Add users from several Active Directories in SAP BPC
Hello everybody,
Does anybody know if you can add users from several Active Directories in SAP BPC??
In affirmative case, how can you add several Active Directories in SAP BPC??
Thank you very much.
Best regards,
Fernando
Hi,
We almost have same issue to add users from several Active Directories.
BPC server is in Domain A. We perform to add users from Domain B. Our trusted relation between AD is Domain B approve Domain A (unidirectional).
We cannot get one user which is able to browse both AD. So we install BPC with a user which has rights to browse Domain A and we use another user in COM+ component (OsoftUSerManage) which has right to browse Domain B.
But it is not working : we encounter an issue (access denied) in web administration by adding users from Domain B.
Any idea ?
Env. : BPC 5.1 SP6
Similar Messages
-
Hi am having issues with getting the list of users from the Active Director
Hi am having issues with getting the list of users from the Active Directory, can anyone help me with this!
Hi Jason,
Try this:
1. In Ultiboard select Tools>>Netlist Editor>>Pins, press the Delete button
2. Select all nets in the Select the Net to Delete dialog and then press the Delete button. This will clear all nets in the layout, don't worry all traces, parts are still on the design.
3. Go to Multisim and select Transfer>>Forward annotate to Ultiboard. This will add all nets that you removed back and it should fix the pin problem
Tien P.
National Instruments -
SharePoint 2010 Central Admin to add users from AD from specific Department
Dear All,
I am working on SharePoint Foundation 2010. I have to add users from specific department to a particular site collection.
Please let me know if there is a way to import users from Active Directory based on the 'Department' filed in
SPCA.
Thanks.Is that okay if I share the PowerShell code? Do you have access to Active Directory and can you query information?
Refer this Link
Code
# set site collection owner for all sites...
# 1-2012
Add-PSSnapin Microsoft.SharePoint.PowerShell
# $AccountList is an array of Windows Identities in the format of $AccountList = @("DOMAIN\USERID" , "DOMAIN\USERID2")
$accountList = @(Get-ADUser -Filter {(Department -like '*Ur Needs*')})
#$AccountList = @("LAB\Jack", "Lab\tom", "Lab\dick", "lab\harry")
#this gets an array of objects representing the sites at the IIS level:
$IISSites = Get-SPWebApplication
Foreach($oneIISSite in $IISSites)
#using .Sites, we can get a list of the site collections
foreach ($SharepointSiteCollection in $oneIISSite.Sites)
write-host $SharepointSiteCollection.url -ForegroundColor Cyan
$spweb = Get-SPWeb $SharepointSiteCollection.url
#now we have the website, so lets look at each account in our array
foreach ($Account in $AccountList.samaccountname)
#lets see if the user already exists
Write-host "Looking to see if User " $account " is a member on " $SharepointSiteCollection.url -foregroundcolor Blue
$user = Get-SPUSER -identity $Account -web $SharepointSiteCollection.url -ErrorAction SilentlyContinue #This will throw an error if the user does not exist
if ($user -eq $null)
#if the user did NOT exist, then we will add them here.
$SPWeb.ALLUsers.ADD($Account, "", "", "Added by AdminScript")
$user = Get-SPUSER -identity $Account -web $SharepointSiteCollection.url
Write-host "Added user $Account to URL $SPWeb.URL" -Foregroundcolor Magenta
else
Write-host "user $Account was already in URL " $SPWeb.URL -Foregroundcolor DarkGreen
if ($user.IsSiteAdmin -ne $true)
$user.IsSiteAdmin = $true
$user.Update()
Write-host "$account has been made an admin on $SPWeb.URL" -Foregroundcolor Magenta
else
Write-host "$account was already an admin on $SPWeb.URL" -Foregroundcolor DarkGreen
$SharePointSiteCollection.Dispose()
Note:
First uncomment the second $accountlist add the user manually to test
If you have AD module installed in your SP server you can use
$accountList = @(Get-ADUser -Filter {(Department -like '*Ur Needs*')})
Regards Chen V [MCTS SharePoint 2010] -
Org Tech Admin can add user from other org?
We are currently on a trial run with CIAC, and I am testing User Management with a Organization Tech Admin account (OTA).
To my suprise, when adding user and select "existing user", I can see every account currently on Cloud Portal, and even successfully add user from other organization to my orgnization.
Is there anyway so that OTA can see only the users in their own organization?I've been able to remove the admin role from a site administrator with an OTA.
I know there are issues when you log with an user then logout and relog with another user, CIAC considers that you are still the previous user (I've encountered the issue several times in portlets in the nsapi requests). I don't know if/how those issues are related, but I'd say that logout/login issue were an user has the same rights than the previous users should be fixed.
