ABAP Query : user is not assigned to user group

Hello All,
i have created user group using sq03 and assigned user name for change authorization in 'assign users and infosets'.
But when user tries to run query using sq01 system is giving message 'User XXX is not assigned to any user group'.
I tried every thing but facing same problem.
Could anyone please help me out .
Thanks

I actually assigned the user group to a role in SQ10.  The user is assigned to the role.  I also created a new post under Security which has more detail:
http://scn.sap.com/thread/3198604

Similar Messages

  • Role SAP_J2EE_ADMIN is not assigned to user J2EE_ADMIN

    Dear All,
    I am new to sap...
    I tried installing SAP NETWEAVER 7.X SR3
    While installing i got a error at phase 33 0f 50.
    The error message is CJS-30196  Role SAP_J2EE_ADMIN is not assigned to user J2EE_ADMIN.
    I am here copying the error log below..
    Can some one guide me how to solve this.
    I am using Oracle DB and Java j2sdkfb-1_4_2_24-rev-b06-windows-amd64.
    Mine is a AMD processor.
    Line:-----
    Line:-----
    SAPINST log file
    Line:-----
    Line:-----
    INFO 2011-12-28 14:26:35.453
    Creating file C:\Program Files\sapinst_instdir\NW04S\SYSTEM\ORA\CENTRAL\AS\x.
    INFO 2011-12-28 14:26:35.453
    Removing file C:\Program Files\sapinst_instdir\NW04S\SYSTEM\ORA\CENTRAL\AS\x.
    INFO 2011-12-28 14:26:40.750
    Creating file C:\Program Files\sapinst_instdir\x.
    INFO 2011-12-28 14:26:40.750
    Removing file C:\Program Files\sapinst_instdir\x.
    INFO 2011-12-28 14:26:43.031
    Copied file 'C:/Program Files/sapinst_instdir/NW04S/SYSTEM/ORA/CENTRAL/AS/statistic.xml' to 'C:/Program Files/sapinst_instdir/NW04S/SYSTEM/ORA/CENTRAL/AS/statistic.99.xml'.
    INFO 2011-12-28 14:26:45.625
    Copied file 'C:/Program Files/sapinst_instdir/NW04S/SYSTEM/ORA/CENTRAL/AS/statistic.xml' to 'C:/Program Files/sapinst_instdir/NW04S/SYSTEM/ORA/CENTRAL/AS/statistic.100.xml'.
    WARNING 2011-12-28 14:26:57.656
    Unable to get information about path
    LABEL.ASC\ using GetVolumeInformation. Operating system error message: The filename, directory name, or volume label syntax is incorrect.
    INFO 2011-12-28 14:27:02.875
    Copied file 'C:/Program Files/sapinst_instdir/NW04S/SYSTEM/ORA/CENTRAL/AS/inifile.xml' to 'C:/Program Files/sapinst_instdir/NW04S/SYSTEM/ORA/CENTRAL/AS/inifile.34.xml'.
    INFO 2011-12-28 14:27:03.156
    Execute step
    Component  W2K_ServicePack_Check|ind|ind|ind|ind
    Preprocess  of component |NW_Onehost|ind|ind|ind|ind|0|0|NW_First_Steps|ind|ind|ind|ind|1|0|W2K_ServicePack_Check|ind|ind|ind|ind|2|0
    INFO 2011-12-28 14:27:14.531
    Copied file 'C:/Program Files/sapinst_instdir/NW04S/SYSTEM/ORA/CENTRAL/AS/keydb.xml' to 'C:/Program Files/sapinst_instdir/NW04S/SYSTEM/ORA/CENTRAL/AS/keydb.34.xml'.
    INFO 2011-12-28 14:27:15.125
    Copied file 'C:/Program Files/sapinst_instdir/NW04S/SYSTEM/ORA/CENTRAL/AS/statistic.xml' to 'C:/Program Files/sapinst_instdir/NW04S/SYSTEM/ORA/CENTRAL/AS/statistic.101.xml'.
    INFO 2011-12-28 14:27:15.500
    Execute step createJ2EEAdmin of component |NW_Onehost|ind|ind|ind|ind|0|0|NW_Onehost_System|ind|ind|ind|ind|2|0|NW_CI_Instance|ind|ind|ind|ind|11|0|NW_CI_Instance_Doublestack|ind|ind|ind|ind|3|0
    INFO[E] 2011-12-28 14:27:16.281
    FSL-02077  File system export (share) saploc does not exist.
    INFO 2011-12-28 14:27:16.656
    Removing file C:\Program Files\sapinst_instdir\NW04S\SYSTEM\ORA\CENTRAL\AS\UserCheck.message.
    INFO 2011-12-28 14:27:16.687
    Removing file C:\Program Files\sapinst_instdir\NW04S\SYSTEM\ORA\CENTRAL\AS\UserCheck.jlaunch.
    INFO 2011-12-28 14:27:16.687
    Creating file C:\Program Files\sapinst_instdir\NW04S\SYSTEM\ORA\CENTRAL\AS\UserCheck.jlaunch.
    INFO 2011-12-28 14:27:16.718
    Creating file C:\Program Files\sapinst_instdir\NW04S\SYSTEM\ORA\CENTRAL\AS\UserCheck.log.
    INFO 2011-12-28 14:27:16.828
    Working directory changed to C:\Program Files\sapinst_instdir\NW04S\SYSTEM\ORA\CENTRAL\AS.
    INFO 2011-12-28 14:27:16.828
