To view "Daily ID Administrators Activity" & "Dormant Accounts"

Dear Hyperion Users,
I am looking out for the below ones on Hyperion 9.3.1.
1. Daily ID Administrators Activity [User maintenance, to track any changes on user's access, etc]
2. Dormant Accounts - Account which are not used or which are idle for certain time [Lets say user who hasn't logged on for 3 months] and remove/clean up the accounts.
I have opened SR with Oracle on the above 2 points and they conveyed that Hyperion 9.3.1 doesn't provide any of the above information.
3. User Access Profile Listing : I could log on to Shared Services and create User access listing report via "Administration" -> "View Report".
We have Hyperion Planning, HFM, Essbase and BI+ applications and I need your help in finding posibility of creating customised query or find way to get these "Daily ID Administrators Activity" & "Dormant Accounts" information for my Hyperion Applications.
Thanks in advance.

Finding dormant accounts in Essbase specifically (so it depends what you mean by 'Hyperion', but you are posting in the Essbase forum :) ) comes up frequently. I believe the information in this thread - Info of Last login details of Users - is still accurate, and I'm sure it would be correct regarding 9.3.1.
EDIT: Must have read that too quickly, as I see you've listed your apps - but what I wrote above stands re Essbase!
Edited by: TimG on Oct 24, 2011 11:52 AM

Similar Messages

  • How can I get an Active Direcotry account to show at login screen

    I've just Binded a computer to our Active Directory network, and when I log off, I only see the local account listed at the login screen, and it takes 5-10 seconds before the arrow comes up that lets me choose Other.
    I  want to be able to list the Active Directory account that the user should login with, is there a way to make it stick at the login screen?

    You can add extra empty toolbars if you want to see more of the persona.
    You can create extra toolbars to get extra space via "View > Toolbars > Customize" or "Firefox > Options > Toolbar Layout"
    You have to put something on a toolbar (drag a Space item onto it) before closing the Customize window because empty toolbars are automatically removed.

  • ActiveSync mail/contacts/calendars removed after Active Directory account is locked out?

    Hey guys,
    Wondering if anybody has seen an issue like this.  This is a new Exchange 2010 deployment (8+ CAS servers) and the devices are all iPhones/iPads running the latest version of iOS (7.1.2).  The CAS servers are behind a load-balancer.
    Basically when a users' Active Directory account is Locked in AD (either manually or by entering the wrong password) their ActiveSync Contacts, Calendars and all Mail folders (except the Inbox strangely!) will be removed from the iOS device within a few hours.  So an account might get locked out at say 6pm, if left locked out by the next morning the ActiveSync account will still be setup on the device as normal, but everything is gone except the mail in the Inbox.  If a user has an iPad and iPhone both will be blanked.
    The behaviour is similar to what is documented here - iOS: How to mitigate a full sync or reload of Exchange account data - however the Exchange servers are not issuing HTTP500 errors as we have captured logging during the window where the device blanks itself.
    Any thoughts would be appreciated!
    Thanks!

    Hello,
    which event ids are shown in the event viewer from the DCs? Or maybe locally also some errors are locked that give some more details.
    If this happens it sounds personally for me that Java is the problem. Have you already opened a call at
    https://community.oracle.com/welcome ?
    Best regards
    Meinolf Weber
    MVP, MCP, MCTS
    Microsoft MVP - Directory Services
    My Blog: http://msmvps.com/blogs/mweber/
    Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.

  • Creating Active Directory Accounts for vSphere 5.1 Services

    To set up the management pieces of vSphere, I need to have an account or accounts created in Active Directory.  I need to determine how many to create and what permissions they need.
    In Single Sign on Server, I need to choose an account that vCenter server will use when it connects to SSO.  I can use the default admin@system-domain.  Or I can add an account that is configured in Active Directory.  Or, I can also use an active directory group instead of an individual user.  What is the best way to do this and if I use an AD account, what permissions does it need at the domain level and at the local level on the Single Sign on Server?  (I'm using multisite mode, so I can't use local accounts)
    In SQL Server, I need to choose an account to use for the SQL server service.  Should this account be an active directory account or a local user account?  If so, what permissions should be assigned to the account in Active Directory and what permissions should be assigned to it on the local machine?  What AD group, if any should it be a part of?  What local permissions does it need?
    In vCenter Server, I need to choose an account to run the "vCenter Server Service" in.  Is it best to use the default "system" account or to use an account from Active Directory, or a local account?
    I'm trying to get a big picture of an AD account/group strategy to use that covers the main management pieces of vSphere - vCenter Server, Single Sign on, Inventory Service, Web Client Services.
    For example, create one group called "vSphere Services", then create separate accounts for each management piece, and assign them specific permissions on specific systems.  Or create separate groups for each management piece and assign permissions to the groups.  Is it better to consolidate some of these user names or split them out?  Any experiences / suggestions welcome.  Thanks.

