Clarification regarding Shared services and essbase security

Hi,
Sorry for the silly doubt. We have shared services to manage security, essbase v 9
1. to assign calc access for users, do i assign calc scripts under databases in group security and assign users to groups in shared services or do it via access control in shared services?
2. If in shared services i havent given calc access but in eas user belongs to a group with that particular calc script access, which would take precedence?
Regards,
N shah

In shared services, when i click on a particular application under the essbase server under the projects folder, there are cases where there are no users or groups under the 'available users and groups'. Why is this so? groups and users are supposed to be there.
Also, in a different application, i saw one available user. however when i try to provide calc access. its not changing anything. I select the calc script and then click the check mark. however nothing changes. The calc access for the user is specified as none. When i login to excel with the same user id, i can see all the calc scripts available for the user. Where are the details being picked up from.??
Edited by: 862089 on Jul 13, 2011 9:55 PM

Similar Messages

  • Regarding Shared Services and Essbase Access

    Hello,
    I am curious on few things regarding how Essbase and Shared services are interlinked.
    Basically we have created Essbase Filters to limit the User access to specific entities , my concern is if a User is trying to Run a report or retrieve through Smart View and if they don't have access to any one of the list of Filter definitions say if there are X , Y ,Z entities in the Spread sheet for Smart View retrieval or in a report and the user does not have privilege for Z do they still get terminated from the entire Essbase Applications. I encountered similar type of problem with one of the users today.
    Any comments.
    Thanks !

    Thanks for the reply Glenn , yes it should not get disconnected or have any connection issue. But below is what the error we get when using Essbase security filter.
    **** Cannot Open Member Selection. Essbase Error(1001064):You do not have sufficient access to perform read on this database ****

  • Shared services and Essbase Sync issue

    Hi,
    Today morning all of sudden lot of users raised an issue that they can't see few applications while connecting through Smart view. I have checked Shared services and the groups are already provisoned. Finally I ran alter system resync sss and after the syncing its fine.
    Any reasons why this morning Syncing was not there.
    Thanks..

    Its fascinating, if the users are provisioned too they can see other applications in smart view and that's what I heard but never checked on it, Is there any possible filters where they cant see it ?
    If so please let me know.

  • Shared Services and Essbase

    Hello All,
    Pretty much an undesired Bug, Basically there is an ID listed as an Essbase admin which yes it was few months back. At present that ID has been removed from Shared Services , also I checked in the list of Essbase Users within EAS and did not find the ID.
    Interesting thing ***** When I exported the Essbase security file I could see that ID listed as an Admin , not sure how it comes up only in Security file but not any where else.
    Is there any issue between Essbase and Shared services communication, because the Essbase should refresh Manually for any changes in the Shared Services.
    Any comments Friends ?
    Thanks !!

    Its probably worth having a read of the following docs in Oracle Support as they should give an idea
    Deleting a User/Group from Shared Services Does Not Delete it from the Essbase Security File [ID 1388447.1]
    How to Delete a User from the 11.1.2.x Essbase.sec File [ID 1396890.1]
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Shared Services and Essbase Server Access Question

    Hi,
    It seems that we have to assign Essbase Server access at the individual username level and that groups don't work when it comes to Essbase Server Access. Is this correct or are we doing something wrong and groups do work with Essbase Server access? We are on 11.1.1.3 Essbase/Planning/Shared Services.
    Thanks

    You can provision Essbase Server Access via groups but it must be the very first thing provisioned and pushed to Essbase. Then after that, provision your groups with other accesses such as Planning, Reports etc....

  • Shared services vs essbase security

    we upgraded from v7 to sys 9 recently..
    when we used V7 essbase security was maintained by maxl scritps..?
    creation of filters granting access and everything was using maxl..
    How can i do the same now?
    I think I cannot grant access to the cube or a filter using maxl anymore?? not sure
    our cube refresh has a cube swap process which I think is done in many companies...
    Can anyone explain the process to have security automated in sys 9

    This is an empty cube that is only used to create the partition to a "back end cube" and support security. The concept of a facade (false front), in cube terms.
    The outline would be a direct match, with security provisioned against it and the partition created as an "all to all" mapping in a "page flipping" approach to one of two alternating back end cubes.

  • Shared services security and essbase security

    recently upgraded to sys 9 and now use shared services 931
    we used to have security at essbase level previously and now its all Shared services..
    now i have so many concerns
    Can we automate the security just like I used to automate in essbase earlier...
    or can we automate secuirty in essbase and them sync it to Shared services??
    I know that we change security settings in SS and then sync it to essbase but is the other way around possible???
    IF yes HOW?
    IF NOT - can we automate SS security which reflects to essbase...
    I have to go through the prod doc and I'll do that very soon but any suggestion on this would really help me out..
    Thanks in advance