Changing OTA rights will not change that particular issue.
For the moment, what we've done is create our own servlet for requests to the sql DB, and our own roles for most services.
Let's see what v4 has in store for us. -
How to add user from domain A to a group in domain B
How would you acheive adding a user from domain A to a group that is in domain B via powershell without the Quest cmdlets? I've been trying to figure this out for about a week now. Please let me know if the scripting guy has seen this issue before.
LittleTechHello jrv,
Here's what i was trying to do. The two domains im working with have a trust between them.
1. Create a user in External.Domain.Com
2. Add the user in External.Domain.Com to GroupOne in ExternalDomain2.Domain.com
3. The only knowledge that ExternalDomain2.Domain.Com would have about the account in External.Domain.Com is whatever is in the Global Catalog. Here is what im trying, but it isn't working.
#Connecting to domain PSDrive
New-PSDrive
-Name
ExternalDomain
-PSProvider
ActiveDirectory
-Root
-Server
DC01.Domain.com
cd
ExternalDomain:
#Create user
#Add to ExternalDomain Groups
$UserDN=Get-ADUser-LDAPFilter"(sAMAccountName=$UserID)"
#Connecting to domain2 PSDrive
cd
AD:
$GroupDN="CN=Wireless
Device Users,OU=Wireless,OU=Systems and Technology,DC=External,DC=Domain2,DC=Com"
Add-ADGroupMember-Identity$GroupDN-Members(Get-ADObject-Identity$UserDN.DistinguishedName
-Server"DC01.Domain.com:3268")
Connecting via port 3268 allows me to talk to the global catalog instead of LDAP.
I receive the following message: A Referral was returned from the server
I know that if i connect using [ADSI] i am able to specify that the connection follows referrals, the AD cmdlets seem to not have that function. The Quest AD cmdlets do... I just dont want to have to use third party cmdlets to do what the AD cmdlets should
be able to do in the first place.
THanks,
LittleTech -
File Sharing - Cannot disconnect or add user from Address book
Hi all,
Had a look through the support pages but haven't found an answer to this issue I am having....
I have recently wired a LAN between my macbook and a friends macbook. My problem is that I "connected' to my macbook using my username and password from the other computer. Once the computers were connected (and file share is switched on) he had full access to my hard drive (which was what I expected). However, we are unable to 'disconnect' the file share connection without disabling the file share option within system settings! The password was not saved in his keychain. Whenever we connect the computers he has full access to my drive!
In our case it is simple enough to ensure security as the example is simply to solve, however, the wider implications of not being able to manually disconnect from a source are obvious. Has anyone else encountered this problem?
The second problem I have is that I am unable to added a named user to the 'file sharing' user list. When I choose the user from my address book the mac asks for a password. Once this is entered and accepted the window disappears but no name is added to the file share list!
Apologies if these seem idiot problems but they are slowly driving me mad!!
Message was edited by: Keef_SI have had zero problems with Mail in Snow Leopard - it's been rock solid and very reliable for me.
I sort of cured the AddressBook problem but I have no idea why it works and I am not happy with my fix. What I did was deleted the contents of ~/Application Support/AddressBook and ~/Library/Caches/com.apple.AddressBook and ~/Library/Preferences/com.apple.addressbook.plist. I then rebooted and opened up AddressBook. The database was empty except for Apple and my own card which OSX creates by default. I then attempted to create a new contact and all of my old contacts magically appeared! I then deleted the new test contact and edited the contact I was originally trying to add a phone number to. I then quit address book and re-launched it and the new phone number was still there! I checked console.log and there were no errors reported this time (previously I was getting lots of error messages each time I quit and re-launched AddressBook.
I have no idea where those contacts came from since I cleared out the entire database and the cache, but whatever happened, it seems to work now.
BUGGY! -
How to add users from person or group field in a sharepoint list to sharepoint group
Hi,
How to add users(single or multiple) from person or group field in a sharepoint list to sharepoint group programmatically?
Any suggestions would be appreciated.
