Assigning admin role with bulk action

Using IDM 6.0 SP1 on tomcat and oracle db
Using a csv file, I can update users with an admin role only if there are more than one admin roles (pipe delimited)
CSV Header Row:
Command,user,accounts[Lighthouse].adminRoles
CSV Line One:
Update,cramert,Administrator - Second Level Help Desk|Administrator - Security Desk|Administrator - Registration Authority
CSV Line Two:
Update,morrisom,Administrator - Registration Authority
The first update with multiple admin roles works - the second does not...
Thanks,
Mike K

Seems we have documentation on this one:
For a list with one value use:
|List|Administrator - First Level Help Desk
For Merging one value to a List:
|List;Merge|Administrator - First Level Help Desk
Thanks,
Mike K

Similar Messages

  • Don't want to assign Admin role to form with business rule

    Hello,
    I have a business rule assigned to a form in EPMA mode. Currently, I have to assign Admin role to the users in order for them to see the name of rule display on the left side of the panel when the form is opened. How can I have the name of rule display for users without having to assign them as Admin role in EPMA mode?
    FYI .. This same form with attached rule was displaying just fine for these users as I assigned them as regular user (not admin role) under a specific user group folder for Classic mode. These users can change data, click save button, and then the rule would run on save.
    Thank you so much for sharing.

    John .. Thank you so much for your previous reply.
    Here is additional information. I hope it provides a clearer understanding on this issue.
    1) To answer your question - Yes, I used Calc Manager to create the business rule named xyz.
    2) The Shared Services version that I used to provision a test user is 11.1.1.3.24.
    3) Here are the steps that I did for testing:
    step a) in Shared Services - I created a test user named: cashtest (Native status)
    step b) in Shared Services - I provisioned user "cashtest" with the following roles for these categories
    Business Rules -> Server 123 -> Interactive User
    Essbase: Server abc:1 -> Server Access
    Foundation -> Shared Services -> Calculation Manager Administrator -> Planning Calculation Manager Administrator
    Planning -> Forecast -> Administrator
    As you can see under the Planning category for application "Forecast", I had to provision for user "cashtest" as "Administrator" in order
    for user "cashtest" to see the business rule named "xyz" displayed on the left panel when a form was opened.
    Prior to this "administrator" provisioning, I tried to provision the roles of "interactive user or Planner" to user "cashtest" but the business
    rule would not display on the left panel when a form was opened.
    I wonder if this is a software bug.
    Thank so much again for your guidance.
    Edited by: CubeQuestion on May 12, 2010 4:09 PM

  • Add role using bulk action

    I'm trying to add a role to multiple users. I've never used a bulk action before and I can't find any documentation. Can somebody point my in the right direction or help me with the syntax/format of a bulk action file?

    Hi,
    This has to be a csv file.
    Syntax for multiple roles
    command,user,waveset.roles
    Update,userid,Role1|Role2
    Update,userid,Role1
    Syntax for appending
    command,user,waveset.roles
    Update,userid,|Merge|Role1|Role2
    Thanks.

  • Assign remote roles with Federated portals

    Hello all,
    We're trying to implement a federated Portal network using the <i>"Implementing a Federated Portal Network" in Detail</i> document.
    The steps that we have follow successfully are:
    1. Connect to the user repository (Producer and Consumer).
    2. Configure system settings (Producer and Consumer).
    3. Define and Configure producers (consumer).
    4. Set permisions (producer).
    Now we want to assign remote roles to local users in <i>User Administration -> Proxy-to-remote Roles option.</i> But <i>Proxy-to-remote Roles</i> tab doesn't appear in the second level navigation...
    We are working with EP7 SP10.
    Any idea?
    Thanks in advance

    Maybe a clue: According to the Remote Role assigment question, We have a similar problem using the Remote content copy option.
    In the consumer EP, Content Administration -> Portal Content, the Netweaver Content Producers contains the producer connection icon but it's empty. So, the content share can't be done...
    Now... Any idea?
    Thanks!
    Message was edited by:
            Marta Sánchez

  • Interaction  with Bulk Action Task

    We are tyring to provide a "cleaner" interface for our customer when using bulk actions. Does anyone know how to interact directly with the Task that runs the bulk actions? I've looked in the repository thru the BPE and it's not selectable. Thanks!

    Ok, so here's the deal:
    If the command is Create, then use "password.password".
    If the command is Update, then use "global.password" (or "accounts[Lighthouse].password" if only IDM resource password is to be updated).
    It would have been nice to have only one reference for all actions, but I tested this and this is the way it is..
    -Adi
    [www.xpressutils.com|http://www.xpressutils.com]

  • Assigning Admin role or any other role to Unity Connection user

    How do I assign a role to a user. I`ve given them the admin role as an example but can not log in . What is the GUI log on details I should use Alisa, Extension etc but no luck. The password I`m also using is the VM PIN I use to listen
    thanks

    Chris,
    I`ve sorted it now, I was looking for as separate ssection for PIN and password , I  didn`t realise that they are under the same heading but separated by the drop down menu - Web and VM application
    thanks for your help

  • Un-assign Admin Roles

    Hi,
    I am trying to set and remove an Admin Role thru XPress code.
    I am able to assign the Admin role.
    But I am not able to remove it.
    I am using the following code:
    <invoke name='remove'>
    <ref>userview.waveset.adminRoles</ref>
    <s>My Role</s>
    </invoke>
    Can anyone tell me why I am not able to remove the role?