    Hi,
    can you please write more about which products and version are you using and on which operating system name and version.
    Why do you use Shared Services? Are you using only Essbase server or any other server? If you use only Essbase server there is probably no need of using Shared Services.
    If you need only Essbase you can see my info about installing Essbase without Shared Services: hyperion essbase installation
    Please provide more info, so that we on forum can help you.
    Regards,
    Grofaty

  • Installation of Essbase, Shared services and Planning

    Hi,
    I am using Essbase (64 Bit), Shared server and Planning +mandatory component of hyperion:
    Can i install 32 bit applications Planning, Shared services, Analytic Provider on 64 bit OS (windows 2003 EE)
    Regards
    Kumar

    Cross post :- Installation of Essbase, Shared services and Planning
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Shared Services and Planning Synchronization

    Ok, this is probably useful for a lot of people, but can anyone articulately explain the relationship between MSAD (or whatever the source security system is), Shared Services, and Planning? There are like 5 utiities and or Web Client buttons that claim to sync different parts to each other.
    MSAD is the source system. It is "plugged into" Shared Services. (Are these always in sync, is there some utility to run to sync them?)
    Then there is this Shared Services "Native Directory" what is this? There is a "Sync Native Directory" button in Shared Services, what does this sync?
    Assuming that SS is synced with MSAD, we then turn to Planning. In Planning, there are "Migrate Identities" and "Remove Non-Provisioned Users/Groups" buttons. What do these buttons sync, and is Migrate Identities the same as the ProvisionUsers.cmd utility?
    I want to know the best way to keep all this in sync, MSAD to SS and SS to Planning. Is any of this automatic, and if I need to run manual utilities, which ones do I need to run and which "buttons" do I need to push.
    thanks
    -Patrick

    Hi,
    Ok here goes, I am not really sure which version you are on because there was a bit of a change between 9.2 and 9.3 with regards to MSAD (uses the ObjectGUID instead of SamAccountName)
    Sync Native Directory - Shared Services contains all the product registration details, OpenLdap (Native Directory) stores all the provisioning, sometimes it is possible they could go out of sync which is pretty rare, so the sync native directory makes sure Shared Services and Open Ldap are in sync.
    Migrate Identities - I think this is more of the line of the updateusers.cmd utility where if a user has changed in the directory (this was more of an issue when SamAccountName was used as users group change OUs in the Active Directory) it will update the planning table with the new details.
    Remove-Non Provisioned Users/Groups - I am sure this doesn't actually work and has been removed in later versions, it is meant to clear up users/groups in the planning tables where there don't exist in Shared Services anymore.
    It depends what you mean by is MSAD always in sync with Shared Services, if you are using 9.3 and configured to use the ObjectGUID then it is pretty much in sync as the id is not likely to change, if you are using SamAccountName and a user moves place in the organisational structure then it can go out of sync. There is another ultilty for that :) (update native directory utility)
    If you run the provision users utility after you have provisioned a user in shared services it will add the user to the planning tables and also push the user to essbase.
    All depends what you are finding is it a problem to what utility to you want to use.
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Regarding Shared Services

    Hi All,
    I have created couple of users in shared services and also i have created a group and provisioned that group with appropriate access.Then i have assigned that users to that group.
    Later i have refreshed from security from shared services.
    But when i see list of users on that server iam unable to find users.
    Any suggestions regarding this issue are most welcome.
    Thanks in advance,
    Ram.

    Hi Cameron,
    I have assigned server access to that group and now iam able to see the user on the user table in EAS.Iam able to log on to the server using Maxl and now the issue is with excel addin when iam trying to log on to the Same box using same id and password iam unale to do that and iam i missing any thing in provisioning.
    During provisioning i have selected
    1)Server Access.
    2)Application manager for the particular application.
    Thanks,
    Ram.

  • Failed cfg on Essbase /Essbase administration service and Essbase / Studio

    Hi Friends,
    I Installed Oracle Hyperion Foundaion services,esbase and planning.
    i deployed essbase in standalone mode.
    when i run EPM system Diagnostic I am geting failes status on
    Essbase /Essbase administration service and Essbase / Studio with the Test Description
    FAILED CFG: Configuration Check whether all configuration tasks have been completed
    Error: Next tasks are not configured:
    hubRegistration: Configuration Failed
    Recommended Action: Try to configure mentioned tasks
    is there any problem because of this?please suggest
    Regards
    DB

    Hi,
    Have you configured Essbase, Shared services and Planning component after installation; were it successful last time.
    Thanks
    Focusthread Hyperion Trainer
    [http://focusthread.com/training]