Thank you,
AA.Hello,
Use SPGroup.AddUser() method to add user in group. I have just written sample code in notepad so it is not tested:
SPSecurity.RunWithElevatedPrivileges(delegate()
using(SPSite Site = new SPSite(SPContext.Current.Site.Url))
Using(SPWeb Web = Site.OpenWeb())
SPList list = web.Lists["ListName"];
SPQuery query=new SPQuery ();
query.Query = "<Where><Eq><FieldRef Name='Title' /><Value Type='Text'>Test</Value></Eq></Where>";
SPListItemCollection items = list.GetItems(query);
if(items.Count > 0)
foreach(SPListItem item in items)
//Get USers from person or group column
SPFieldUser userField = (SPFieldUser)item.Fields.GetField("Users");
SPFieldUserValueCollection userFieldValueCollection = (SPFieldUserValueCollection)userField.GetFieldValue(item["Users"].ToString());
SPGroup spGroup = spSite.RootWeb.Groups[groupName];//group name
if (users.Count != 0)
bool isUserInGroup = false;
foreach (SPFieldUserValue user in users)
foreach (SPUser item in spGroup.Users)
string itemUserName = item.LoginName;
string UserName = user.User.LoginName;
if (itemUserName == UserName)
isUserInGroup = true;
break;
if (!isUserInGroup)
spGroup.AddUser(user.User);
The above code will query list item and then get users from "Users" column. Now it will check whetehr user is already in group not, if not then add user in group.
http://rajanijilla.blogspot.sg/2012/09/add-users-to-group-programmatically.html
Hope it could help
Hemendra:Yesterday is just a memory,Tomorrow we may never see
Please remember to mark the replies as answers if they help and unmark them if they provide no help -
Powershell Script: Add users from an OU to an AD security Group
Hi
can anybody point me to a link or have a script which I can get a list of users from an OU then put them into an AD security group
RegardsHi - thanks for the info the script didn't run as expected.
What we are trying to achieve is that we have an OU with several child OU's below and we need to capture all user accounts from al OU's and then either be able to export to a CSV or pipe the out put to an AD group
dsquery user "OU=organizationalunit,DC=name,dc=com" -limit 0 >>
filename.txt
with the filename.txt you can do this:
for /f "tokens=* delims= " %i in (filename.txt) do dsmod group "CN=groupname,OU=organizationalUnit,DC=name,DC=com" -addmbr %i
or, just pipe the initial results into the dsmod command:
dsquery user "OU=organizationalunit,DC=name,dc=com" | dsmod group "CN=groupname,OU=organizationalUnit,DC=name,DC=com" -addmbr -
How to stop the users from changing the Decimal in SAP
How to stop the users from changing User Profile
Hai,
It is not possible to restrict SU3 to display, because it has only S_TCODE has the authorization object.
If you really want to restrict users from changing their profile you have to remove the SU3 access and give SU1 or SU2 which gives access only to Personnel details and Parameters.
Hope this helps.
Regards,
Yoganand.V -
Add Users from people picker field to sharepoint group
Hi,
I have created infopath form and added people picker control and then created data connection to add users to sharepoint group.
Used UserGroup webservice and "AddUserToGroup" operation. If I select single user in people picker and click submit button, web service data connection adding user to sharepoint group without any issue but it's not working for multiple users.If
I select multiple users in people picker, web service adding only first user to sharepoint groups. In our company we do not prefer custom coding.
Can anybody help me out to resolve this issue?
Any help or suggestions would be appreciated.
Thank you,
AA.You ll be able to achieve this by placing people picker in repeating table control in the form, below url may help you.
http://infopath.wordpress.com/2013/04/02/people-picker-email-addresses-repeating-tables-infopath-2010/
Sivabalan -
Is their any way to restrict user from overriding the graphs in SAP APO?
Dear All,
As we know, we can copy the graphs to other users using /n/sapapo/sdp_graph. But is their any way to restrict user from overriding the graph to particular user.
Scenarios:
In a project we have super user and semi-super user, whenever super user uses above t-code to copy graph to all users (he has included semi-super user id to target user list) but semi-super user does not want to override his graph by super user.
Do we have such function in APO to restrict?
Hope it is clear to understand.
Regards,
Pravin TikarHi Amol,
thanks,
I have checked SP Note 400434 - Authorizations in APO demand planning Also.
Will check the authorization and will update the same.
regards,
Pravin Tikar -
Email notification for instance activation not working - SAP BPC 7.5
Hello Everybody,
I have a problem with email notification in SAP BPC 7.5.
I want to configure an email notification to whenever an instance is activated.
I have followed one How-To guide and basically I have created and activated a template in SAP GUI with transaction se38 and a program called UJB_MAINTAIN_EMAIL_TMPL.
Also, the web server was configured by systems admin.
But still is not working.
I am completely new with SAP BPC so I donu2019t know what more can I do to solve the problem.
Hope you can help me.
Regards,
NadineYou can greatly improve your chance of receiving a helpful answer to your question if you state the version (MS or NW) of BPC which you are using.
Also notice the sticky [note|Please do not post BPC, SSM or FI/CO questions here!; at the top of this forum whereby we announced new dedicated forums for BPC which are the proper place to post your questions regarding BPC in the future to be able to reach the right audience for your question.