    Output of F:\usr\sap\D04\DVEBMGS00\exe\jlaunch.exe UserCheck.jlaunch com.sap.security.tools.UserCheck "C:\Program Files\sapinst_instdir\NW04S\SYSTEM\ORA\CENTRAL\AS\install\lib;C:\Program Files\sapinst_instdir\NW04S\SYSTEM\ORA\CENTRAL\AS\install\sharedlib;C:\Program Files\sapinst_instdir\NW04S\SYSTEM\ORA\CENTRAL\AS\install" -c sysnr=00 -c ashost=VIJAYA04 -c client=001 -c user=DDIC -c XXXXXX -a checkCreate -u J2EE_ADMIN -p XXXXXX -r SAP_J2EE_ADMIN -message_file UserCheck.message is written to the logfile C:/Program Files/sapinst_instdir/NW04S/SYSTEM/ORA/CENTRAL/AS/UserCheck.log.
    WARNING 2011-12-28 14:27:47.625
    Execution of the command "F:\usr\sap\D04\DVEBMGS00\exe\jlaunch.exe UserCheck.jlaunch com.sap.security.tools.UserCheck "C:\Program Files\sapinst_instdir\NW04S\SYSTEM\ORA\CENTRAL\AS\install\lib;C:\Program Files\sapinst_instdir\NW04S\SYSTEM\ORA\CENTRAL\AS\install\sharedlib;C:\Program Files\sapinst_instdir\NW04S\SYSTEM\ORA\CENTRAL\AS\install" -c sysnr=00 -c ashost=VIJAYA04 -c client=001 -c user=DDIC -c XXXXXX -a checkCreate -u J2EE_ADMIN -p XXXXXX -r SAP_J2EE_ADMIN -message_file UserCheck.message" finished with return code 3. Output:
    Dec 28, 2011 2:27:26 PM  Info: User management tool (com.sap.security.tools.UserCheck) called for action "checkCreate"
    Dec 28, 2011 2:27:31 PM  Info: Connected to backend system D04 client 001 as user DDIC
    Dec 28, 2011 2:27:42 PM  Info: Called for user J2EE_ADMIN
    Dec 28, 2011 2:27:44 PM  Info: User J2EE_ADMIN exists
    Dec 28, 2011 2:27:46 PM  Info: User can log on with the given password
    Dec 28, 2011 2:27:47 PM  Error: Exception during execution of the operation
    [EXCEPTION]
    com.sap.security.tools.UserCheck$MissingRoleException: Role SAP_J2EE_ADMIN is not assigned to user J2EE_ADMIN
         at com.sap.security.tools.UserCheck.checkUser(UserCheck.java:940)
         at com.sap.security.tools.UserCheck.main(UserCheck.java:268)
         at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
         at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:39)
         at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25)
         at java.lang.reflect.Method.invoke(Method.java:331)
         at com.sap.engine.offline.OfflineToolStart.main(OfflineToolStart.java:81)
    SAPINST Log:-
    Dec 28, 2011 2:27:47 PM  Info: Leaving with return code 3
    INFO 2011-12-28 14:27:47.625
    Removing file C:\Program Files\sapinst_instdir\NW04S\SYSTEM\ORA\CENTRAL\AS\dev_UserCheck.
    ERROR 2011-12-28 14:27:47.640
    CJS-30196  Role SAP_J2EE_ADMIN is not assigned to user J2EE_ADMIN
    ERROR 2011-12-28 14:27:47.734
    FCO-00011  The step createJ2EEAdmin with step key |NW_Onehost|ind|ind|ind|ind|0|0|NW_Onehost_System|ind|ind|ind|ind|2|0|NW_CI_Instance|ind|ind|ind|ind|11|0|NW_CI_Instance_Doublestack|ind|ind|ind|ind|3|0|createJ2EEAdmin was executed with status ERROR ( Last error reported by the step :Role SAP_J2EE_ADMIN is not assigned to user J2EE_ADMIN).
    Line:-----
    Line:-----
    USER CHECK LOG
    Dec 28, 2011 2:27:26 PM  Info: User management tool (com.sap.security.tools.UserCheck) called for action "checkCreate"
    Dec 28, 2011 2:27:31 PM  Info: Connected to backend system D04 client 001 as user DDIC
    Dec 28, 2011 2:27:42 PM  Info: Called for user J2EE_ADMIN
    Dec 28, 2011 2:27:44 PM  Info: User J2EE_ADMIN exists
    Dec 28, 2011 2:27:46 PM  Info: User can log on with the given password
    Dec 28, 2011 2:27:47 PM  Error: Exception during execution of the operation
    [EXCEPTION]
    com.sap.security.tools.UserCheck$MissingRoleException: Role SAP_J2EE_ADMIN is not assigned to user J2EE_ADMIN
         at com.sap.security.tools.UserCheck.checkUser(UserCheck.java:940)
         at com.sap.security.tools.UserCheck.main(UserCheck.java:268)
         at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
         at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:39)
         at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25)
         at java.lang.reflect.Method.invoke(Method.java:331)
         at com.sap.engine.offline.OfflineToolStart.main(OfflineToolStart.java:81)
    Dec 28, 2011 2:27:47 PM  Info: Leaving with return code 3
    Thanks & Regards,
    Vijay...