    Try updating userview.accounts[Lighthouse].adminRoles instead.

  • Is there any way to create admin role only for one resource.

    Hi all,
    I am trying to create an admin role with 'update user' capability. But I want to restrict the user(with the admin role) to be able to update a user's attribute only for one resource, The user(with the admin role) should not be able to update the attributes of the other resources which a user have.
    Is there any way to create admin role only for one resource?
    I customized the tabbed user form to show only one resource attribute (deleting the missing fields and adding my tab for the resource) and then assigned this new User Form to the user(with the admin role) in security tab.
    It works fine. But the problem is that if any user(with the admin role) is also admin of some other resource then he/she will not be able to view the other resource attributes.
    Please suggest,
    thanks

    The loop function always repeats the same region so of course the fade is also copied. So option+drag the original region to make a (non clone) copy, fade the first region and loop the second one (which you just copied).

  • No "Admin Roles" or "Capabilities" on the Create User - Security tab

    I have created some Admin roles with full Capabilities for an Organisation (other than Top).
    However, when I login as "Configurator", and attempt to create a user under the "Accounts" tab, I cannot see any of the "Admin Roles" created under the "Security" tab. In fact, the "Admin Roles" or "Capabilities" list boxes somehow disappear altogether.
    Does anyone know what can cause the "Admin Roles" and "Capabililties" list boxes to disappear from this tab?

    Are you using IDM version 7.0 and above? If so, it is a security feature introduced by Sun.
    An administrator can assign an admin-role to a user only when he/she is designated to be the "assigner" of that role. Here's how you do it:
    Go to Security -> Admin Roles tab in the admin console, and click on the role to be assigned
    In the form that opens up, click "Add from Search" in the general tab and search/add the desired account.
    You would expect configurator to be a default assigner to any admin-role, but even this account needs to be configured to be the assigner for each admin-role.
    Hope this helps.
    -Adi
    [www.xpressutils.com|http://www.xpressutils.com]

  • Help required for linking Organization Admin Roles to User Profile in R2

    Hi,
    We are using OIM 11.1.2.0 (Without any patch).
    Current Requirement:
    We have requirement to provide search capability to end users to search/see users of other Organizations in OIM.
    For example: I belong to Org1: UK, So OOTB OIM just support searching/viewing profile of UK Organization users. I can not search/view user info of Org2: Italy.
    To overcome this issue,Oracle has suggested us to add both the following roles in order to see user information of other organization.
    • User Viewer
    • Organization Viewer
    After just logged in using xelsysadm, I can able to assign Admin Roles of each organization to end users.
    We want some API info/ how to automate this assignment to Admin Roles(Which are available to Organization) to end users?
    We went through the APIs available for OIM 11.1.2.0, but could not find any API related to Admin Roles of OIM.
    Please suggest.
    Regards,
    J

    Hi,
    Has any one implemented this method?
    addAdminRoleMembership(oracle.iam.platform.authopss.vo.AdminRoleMembership membership) Add a admin role membership.
    Regards,
    J

  • Role with SPRO for FICO

    Hello SAP EXperts,
    Can anyone tell me how to create a role with SPRO authorization for FICO transactions and roles only. I need to assign a role with which a FICO consultant can do all the customizing related tasks in the development server. Please give some solution.
    I invite your valuable inputs
    Thanks & Regards
    Vanitha
    Edited by: Vanitha badampudi on Oct 21, 2008 1:33 PM
    Edited by: Vanitha badampudi on Oct 21, 2008 1:36 PM

    Hi there,
    The easiest way to get all of the t-codes, is for a customising project to be created in the IMG with all of the relevant IMG activities assigned to it.  (Your FI CO consultant can assist here.)
    Once that has been done, you can go and create a role in PFCG.  Select the menu tab, then select Utilities - Customizing Auth. and it will then ask you to select a customising project.
    Once you've done that, all IMG activities and transactions for that customising project will automatically be entered into the menu.
    You then need to go and maintain and generate the authorisations.
    That's my suggestion.
    Hope you can use it.
    Regards
    Lucille

  • Assign Portal Roles from R/3

    Hi all,
    We've here an EP6 SP14 SR1 with R/3 as data source, this R/3 is used to ESS and MSS implementation on portal. The users are created at R/3 using SU01 and then Logon portal with  this same user. But we've to assign portal roles with portal administrator to have access to menus in portal. There's a way to, when create user in backend we can assign automatically portal roles to the user ?
    We do not have CUA neither LDAP.
    Thanks a lot for help.
    Best Regards,
    Pedro Rodrigues.

