Client setting permission

I created a client setting from CAS for one of primary site, but user from that site with member of  "Operations Administrators" security roles is not able to view/modify the property of this client setting on the Primary
Site server console. When I check the client setting, the security group that user belong to has full control permission to the client setting? Can I know where is wrong? DB permission?
Jason

I'm not sure that I fully understand your question...
If you want to delegate the control of a custom Client Setting to a specific administrator, you will need to do it via RBA.
Create/use a custom scope (not Default) and assign the scope to the custom client setting. Then assign the Security Role (e.g. "Operations Administrators") to the admin user and restrict it to the scope.This is so that the admin only has permissions on client
setting(s) that are linked to the select scope.
more on RBA:
http://blogs.technet.com/b/configmgrteam/archive/2011/09/23/introducing-role-based-administration-in-system-center-2012-configuration-manager.aspx
If the settings "All instances of the objects that are related to the assigned security roles" is working, it could be that you did not create a scope to assign when using another option (e.g. "Only the instances of objects that are assigned to the scpecified
security scopes and collections" or "Associate assigned security roles with specific security scopes and collections").

Similar Messages

  • Error: The user does not exist or is not unique - when setting permission programmatically

    Hi,
    I am custom Sequential workflow in which I am breaking the permission and setting permission to list item.
    I have used the below code for setting Permission:
    SPRoleDefinition oSPRoleDefinition = oSPWeb.RoleDefinitions["RoleName"];
    //Grant permission to Manager
    SPRoleAssignment oSPRoleAssignmentManager = new SPRoleAssignment(strManagerLanID, strManagerEmail, "", "");
    oSPRoleAssignmentManager.RoleDefinitionBindings.Add(oSPRoleDefinition);
    CurrentListItem.RoleAssignments.Add(oSPRoleAssignmentManager);
    I am getting the error as :
    Error: The user does not exist or is not unique.
    How to fix this?
    Thanks

    I think you misunderstood the solution proposed by frederic, what he is suggesting is that the error doesn't come from your code but from the user account
    have you tried with another account ? (maybe the one you are using to log to your environment)
    With this information, it will help us to know if the problem comes from your code or from the user account
    Best regards, Christopher.
    Blog |
    Mail
    Please remember to click "Mark As Answer" if a post solves your problem or
    "Vote As Helpful" if it was useful.
    Why mark as answer?

  • SCC4- Client Role ? in Client Setting

    Hell Friends,
    I need some information on Client's Role Setting in SAP system  in SCC4.
    Which role need to be assigned to each client based on the requirement/purpose in a SAP System ?
    Here, i am giving brief information on the Clients created in our SAP System Landscape.
    SAP ECC DEV System
              100 - Golden Master Client
              110 - Unit Testing Client
              120 - ABAP Development Client
              190 - Sand Box Client
    SAP ECC QAS System
              200 - Integration Testing Client
              220 - Training Client
    SAP ECC PRD System
              300 - Production Client
              310 - Pre- Production Client
    Now, my question is which role is assigned to which Client in "Client Role" setting under SCC4, based on the Purpose of the respected client. ?
    I am waiting for your valuable response.
    Regards
    Bhavik G. Shroff

    Hi Presu,
    Thank you very much for your valuable response. This inforamtion is useful for the Client Setting in SAP System.
    But, I also want specific information for this setting in SCC4.
    Client Role:
                       C Customizing
                       D Demo
                       E Traning/Education
                       P Production
                       S SAP Reference
                       T Test
    Based on my client List, which Client Role need to be assigned to Which Client ,according to their Purpose ?
    Regads
    Bhavik G. Shroff
    Edited by: Bhavik G. Shroff on Jul 11, 2009 12:44 PM

  • Client setting option for Productive solution manager

    Dear all expert,
    I've set in transaction code SCC4 (client setting) for my productive solution manager:
    1. "No changes allowed" for changes & transport for client-specific object
    2. "No Changes to repository and cross-client customizing objs" for cross-client object changes
    However with above setting, when execute Tcode SOLAR01 & edit the structure/document, I am not allowed to save it, getting the error "Changes to Repository or cross-client Customizing are not permitted".
    could anyone please advise what is the correct setting for the solution manager?
    please help
    thank you