    Dear All,
    As the installation is not completed i could not login SAP.
    I tried to create user at OS level and assign SAP_J2EE_ADMIN.
    Doing so i am getting an popup saying an object SAP_J2EE_ADMIN cannot be created.
    I am still in the installation phase.
    Below is the User Check Log..
    Dec 28, 2011 2:27:26 PM  Info: User management tool (com.sap.security.tools.UserCheck) called for action "checkCreate"
    Dec 28, 2011 2:27:31 PM  Info: Connected to backend system D04 client 001 as user DDIC
    Dec 28, 2011 2:27:42 PM  Info: Called for user J2EE_ADMIN
    Dec 28, 2011 2:27:44 PM  Info: User J2EE_ADMIN exists
    Dec 28, 2011 2:27:46 PM  Info: User can log on with the given password
    Dec 28, 2011 2:27:47 PM  Error: Exception during execution of the operation
    [EXCEPTION]
    com.sap.security.tools.UserCheck$MissingRoleException: Role SAP_J2EE_ADMIN is not assigned to user J2EE_ADMIN
         at com.sap.security.tools.UserCheck.checkUser(UserCheck.java:940)
         at com.sap.security.tools.UserCheck.main(UserCheck.java:268)
         at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
         at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:39)
         at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25)
         at java.lang.reflect.Method.invoke(Method.java:331)
         at com.sap.engine.offline.OfflineToolStart.main(OfflineToolStart.java:81)
    Dec 28, 2011 2:27:47 PM  Info: Leaving with return code 3
    Thanks & Regards,
    Vijay..

  • Not assigned to user group /SAPQUERY/H2

    Dear Gurus,
    I have assigne Tcode S_PH0_48000510 to a user but when she executes this TCode, she is getting an error that "Username is not assigned to user group /SAPQUERY/H2. How can I resolve this?
    Chansa

    Hi,
    Assign the user name to the relevant user group via SQ03.
    regards,
    Dilek

  • SAP MII 14.0 SP5 Patch 11 - Error has occurred while processing data stream Dynamic Query role is not assigned to the Data Server

    Hello All,
    We are using a two tier architecture.
    Our Corp server calls the refinery server.
    Our CORP MII server uses user id abc_user to connect to the refinery data server.
    The user id abc_user has the SAP_xMII_Dynamic_Query role.
    The data server also has the checkbox for allow dynamic query enabled.
    But we are still getting the following error
    Error has occurred while processing data stream
    Dynamic Query role is not assigned to the Data Server; Use query template
    Once we add the SAP_xMII_Dynamic_Query role to the data server everything works fine. Is this feature by design ?
    Thanks,
    Kiran