  • Issue bringing up Shared Services and Planning

    Hi guys,
    We have added 3 new MSAD to our Shared Services for user authentication, previously we already had 2 setup and working fine.
    Now that we added the 3 new ones, we restarted Planning and Shared services and now it doesn't come back up.
    We see the following error message on the logs:
    2009-11-27 17:05:09,702 [Thread-23] WARN com.hyperion.css.spi.impl.msad.MSADCacheUpdater.updateUserCache(Unknown Source) - Ignoring User. Error getting User for User Cache:[LDAP: error code 32 - 0000208D: NameErr: DSID-031001CD, problem 2001 (NO_OBJECT), data 0, best match of:
         'DC=IL,DC=x,DC=Corp'
    2009-11-27 17:05:09,811 [Thread-23] WARN com.hyperion.css.spi.impl.msad.MSADCacheUpdater.updateUserCache(Unknown Source) - Ignoring User. Error getting User for User Cache:[LDAP: error code 32 - 0000208D: NameErr: DSID-031001CD, problem 2001 (NO_OBJECT), data 0, best match of:
         'DC=IL,DC=xx,DC=Corp'
    2009-11-27 17:05:09,936 [Thread-23] WARN com.hyperion.css.spi.impl.msad.MSADCacheUpdater.updateUserCache(Unknown Source) - Ignoring User. Error getting User for User Cache:[LDAP: error code 32 - 0000208D: NameErr: DSID-031001CD, problem 2001 (NO_OBJECT), data 0, best match of:
         'DC=IL,DC=xx,DC=Corp'
    These "xx" we are just using because of the company name but it has the right name
    That's the security log for Shared Services.
    Do you have an idea of what I can do either to bring it up with the new MSAD or delete the newly created and bring it back up?
    Thanks in advance

    Usually your MSAD admins will have a master domain setup that has access to all geographic specific domains. You would have a user setup in this higher level domain
    Let's say you have the following setup:
    na.ad.co.com
    sa.ad.co.com
    eme.ad.co.com
    jp.ad.co.com
    cn.ad.co.com
    You would just need one domain setup at ad.co.com with a user who has read access to that directory. The way Shared Services security is setup you may need to re-provision some users with that new global provider and I highly recommend using a group filter -- your group filter can be in any of the domains just all users would need to be added to it in that domain.
    Regards,
    John A. Booth
    http://www.metavero.com

  • Shared services and workspace login error in epm 11.1.2.3

    Hello,
    When click on the url of shared services and workspace for epm 11.1.2.3
    showing the below error as soon.
    "Internet explorer can not display the webpage error"
    Tried with all supported browsers
    Please suggest all possibles solutions..
    Thanks

    Have you check the logs to make sure all the web apps are up and running and no errors are being generated.
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Shared services and Filter

    Hi Guru's
    how can i assign a filter to a group in shared services. I have created one group in shared services and filter in EAS.Do i have to click on export to shared services ? where in shared services will i see my filter to make it effective on the group
    thank you

    Hi,
    Refer to this thread. The same was discussed there...
    Re: Granting filters without writing maxl

  • Hyperion EPM: Will Oracle Express suffice for Shared Services and Registry?

    Hi.
    I'm trying to install Hyperion EPM on Linux to make use of the Hyperion Interactive Reporting server components to allow report scheduling, web delivery of reports, etc. My data sources will all be MySQL. I'm at the point where I'm attempting to use the EPM Configurator for setting up Shared Services and Registry Database Connection. It seems my options for choosing a database on which to allow Shared Services and Registry data to reside are limited to 3: Oracle, SQL Server or DB2 (noticeably absent is MySQL)
    So, it looks like I'm going to have to install an Oracle DB instance at the very least.
    My question is this:
    Can I get away with just installing Oracle Express for the Shared Services and Registry or will I have to install a full blown Oracle DB instance?
    Thanks
    -- Tom

    Hi, I confirm that you can use Oracle Express for Shared services and registry. We have installed the complete EPM platform on a single virtual machine using Oracle Express. It’s interesting to use it because Oracle Express use less resource. We can run this virtual machine on a computer that only have 4GB of RAM and get good performance (for a single user).
    I recommend using it for proof-of-concept and Bootcamps.

Maybe you are looking for

  • INCOTERMS : Different Incoterms for a Customer by Plant

    Hi there, I have a customer - ABC. ABC's sales orders are fulfilled from 2 Plants - X and Y. X and Y are in two different countries (one in EU, one non-EU). Rerquirement is to have different incoterms based on what plant the customer's sales order is

  • How do I get sound to work on my early 2009 iMac after upgrading to Yosemite?

    The sound on my early 2009 iMac has stopped working after upgrading to Yosemite from 10.6.8. It still makes sound when I boot it up, so I don't think this is a hardware issue.

  • Poor print quality black and white

    I'm using a psc 2410xi "all-in-one"   I've got some old 81/2 x 11 black and white photos I'm trying to copy.  About half the picture comes out great, the other portion is faded or washed out.  I tried changing the black print cartirdge with a new one

  • Work book migration problem : error in graph

    Hi all, I have a work book ,created in 3.x ...now we are on 7.0 So when iam migrating i got error . I have resolved  other errors..but one error is remained , problem with the graph.... on X axis with values it is showing header row also..how can i a

  • Security issues with password retrieval

    Anyone who comes in physical contact with a mac can open and edit as desired, theadmin users that already exist on the machine. I wonder if there is someone who hasa proposed security measures around this problem? For example, if a company wants to u