    Hi Pradeep,
    User just need to edit/upload new documentation to the project SOLAR01, and this is not allowed because of the system setting
    By the way, do you know any method that I can restrict user to edit the 'Structure' tab, but only allow them to upload & edit the documentation under 'project document' tab?
    the recommendad way will be we always setup the project & complete in development system & then finally transport to productive solution manager without any further changes anymore?
    please advise.
    thank you

  • Question about  SAP client setting when create new connection in CR2008

    Dear All,
    I have a question about SAP client setting in Crystal Report 2008 when I try to create a new connection use SAP OpenSQL(SAP Table,Cluster,or Function).
    I have a SAP IDES environment with 5 clients.
    While I try to create a CR standard report use SAP OpenSQL, I entered 800 into Client field in u201CUser logon credentialsu201D. The connection can be created and I can get table list. After I built a report ,I can not get data from IDES client 800, but I can get data from client 000.
    I am sure client 800 has data.I checked client 800 table with Tcord se16.
    I also did other tests and felt confused a lot.
    Even inexistent client, such as u201C00u201Dand u201C8000u201D can be used for creating connection.
    I just want to know how can I get data from client 800.
    Thanks for your kindly help!
    Wayne

    Dear Ingo,
    Thanks for your reply!
    I am not sure about your suggestion clearly. What's your mean all the authorizations to use CR?
    Maybe I should clarify my operations.
    I logon CR2008 as administrator and created two SAP connections with different client.
    There is a table named "/BEV3/CHBALLG" be showed in these connections.
    I checked  clients "000" and "800" both have data in the table.
    I can use client 000 connection create report and get right data, but the report base on client 800 connection could not get data.
    If change to another table,such as "/SAPDMC/LSOFIL", I can get data both form these connections.
    I found one thing is very weird. Client "00" and "8000" do not exist in my IDES environment, but I can use them for creating connection.
    May I have your further suggestions?
    Wayne

  • ConsoleOne lacking Date/Time-Format-Tab for Client-Setting

    I remember from GW6 the Client-Setting-Tab in ConsoleOne for Date-/Time-Format (for local german format)
    There is a tab with these settings in the GW8-Client, but I cannot find this specific setting in ConsoleOne.
    Any ideas?
    Sincerely
    Karl

    The availability in ConsoleOne with GW6.0 is confirmed. Now, since it seems to be gone with GW8.0, how would someone deal with the need of a central adjustment of this setting? At time I am running through the firm with setting this at the users workplace in the GW8.0-Client under Tools/Options/Calendar/Date-Time with hitting the button "Set to System" (or something like that - I have it in German).
    Sincerely
    Karl
    Originally Posted by laurabuckley
    Hi Karl,
    Personally, I don't recall such a setting in ConsoleOne.
    Sorry, not much use, just confirmation that you are not doing something wrong!
    Cheers,

  • Default mail client setting?

    Since my desktop software was upgraded, everytime I open it...I get the message that "Either there is no defaul mail client or the current mail client cannot fulfill the messaging request.  Please run Microsoft Outlook and set it as the default mail client."
    Problem is...I opened up MS Outlook and it **is** set as the default mail client.....so what gives?  
    Solved!
    Go to Solution.

    Uninstall Desktop Manager:
    http://www.blackberry.com/btsc/microsites/search.do?cmd=displayKC&docType=kc&externalId=KB02206&slic...
    Obtain the latest DM software:
    http://na.blackberry.com/eng/services/desktop/
    Launch your default email client.
    Reinstall DM from the latest download.
    Occam's Razor nearly always applies when troubleshooting technology issues!
    If anyone has been helpful to you, please show your appreciation by clicking the button inside of their post. Please click here and read, along with the threads to which it links, for helpful information to guide you as you proceed. I always recommend that you treat your BlackBerry like any other computing device, including using a regular backup schedule...click here for an article with instructions.
    Join our BBM Channels
    BSCF General Channel
    PIN: C0001B7B4   Display/Scan Bar Code
    Knowledge Base Updates
    PIN: C0005A9AA   Display/Scan Bar Code

  • Basis Changes possible with prod client set to "no changes"