    Jörg,
    Thanks a lot, that's very helpfull, now I can see the roles in portal groups. But, we need to use dataSourceConfiguration_r3_rw.xml because when user have to change his own password first time they enter in portal.
    How could we got this authorization ?
    Could we assign to pfcg roles that we pretend to use this authorization ?? What authorization is it ??
    Thanks,
    Best Regards,
    Pedro Rodrigues.

  • Granting an admin rights to view and execute a task with user actions

    I am trying to grant an admin the rights to view and execute a new task that i have created from the search results and user actions applet.
    I have added an auth type to the authorization types configuration object with the following:
    <AuthType name="terminateUser" extends="TaskDefinition,TaskInstance,TaskTemplate"/>
    I created a new task and assigned it this auth type. I then created the new admin group and assigned the following permissions:
    <Permission type='terminateUser' rights='View'/>
    I then added this capability to the admin role to which the user has been assigned. This admin role also has the view user capability and has been assigned to the top level of this organization as a controlled organization.
    I also added the task to the user actions configuration so that the menu item appears in the context menu and on the find users page.
    The user can see all users but cannot see the new task. The only thing that is visible is the "view" menu item.
    I have other users that have lots more capabilites that can execute this task with no problems. I am wondering if the view user capability is the problem or is there some other capability that anyone knows of that I must add in order to allow this admin role to view and execute this task.
    Thanks,
    Ruth

    BTW, the answer is to restart the app server. Duh!
    Ruth

  • Create Organization & assign forms bulk action

    How can you create organizations by a bulk action,
    Is it possible to assign userform & viewuserform along with this bulk action
    As well as is it possible to assign a admin user to each Organisation

    i figure it out by myself, Thought would be of use to someone if required.
    created an xml file .... like below, and import it using the "Configure"- "ImportExport File " from the Administrator UI.
    <?xml version='1.0' encoding='UTF-8'?>
    <!DOCTYPE Waveset PUBLIC 'waveset.dtd' 'waveset.dtd'>
    <Waveset>
    <ObjectGroup name='OU one'> <MemberObjectGroups> <ObjectRef type='ObjectGroup' id='#Top#' name='Top'/> </MemberObjectGroups> </ObjectGroup>
    <ObjectGroup name='OU two'> <MemberObjectGroups> <ObjectRef type='ObjectGroup' id='#Top#' name='Top'/> </MemberObjectGroups> </ObjectGroup>
    <ObjectGroup name='OU three'> <MemberObjectGroups> <ObjectRef type='ObjectGroup' id='#Top#' name='Top'/> </MemberObjectGroups> </ObjectGroup>
    </Waveset
    if u need to add approvers for any of these OUs you can add the tag "Approver" and you can assign forms too along with this .
    The best way to do this is create a test OU with all that you need like approver, form etc...
    and use the same syntax.
    If multiple OUs are created make sure you have the <Waveset> tag in there....
    Thanks NSankar

  • SP12: Auto-provisioning failed for role with action "keep"

    Hi,
    If you want to keep an exisiting role for a user in CUP. It wasn't possible to change the validity of the role. Therefor you have to set parameter 145 value to 1 in database table VIRSA_AE_ERMCONFIG and refresh cache in CUP(solution with SP11).
    But know we have problemes with the auto-provisioning.
    We can enter the other validity of the role and after that the request provisioning failed. In our workflow the request rerouted to the admin because of escape-route settings. All other new roles in the request are assigned well to the user in the backend system.
    Any ideas?
    Many thanks,
    Alexa

    Hi,
    we actually have the same Problem, that changes to the role validity with action "keep" are not provisioned to the SAP system.
    If it is only possible to change the validity with the action "add" it is not possible to limit the validity of a previously unlimited role. Because as you said another role with the new validity dates is simply added to the existing roles.
    The only workaround would be to delete the old role and add a new one with new validity dates. But in my opinion this workaround is not acceptable for the users.
    Best Regards
    Jonas

Maybe you are looking for

  • Importing XML using OWB

    We are developing a new application using Oracle 10g R2. This is a hybrid warehouse/on-line system. Some users will need access to current information (less than 24 hours old) while others will need to access data up to 12 months old. The system will

  • Error 2032 returned after AIR 3.7?

    After the updates on April 10th, our AIR application is giving the same I/O errors from a few years back. HTTP request error: Error: [IOErrorEvent type="ioError" bubbles=false cancelable=false eventPhase=2 text="Error #2032" errorID=2032]. I noticed

  • Printline coordinating

    As of now I have this piece of code: System.out.println("ACTIVE RULES: \t\t\t AVAILABLE COMMANDS: ");                         int n = 25 - str.length();                   String ws= " ";                   String ws_new = "";                   for (in

  • My iPad was at 100% and then it suddenly shut down.

    Once my iPad shut down, I thought my battery died so I sent it in for battery replacement. They also charged my iPad for me. I brought it home and enjoyed my iPad until it completely ran out of charge. I plugged my iPad in and thought it was charging

  • New purchased program from Adobe not working to open attachments in E-Main shown as DOC

    Purchased Adobe program to open DOC attachments--still can't open --need help  {email address removed by  admin}  Have important attachment but Adobe says can't open. What do I need to do? william logan