    Hello,
    For general services I use a service specific account within AD. This was before SSO and I use the same after SSO. SSO is used by only two services that I know about at the moment (Inventory Service and perhaps vCloud). However, there are many other service accounts that should be created. You want one account per service and I use AD for this, this way I can create a service account group and give it the appropriate roles and privileges. FOr example I have service accounts for:
    VMware View
    XenDesktop
    vCops
    HPSIM
    Solarwinds
    VMTurbo
    NetApp
    etc.
    One service, one service account, each with either a general role or custom role depending on access requirements to vCenter.
    For SSO, I to am waiting on general information, but I set mine up fairly basically to cover only those resources that make use of SSO. Since the vast majority of items do not use SSO, the rule still applies.  Once SSO is supported by more than one or two tools, you still need to maintain that separation.
    So I say yes, tie SSO to AD and do everything in one place, unfortunately, that is not very clear, or at least was not to me and these SSO issues are either beng fixed, documented, or both.
    Best regards,
    Edward L. Haletky aka Texiwill

  • HT1918 I have 2 active itune accounts on the same laptop, I would like to know if I can delete or cancel the newest account and if so how do I do this.

    I have 2 active itune accounts on the same laptop. My orginal account was set up 3 yrs ago I believe for an ipod that I have but I hadn't used it in a long time. I recently bought an iphone 4s and my daughter was helping me with itunes. She made me another itunes account under another email address that I use for facebook instead of using the account I already had. I have purchaed a few songs and ring tones from this new account, but since then I logged out and started using my old account a week or so ago. What I want to do is delete or cancel the newest account but don't know how to or what to do. The email I get from "Apple" is being sent to the email address I use for facebook and not to my orginal aol email account. Can you tell me what I need to do to? I only want one account and I would like to keep the old account.
    Thank you!

    Stop using the account.
    You need do nothing more.
    You will need to authorize your computer for both accounts as you have purchased from both accounts.

  • How to avoid duplicate DN exception when creating Active Directory Account

    I am using OIM 9.1.0.2 to provision Active Directory accounts.
    I run into issues when the DN of the user to be created already exists and I would like to know if anyone has some logic I can use to generate a different DN for new user by adding a number or something like that to the DN
    Here is an example.
    User 1 exists already and their DN: cn=john smith, cn=users, dc=company,dc=org
    New user joins the company and his name is also john smith and he has no middle name: so system attempts to create his account as cn=john smith, cn=users, dc=company,dc=org
    how can I accomplish this by making the account say cn=john smith_1, cn=users, dc=company,dc=org

    855640 wrote:
    I run into issues when the DN of the user to be created already exists and I would like to know if anyone has some logic I can use to generate a different DN for new user by adding a number or something like that to the DN
    There are two different questions:
    1. How to generate a sequence of candidates for the name attribute
    2. How to check if a record with the given name candidate already exists in the Active Directory, and hence try the next candidate from the sequence.
    The answer for the first part is usually defined by the policy existing in your organization, in the simplest case you can append sequential integer numbers to the end of the original name.
    The answer for the second question is not so simple if you use are provisioning with MSAD connector.
    There are two places you can put the check:
    -- in the pre-populate adapter for the UD_ADUSER_COMMONNAME field
    -- in the adpADCSCREATEUSER event handler, which is responsible for new AD user record creation.
    Both cases need some coding, since you have to obtain the AD connection and search AD for matching records.
    Pros & cons
    Placing check code in the pre-populate adapter:
    Pros:
    the result is visible in the form, administrator can change the pre-calculated value if he wishes
    Cons:
    you need to have all access to connection parameters, and establish one extra connection
    this is not the way OIM is supposed to work :-(
    Placing check code in the AD user creation task:
    Pros:
    you have all access to connection parameters, and open a connection here anyway
    Cons:
    the result is not present in the form, so no way for manual interaction by administrator here
    BTW: this problem is not only related to DN generation, some other AD attributes (e.g. sAMAccountName, mailNickName, userPrincipalName, mail) should be unique in the AD domain scope.
    Edited by: madhatter on Sep 7, 2012 12:02 AM