    Hi SAP Basis Experts
    I am busy with an internal security review of a client's SAP Environment and I experienced a query from the client side regarding a finding on SAP Basis Changes - an area I'm not too well versed in. The Client's Change procedures require all changes to be requested by logging it in a notification screen and the classification of the SAP changes according to it being either, small, normal, emergency or basis changes.
    Should the change be classified as basis changes, it bypasses their security procedures  and no authorisation is required for the implementation thereof, it seems, straight into the production environment.
    The Client has the following settings
    Their Global Security Setting (SE06) is set to "Modifiable"
    Cross Client Obj Changes for the Production Client (SCC4) is set to "No changes to repository and cross client customising objs"
    The person performing the basis changes has a development key in the production client (DEVACCESS) along with two others.
    Other than a myriad of security shortcomings my question is this:
    The Basis Administrator argues that he can not make changes to the production environment due to the the "No changes..." setting even if he does have a Developer key.
    1) Is this correct?
    2) What further reports can I ask to validate that this administrator can not make changes without due authorisation?
    3) Is there a report that details which users can make changes to the Client Settings (SCC4)
    Thank you for the assistance!
    Jacques du Plessis

    Hi,
    The Following things needs to be take care in this Activity
    1) No Need to create Another TS for SAP R/3, this will not allow you to create another one.
    2) Just Add the Business system for the Existing TS with Client 216 and also take care abt the Logical System Name here.
    3) Refresh SLD Data Cache in IDEnvironment-
    4) Now Use this New Business System for Communication which is having the New Client and Corresponding LS Name
    REgards
    Seshagiri

  • Any Setting/Permission for GRPO to Restrict Update

    Dear all
       Is there any setting for Restrict permission for update GRN before add,for example user want add GRN only based on Purchase order (Quantity,price,tax,item...)he should edit the GRN,he can only ADD

    hi,
    Make a seperate approval procedure for the GRPO. then he(End User) can add GRPO. but the manager can reject are approve the docuemtns like wise you can restrict the user.
    it means it is draft mode this will not create the journal entry. once the document gets approve then it will create teh journal and inventory gets updated.
    Regards
    Chidambaram

  • Set permission level for views

    I have a list which has some views.
    I am showing one of the view in a list view webpart on a wiki page. I dont want the users to view the other views on this list apart from the view set up on the webpart.
    How do I set the permission levels to achieve the same.
    Many thanks in advance.

    The views can either be personal or public. If the view is public it will be visible to users. You may either need to delete the view or create a new personal view similar to the public view before deleting it.
    Blog | SharePoint Learnings CodePlex Tools |
    Export Version History To Excel |
    Autocomplete Lookup Field

  • Setting permission using java code

    hi all i am writing a code to upload file from the users to the server. i can write the files to the server but after that i cannot change it's permission to read and execute by all. only the server can read and execute it. i talked about this problem with the systems admin and he suggested i include some sort of java code to set the permission to everyone. can any one suggest me what sort of code is helpful in this regard? i am absolutely helpless about this. any help will be appreciated.

    Depends on what you mean. If you want to programatically include/exclude a folder in a, say, File Open dialog that your program displays, then yes, absolutely. If you're asking whether can set an operating system security flag on a folder, then the answer is probably not (at least not without resorting to native code), and it will almost certainly not be portable across different operating systems.

  • Setting permission on a GUI

    Hi,
    I have a question that have bothered me for a few day. I'm developing a GUI and would like to set different permissions on the various parts of the GUI.
    When the GUI is loaded these permissions are read and components who should not be shown will not be created, is there a smart way to do this with the API?
    Solving this with if(buildThis()) { //... } is not nice, have you got any ideas?
    Thanx
    MD

    This is something you will have to handle yourself. Its really not that complex, and if a particular user is not going to see the objects, ever, then theres no point creating them and just setting them invisible. That is a waste of memory. But if you don't ahve the permission level at the beginning, then you'll have to do the setVisible version.
    static final int ADMINISTRATOR = 5;
    int permissionLevel = getPermissioneLevel(user);
    if (permissionLevel > ADMINISTRATOR) {
    buildAdministratorTools();
    etc.. you probably already know all this, but the quick answer is no, the API can't do this for you.