    Thanks Anushree !!
    I thought that just adding the role to the user and enabling the dynamic query checkbox on the data server should work.
    But we even needed to add the role to the data server.
    Thanks,
    Kiran

  • Created By User added to Assigned To User when Assigned To User is empty

    I have a requirement to build a runbook activity that will assign the Assigned To User to match the Created By User when the Assigned To User field is empty. However, I am having difficulty pulling both the Assigned To User and the Created By User and keeping
    them on the same data bus to do my update after comparing my Assigned To field.
    Here is the runbook how I have it currently configured.
    High Level Flow
    Get RBA
    Get CR
    Get Users
    Pull the Created By and Assigned To users
    Determine if Assigned To user is Empty
    If Assigned To user is not empty then end
    If Assigned To user is empty then Update CR to have Created By User = Assigned To User then end
    My problem lies in trying to keep both the Assigned To and Created By users on the same data bus so I can have the Create Relationship activity make the assignment. If I put them in sequential order or wrap around the Created By user with the Assigned To
    user, it has issues pulling the Assigned To user. Here is my attempt of keeping the users on the same databus but this fails when trying to pull the 'Assigned To' user - it makes them the 'Created By' user.
    Any help will be appreciated.

    If the Assigned To User is blank then it will not be returned from the get relationship activity since it does not technical exist. What you can do is flatten the data coming from the Get AD Users activity. Then put a filter on the link to only include
    if the Relationship Class does not contain Assigned To User. This will make it so your runbook will only continue if an Assigned To User is not present. Then you can add a second Get Relationship this time to return the value for the Created By user. Again
    you will create a link filter, but have it only include Created By User. Then you can use the data returned from that to set the Assigned To User.
    Matthew Dowst |
    Blog | Twitter

  • ITunes accounts can be accessed under one User but not a second User.

    Hi
    I'm having problems setting up iTunes on a new PC I've recently purchased. On my old PC - (Vista), myself (David) and my wife (Chris) had different Windows Users accounts, both with separate iTunes accounts which we could access with no problems.
    On my new Pc (Windows 7) I have downloaded iTunes and can access my iTunes account with my ID and password when the PC is logged in as 'David' as the User, as can my wife BUT when the PC the PC is logged in as my wife as the  User 'Chris' neither of us can access our iTunes account with our relative ID and passwords. We get the message.. "The iTunes Store is temporarily unavailable. Please try again later.".
    I have seen this sentence on Google and on various forums including this one but cannot find a solution which fits my problem which is our iTunes accounts can be accessed when the PC is logged in under one User but not a second User.
    Has anyone have ideas to attempt to resolve this issue?
    Thank you

    Hi DavidG56,
    If you are having issues connecting to the iTunes Store from one of the user accounts, you may find the following article helpful:
    Apple Support: Can't connect to the iTunes Store
    http://support.apple.com/kb/ts1368
    Regards,
    - Brenden

  • Contacts not assigned to a group

    I've been working on getting my contacts and calendars synced up and going fairly well. Have a completely mixed environment: Outlook 2007, iPad IOS 7.1.2; Android phone and Macbook (10.6.8 but not in the current sync process).
    What I've found after a lot of troubleshooting is that I have duplicate contacts and am trying to figure our how to find and remove them. Now before you just say search for them and remove one of the duplicates, the issue is more complex. First, I am very much a geek so know what I'm doing - that doesn't mean that I don't miss simple things now and again though but please don't assume I've not check to see if it's plugged in and turned on
    I, like most I'd guess, prefer to keep my contacts grouped together. When I first setup the sync, everything was on the iPad as I had manually (wifi/USB) kept the iPad and Macbook synced. Simply setting up the iCloud sync from the iPad was simple enough and never really noticed any issues - doesn't mean it didn't start there though; just didn't see it.
    In Outlook, there is a plugin for iCloud and I have that loaded with no problems. Contacts all came in and the groups all appear to work. If I create a new group in Outlook, I see it on the iPad and phone. If I delete it from the iPad, it's gone everywhere.
    Now to where the duplicates are. When I look at the counts in Outlook - just because it's the easiest place to do it, the total contacts added up from all the groups is 626. The total contacts when I get the properties of the top level is 833
    If I select the top level, I can see the duplicates, if I select the individual groups, there are none. I verified this on the iPad by manually selecting each group rather than the "All Contacts". Doing this, the duplicates are gone. So clearly, at least to me, what has happened is that there are 208 contacts (834-626) that are in iCloud but not assigned to a group. The problem is, I can't see them without selecting "All Contact" and at that point, I won't know which one I'd be deleting and would rather not delete the one that is currently and correctly assigned to the group.
    Hope that gives someone enough details to give me some ideas. I've already though about manually exporting all of the groups one at a time and deleting them until all I have left is "All Contacts"/top level in Outlook and then deleting whatever is left and re-importing all of the groups but would rather not do that unless I have to. I'm guessing the biggest reason this is so hard is that the vCard standard did not fully support groups until v4.0 and Outlook is v2 or v3?
    Thanks in advance.