  • How do I get my Adobe Reader to understand I have an active ExportPDF account?

    I work on a Mac - and when I try to convert a file it tells me my trial subscription is over and sends me to a link to subscribe. However, I already have an active ExportPDF account. How can I get my program to recognize this?

    Red --
    Look at the PDF files you already have on your HD.
    Select one, and then press the letter " i "
    Look down to "Open with."  Change it to "Adobe Reader."
    Then select "Change all."
    So, in the future, all PDFs will open with Adovbe.

  • I purchased some movies off iTunes from my account from my fathers IPad as a gift but didn't realize can not view if not logged with my account. Is there any way to save directly to the IPad (regardless of account)? Or transfer to him so he can view have?

    I purchased some movies off iTunes from my account (but from my father IPad) to download as a gift,
    but didn't realize he can not view if not logged in with my account.
    Is there any way to save directly to the IPad (regardless of account) so he can view?
    Or transfer to his account?
    Or is any was to cancel the recent purchase if can not transfer as I will not watch these myself?

    sure pretty simple.  make a backup of your current settings
    http://support.apple.com/kb/HT1766?viewlocale=en_US
    then restore device from old backup you need pics off of
    then import pics to computer
    http://support.apple.com/kb/HT4083
    you may need to save pics to camera roll first
    then restore the new backup and sync pics back to phone via itunes
    Peace, Clyde

  • 'Public' Active Directory account no longer works w/Tiger?

    We have approx 20 public Macs that all log onto our Windows 2003 server using the same Active Directory account - 'Public'
    This has worked fine until Tiger - Now when we attempt to log onto one of our network drives with this account name I'm told by a pop-up window that the account is either disabled or I've put the password in incorrectly.
    Can anyone confirm if 'Public' cannot be used by a user on Tiger? Is it exclusively for the OS?

    Ran accross this in help file...
    "Mac OS X 10.3 or later: "Invalid user name and password combination" Message When Using Active Directory
    When binding a Mac OS X client computer to Active Directory, the account entered is not validated (resolved) at that time. It is used as entered. If entered incorrectly, you will see an alert message later.
    Symptom
    After configuring the Active Directory Directory Access plug-in, an alert message appears at the client computer that says "invalid user name and password combination."
    Products affected
    Mac OS X 10.3 or later
    Solution
    This happens when an incorrect name and/or password is entered, including a username entered with incorrect syntax.
    The user's login name (also known as "PrincipalName") is required when binding a computer to Active Directory.
    The user can also use the short part of the login name (such as "virginia"). The typical syntax of a login name is similar to "[email protected]".
    Note: If the user's login name has been modified from the default "[email protected]", then the default login name must be used. The modified login name (such as "[email protected]") cannot be used."

  • Active Directory account lockout from OS X Server

    I'm looking for assistance in tracking down why our 10.9 Mac server is constantly trying to use my Active Directory account. I changed my password a week ago and have been getting locked out constantly, and it appears the lockouts are coming from invalid password attempts from this OS X server. However, I don't know why the server would be using my AD credentials since I login to the Mac with an admin account and not my own. The only thing I can think of that may have used my AD credentials is connecting to a network file share at some point in the past, but I wouldn't have saved the credentials and it shouldn't be auto-mapping the share. The Mac itself is bound to Active Directory too.
    I checked the Login Items and there is nothing there. I also reset the keychain to defaults and that didn't help. Does anyone else have any ideas for me to try to narrow down what the OS X server may be trying to use my credentials for?

