step?
    Thanks,
    Kent

  • Need Flash Help - configuring AIrtight Simple Viewer Pro

    I need some help configuring the Airtight Interactive simple viewer pro, which requires flash. I am a complete beginner with flash, and I am reluctant to undertake the learning curve, though I am very tech saavy.
    My ideal would be to locate someone who could do this FOR me, though resources are very limited for this project. Any suggestions of where I might connect with someone interested in doing this?
    Alternately, I could undertake it myself, with someone qualified to coach me rather thouroughly through the whole process. That could be offline, or here where others could benefit from the thread. If someone offers this, I will post the precise details of what I need. The project is medium challenging, not extremely complex, but more than very basic.
    Many Thanks.

    Hi:
    When you create the simpleviewer slideshow with iPhoto's plugin there should be a folder created on your HD that contains the items seen in the screenshot below:
    The folder was named simpleviewer because that's what I named it during the export from iPhoto. That's the same folder as I refer to as "Slideshow folder". It can be whatever you name it when exporting from iPhoto. Upload that folder to your iDisk/Web/Sites folder as shown below:
    In the iFrame code use the following URL to the index.html file inside the simpleviewer folder:
    http://web.me.com/YourMMe_AccountName/simplerviewer/index.html
    That should do it.

Maybe you are looking for

  • ITunes 9 Genius Mixes (having issues)

    I turned off Genius, turned it back on to get Genius Mixes and have not been able to actually play a Genius Mix yet! When I go to the Genius Mix icon and then try and select a Mix, I hit the Play button that appears in the middle of the 4 random cd c

  • SCCM 2012 R2 CU3 UPGRADE BROKE REMOTE ADMIN CONSOLE CONNECTIVITY

    I installed SCCM 2012 R2 CU3 on my site server but it broke a couple things. I've never had problems with SCCM upgrades before. The admin console works if you log into the site server and run it from there but not when you try it from anywhere else (

  • Why can I no longer undo in search bars?

    Now that I'm using Mountain Lion, once I've pressed Enter in a search bar (e.g. in dictionary, firefox) I am no longer able to use Command+Z to undo my typing to get back to what was in the search bar before I pressed Enter. This means I can't go bac

  • Istat Pro "Processes" doesn't work since upgrade to OS X 10.8.2

    Ever since I upgraded the OS to 10.8, the istat Pro widget on the dashboard doesn't list anything but a stack of empty white squares under "Processes". Is this a known bug?

  • Exporting an altered graphic from pages for use in other apps

    Does anyone know how to export a graphic, altered in Pages to like iphoto for example? The reason i am asking is i had a logo i needed to alter.  The logo is a sphere but had a white space box around it that i needed to remove.  Using the Instant Alp