    I'm not sure there is an easy way to do this.  In addition to the approach you mentioned of exporting the group contacts as vCards (which would probably involve importing them to Gmail so you could export an iCloud-compatible vCard), then deleting the remaining contacts and reimporting the vCards, another option would be to identify the duplicates in the All Contacts list and edit the name of one of each of the duplicate (by, for example, adding a "1" to the last name).  That would allow you to go through your groups and identify which one belongs to the group and which doesn't.  It would still be a tedious exercise though.

  • SAP CRM Error: A number range is not assigned to account group

    Hi Experts,
    We have a stuck BDOC for a BP with "ZEmployee" (custom) role in CRM with error as "Fill in Required fields". We knew this is b'cos one of the mandatory field in not maintained in CRM. After maintaining the mandatory field in CRM; we are re-processing the stuck BDOC and again it is getting into the error message with error "A number range is not assigned to account group Sold-to party".
    We have checked the number range and grouping configuration both in ECC and CRM. But still not able to identify the gaps. Is there a detailed step-by-step approach which can be taken up to resolve the issue.
    Request you quick response.
    Thanks,
    Chaudh.

    HI Chaudh,
    I am facing similiar issue. When i am creating BP in CRM WebUI, I am getting an error message: "Error in Transporting Number Range".
    Could you please share your findings, how you solved your issue?
    Dave

  • BDOC Error: A number range is not assigned to account group Sold-to party

    Hi Experts,
    We have a stuck BDOC for a BP with "ZEmployee" (custom) role in CRM with error as "Fill in Required fields". We knew this is b'cos one of the mandatory field in not maintained in CRM. After maintaining the mandatory field in CRM; we are re-processing the stuck BDOC and again it is getting into the error message with error "A number range is not assigned to account group Sold-to party".
    We have checked the number range and grouping configuration both in ECC and CRM. But still not able to identify the gaps. Is there a detailed step-by-step approach which can be taken up to resolve the issue.
    Request you quick response.
    Thanks,
    Chaudh.

    Hi Chaudh,
    Please find the exact solution here.
    http://wiki.sdn.sap.com/wiki/display/CRM/IssuesduringBusinessPartnerreplicationbetweenCRMandERP
    Cheers,
    Josh

  • Privilege not assigned to user despite being in user_attr

    I gave net_privaddr to a user by using usermod on solaris 10. user_attr was changed as expected and correct defaultpriv was added for the user but when I su to the user and check
    ppriv $$ I don't see the privilege and neither can I bind to privileged ports.
    I believe it is using the correct user_attr as all entries in nsswitch.conf has only files entries.
    What could be the reason? Can anyone tell me how to resolve this problem?
    Edited by: user13755008 on Jan 16, 2011 6:04 AM

    I did not modify any files. I just used
    usermod -K defaultpriv=basic,net_privaddr username
    I then checked in user_attr file and the changes were there.
    When I log in as that user and run
    ppriv $$
    I just see basic privileges in both E and I sets.
    When I try to run apache with this user it says cannot bind to privilege port as expected because net_privaddr. If i change the apache port to say 8080(in httpd.conf) it runs just fine. So the problem is that apache cannot bind to port 80 because the user dosen't have net_privaddr privilege. So, getting the user to have net_privaddr privilege is the problem. And I don't understand why the user is not getting the privilege.

  • I changed an existing abap query ME80FN but not find in production system.