Thanks and best regards,
[Jeffrey Holdeman|http://wiki.sdn.sap.com/wiki/display/profile/Jeffrey+Holdeman]
SAP Labs, LLC
BusinessObjects Division
Americas Customer Solutions Adoption (CSA) team -
How do I create Local Network Home Folders for Users from an Active Directory binding?
My situation is this... I run an iMac lab at my school. I have a server set up to manage the network user accounts in the lab. Currently, I can sucessfully create Local Network Users and log in to them from any of the iMacs. My school has an Active Directory set up for all the students on campus. What I'd like to be able to do is configure the server to allow the students to use their user names and passwords from their school accounts to log in to the iMacs and have it automatically build a network user folder on the server for them to use during the lab.
So far, I have been able to configure access for the Active Directory accounts to use the services on the server, mainly File Sharing, but I cannot figure out how to allow them to log into a user account on the client's machines using their same Active Directory credentials. I have even attempted to allow the user accounts to create mobile accounts, but that's not working out either. Entering indivual network user accounts into the server for every student every semester will be a nightmare. I'm sure there's a way to do it automatically using the exisitng Active Directory structure.
The live server is running 10.8.5 Server still, but I've also got a clone running OS X Server in case it matters. Please help!ok reinstalled everything dns seems to be working have done sudo changeip -checkhostname and it says that both names match but then i started open directory and can't seem to get Kerberos started, i've tried changing it to stand alone then back again but it does nothing. I'm wondering why this would happen? i've tried adding a kerberos record but it doesn't do it just does nothing so i don't know what i'm doing wrong. I wondered if it might be a problem with the two network cards and dns as on ethernet one it is getting the dns name xserve.xxxx.ac.uk (which matches what the college server wants to call us) but on ethernet 2 gets xserve-2.local because it tells me that it already exists on ethernet one and renames it to this. I need to set up NAT so have ethernet coming in on port one and out again on port two. I wonder if my dns is backwards as its got the 192. address the NAT uses but its linked to the ethernet port one dns maybe this is the problem. would this cause open directory not to start kerberos?
-
How can I add user from C program?
I need to add, change, remove users and change passwords from my application on Solaris 2.6.
How can I do it?Hi,
I do not think there is a direct API for accomplishing this.
You can try calling "useradd" through Std C library function
system (3C).
"useradd" has a limitation that you can set/change password. Bundled
with Solaris 2.6 and higher, there is a functionality called
'admuseradd' which allows the passwd to be set on the command line. You will need to install Adminsuite from the 'Solaris Internet
Extension CD' to get the functionality.
Hope this helps.
Thanks,
Gopinath
Sun - DTS. -
Getting error while activating content in sap bpc 10
HI All,
since many days i was facing an issue while loading my BPC portal .
i have applied the below medntioned notes as suggested by SAP
1) 1997203
2) 2025612
i have also tried to activate the content by running program : UJS_ACTIVATE_CONTENT
but after implementing i am getting the attached errors
as a result i am unable to login in bpc front end
getting the message as 500-internal server errror
u have no access to any enviornment
Kindly Suggest
Best Regards
Bhupendra AryaDear Astha,
i have checked all my roles n authorizations
all are the same
i guess thats is not an issue
Best Regards
Bhupendra arya
Maybe you are looking for
-
Can't get Windows 7 to recognize my keyboard, usb drives, nor the mouse pad on my MacBook Pro. Have settup Bootcamp division and loaded Win 7. Apparantly the needed drivers did not load. How do I deal with this issue? Thanks.
-
I can't send any mail from my apple mail account, whether it be one that I want to write or send from a web page. I tried gmail and that didn't work, so now I have a 60 day trial of mobileme and that's not working either. One thing I have noticed whe
-
Button not visible in IE7 until clicked
Perhaps not entirely ADF-related, but we have a login page in our ADF/WebCenter 11g PS5 application. In IE7, the submit button is not shown upon rendering the page, but suddenly appears when the form is submitted when pressing enter. Anyone seen this
-
Sp.Procurement key 40 stock transfer order.
Hi Friends, I am facing typical probelm in post go live stage of the project . Scenario : 2 plants say 'A ' & 'B' both are producing product 'x'. this product contains dependent componenets 'y' it is onle produced in plant A. Hence sp.procurement ke
-
User exit solution for Zprogram
Hello Friends, I have a custom solution in ABAP that I am implementing at a customer. My customer needs a solution or a feature that is very specific to his company. I do not want to change the program that is only for that customer. This will imp