    So I'm going to guess I'm the only one that's ever had this issue...
    Further digging with Wireshark shows that the OS X server is indeed issuing bind requests using my old AD account credentials multiple times per minute. I tried unbinding and rebinding, but that didn't help. The requests also start right away after a reboot, so whatever is using my credentials is doing so prior to any user logins on the server. Now I'm trying to track down what is actually issuing these requests on the server
    In a span of a few seconds the machine issues three bind requests. The first is
    bindRequest (1) "[email protected]" simple
    Followed by
    bindRequest (1) "<ROOT>" sasl
    then
    bindRequest (2) "<ROOT>" sasl
    Anyone have an idea for me as to how to track down where my user account comes into play? It wasn't used to bind the machine to AD, I didn't see it anywhere in the keychain, and I only have a few apps running on the server, none of which use AD authentication or would request binding.

  • I am no longer able to use my microsoft exchange active sync account

    I have been using my active sync account in my iphone just fine up until last wednesday 6/1/2011.  It keeps saying can't connect to server.  All of the other internet services and mail services work just fine.  I have been on the phone with Comcast making sure all the settings are correct for their active sync server

    I have no advice for the OP but a quick story ....
    Allan Sampson wrote:
    This must be a Comcast business account.
    Yes it is a business account through Comcast and I have one as well. I can not explain this but the exact thing happened to me about one week ago and no matter what I did I could not get it to work after having used it successfully for months.
    I deleted the account and then could not reinstall it. I came home from work and restored my iPad to my backup from the night before and still had no luck with mail except that the mail account was back on my iPad.
    About 36 hours after fighting and trying to reinstall the account - it inexplicably began to work again.

  • How do i add an active email account in outlook to set up icloud

    how do i add an active email account in outlook to set up icloud

    would love to know the answer to the question.  i do have outlook up and running and want to sync it using icloud to all my devices.  thought that installing icloud on my pc would do this - maybe I am wrong.

  • T.Code for viewing list of customers of particular account group - Reg

    Hi,
    Can anyone suggest me T.code to view list of customer of particular account group?
    IS there any other method to view the list of customers in a particular account group?
    Please, it is an urgent requirement.
    Rewards sure
    Regards,
    SP.Balaji
    Message was edited by:
            balaji soundarapandian

    Hi Sai Srinivas,
    Already solved it and thanx for your help
    Regards,
    S.P.Balaji

  • Missing Account information when creating Planned Activity in Account

    Hi Expert,
    When creating planned activity in Account inwebUI, I am expecting that the Account information would be populated in the Account field of a planned activity but it is not. Could you please tell me if this is a SAP standard? Thanks

    Check Partner Determination Procedure of Activity Transaction
    regard,
    vijay.

  • How to change mobile activation email account?

    Mistakenly while making activation of mobile iPhone 4, I entered wrong email address and now its getting problem. How could I change my activation email account, its creating problems in itunes, and other applications?

    Hi there,
    I would recommend taking a look at the article below.
    iOS: Changing the signed-in iTunes Store Apple ID account
    http://support.apple.com/kb/ht1311
    -Griff W.

Maybe you are looking for

  • Strange performance issue

    Hi, I've been programming Java professionally for 10 years and I've seen som weird sh*t over the years, but this one takes the cake: I have a huge complex application that does all kinds of funny stuff with doubles. In a specific test case, one metho

  • Excel output display issue after exporting the report

    Hi All. We are using BI Publisher with Oracle retail for report generation.While exporting report in excel format , after saving the file we are not able to see the data. When we do a Format-->Autoformat and select one of the options, we can see the

  • Bug in auto-increment for MSSQL

    I am using kodo 3.1.0 and have a scenario where I am persisting a new object that uses an auto-increment PK and the database has an on-insert trigger that inserts a log into an audit table. At the database level, what is happing is: 1) kodo calls "in

  • Configuring EM Database Control when database is running on different IP

    OS Solaris DB Oracle 10.2.0.2 The have the following situation: We have a veritas active/passive cluster. This is not RAC. Server name is abc. But the database is running on VIP xyz. How do I configure database control to run on vip xyz. whenever I r

  • PLEASE help me.  I'm new...

    I just purchased my first iMac a few days ago. I was installing an app called My Living Desktop but it seems like something didn't go right. Now I have an image stuck as my wallpaper and I can not get it off. It does allow me to change it to another