    Hi,
    I have changed an ABAP QUERY  ME80FN for user group SAPQUERY/ME in Dev system via transaction SQ01 & SQ02.
    But when I am searching for same query in Production via transaction SQ01 it is not existing.
    Please give me some inputs.
    Thanks,
    Jwala

    Hi Jwala
    1. Check if that ABAP query is transported to production or not.
    or
    check the versions of the ABAP Query in dev w.r.t Production so that you will know the status of the program in production.
    regards
    PBI

  • Report visible for one user but not for other user

    Hi all,
    We have a situation where a report is visible to one user but not to some other user. What could be the possible explanation for this? Please let me know.
    I need quick responses.
    Thanks in advance,
    Sananda

    Hi Sananda,
    Just assign the saem roles as the other user who can view ..
    You can inform the Auth/basis team and they shud be able to do this..
    The T Code is RSECADMIN>user  Tab>Assignment>user.Display and BView the roles here..
    or goto SU01 and check for the Roles Tab.....
    The New user must have the same roles as that of the other..
    Rgds
    SVU123
    Edited by: svu123 on Sep 22, 2010 7:14 AM

  • WD abap Query - Regarding Edit note

    Hi all,
    On click of one button on main screen, i need pop up screen where i can edit this prepopulate text.
    Assistant Manager (CSM) request/removal
    Organisation reference         : 50158579
    Add or Remove (A/R)           :
    Employee Full Name            :
    TOMI user ID (NOT password)   :
    Employee Personnel No         :
    Effective date                :
    Your Name                     :
    Your contact telephone number :
    Employee must appear on your timesheet before you can apply for them
    to have access. Allow 5 working days. The named employee will then
    be able to complete the timesheet on your behalf using a special
    link from TOMI headed EFORMS.
    User can edit this note and then he will click on Ok button to send this text as Email.
    I  tried to achieve this using text edit element  but not able to achieve this functionality.
    In module pool we can achieve this functionality using function module which call standard editor. But we could not call this in WD abap.
    CALL FUNCTION 'TXW_TEXTNOTE_EDIT'
           EXPORTING
                edit_mode = 'X'
           TABLES
                t_txwnote = note.

    >But we could not call this in WD abap.
    No, function modules that relie on the control framework, SAPGUI, or office integration of course can not be used within the browser only enviornment of Web Dynpro.
    >I tried to achieve this using text edit element but not able to achieve this functionality.
    Please elaborate. What about the TextEdit UI element did not meet your needs?  Do you want more editing/formatting functionality?  Or did you have some other problem. Please describe.

  • Custom User Attributes not visible on user profile in OIM 11g

    hi ,
    As I have created a custom attribute in OIM11g. I am not able to view the attribute after I crate a User in OIM.
    Please help me in solving my issue .
    Thanks
    srikanth

    It's a very basic thing. Just try creating an Authorization Policy and you would know how to do it. For your refernce I am also pasting the excerpt from the same Metalink Article
    After creating the UDF, please follow the below steps to make the UDF visible for modification by an admin user:
    1. Navigate to create a new 'Authorization Policy'as below:
    a. Login to UI and click on Administration
    b. On the top left you will see the Authorization Policy tab
    c. Now click on Create Authorization Policy
    2. Please use the below information to create the Authorization Policy
    a. Name: UDF policy
    b. Entity Name: User Management
    c. Permissionsc. Permissions:
    i. Modify User Profile
    ii. View User Profile
    Please make sure that the UDF is selected in the attributes for these permissions.
    d. Data Constraints: All Users
    e. Policy assignment: All Users
    3. Create a user called "useradmin' and add the below 2 roles:
    a. All Users (This is default)
    b. Identity User Administrators (This will provide the administrative tab to this user so that he can administer other users)
    4. Create another end user called 'testuser1' populations the necessary fields.
    5. Now login as 'useradmin'
    6. Search for a user called 'testuser1' and open the user.

  • Users "redlined" - "Not Found in User Directory"

    We've been having this problem off and on all day:
    In my User list under Admin page on Contribute, half of the
    users have a red slash across their ID and in paranthesis this
    message "Not Found in User Directory". The odd things are that 1)
    they are in AD and active accounts, 2) using CPS console we can
    verify the names and passwords and 3) those using C4 can log in
    just fine. Those using C3 and CS3 seem to be having log-in problems
    - except that I'm running CS3 and administering site, and I can log
    in just fine..
    Any ideas?

    Have you tried using the Transition Mode (Edit, Adminster
    Websites, Compatibility) for all your users, since you are working
    with two versions of Contribute?
    grtz
    Hayo

Maybe you are looking for