  • How to set permission to export PDF?

    We developed plugin based on Acrobat XI SDK to save PDF as TIFF using example of AVConversionEnumFromPDFConverters
    How can I set PDPermReqObjDoc document permission PDPermReqOprExport to "yes" to always allow conversion?

    Our plugin converts PDF to TIFF automatically. How can we set option not to show pop-up dialog boxes, i.e. not to interact with user?
    So far, we set  kAVConversionNoFlags and for AVConversionConvertFromPDFWithHandler setting use:
         ASCab settings = ASCabNew();
        ASCabPutInt( settings, kExtractImgCmdKeyResolution, kImgResolutionAuto );
        ASCabPutInt( settings, kExtractImgCmdKeyColorSpace, kColorSpaceMonochrome );
        ASCabPutInt( settings, kExtractImgCmdKeyConvFormat, kImgConversionFormatTiff );
        ASCabPutInt( settings, kExtractImgCmdKeyConfigured, true );
        ASCabPutInt( settings, kExtractTiffCmdKeyMonoCompression, kTiffCompressionCCITT_G4 );
        ASCabPutInt( settings, kInsertPagesCmdKeyInsertBefore, kAVPosRelativeToFirst );

  • Lync 2013 client - Set people to "Blocked Contacts" relationship by default?

    We are in the process of implementing Lync Server 2013 (on-premises). We have already implemented one front end pool and one edge pool and successfully tested the basic functionality.  Now we are moving on to configuring the various policies based
    on our requirements. One requirement that has come late in the planning is to prevent people from receiving IMs unless they explicitly allow people to IM them and to have the ability to whitelist IMs from people on an individual basis.  This is a feature
    that was submitted as a requirement by way of our IT HelpDesk manager.
    From what I gather, this could be accomplished if someone had the ability to set the default to the "Blocked Contacts" relationship for everyone instead of "Colleagues".  In my research on how to set that as the default, I found
    a setting "ShowManagePrivacyRelationship" in Set-CsClientPolicy.  I created a new per-user client policy called "TEST" and applied it to myself.  Then I set ShowManagePrivacyRelationShip to $true via PowerShell on the TEST policy. 
    However, even hours after making the change and signing out and back into the Lync 2013 client, I still don't see any change in functionality or new options.
    Now, if I instead sign in with the Lync 2010 client, I can indeed see a "Manage Privacy Relationships" option in a drop-down near the right side of the client which takes me to a view where I can see and move "People in my company" and
    "People in domains connected to my company" pseudo-contacts from the "Colleagues" relationship to "Blocked Contacts" and this accomplishes exactly what we want to do.
    Where can I find the "Manage Privacy Relationship" setting in Lync 2013 client?  If there is no setting called that, how can I accomplish what I am trying to do using Lync 2013?
    I would rather not use the Lync 2010 client, as our HelpDesk technicians all use Windows 8.1 and Office 2013.

    David:
    Yes, I have all of those relationships categories in Lync 2013.  What I am missing is the ability to set the rest of the organization to
    Blocked Contacts by default.  I can do this with the Lync 2010 client using the same user login and the same Lync Server 2013 environment.
    The following image demonstrates the location of the Manage Privacy Relationships option I would like to leverage in Lync 2013.  The image is of the Lync 2010 client.
    https://www.dropbox.com/s/i0g83i9su9e5zox/Manage_Privacy_Relationships.png
    If I click that Manage Privacy Relationships option, I end up on the following screen.  Note that there is a
    People in my company object under Colleagues.
    https://www.dropbox.com/s/kkatgtoexea7evt/Default_Privacy_Relationships.png
    I am able to move that People in my company object to another relationship option.  I moved it to
    Blocked Contacts, as you can see below.
    https://www.dropbox.com/s/956kw0ih15uksgr/People_In_Company_Blocked.png
    As you can see in the following image, after making this change if I do not have a person on my Contacts list, they are unable to IM me.  As you can see in my Lync 2013 client relationships list, no one is in my
    Blocked Contacts list yet the Lync Test Account is being blocked due to the fact that I put People in my company there and haven't added them to my Contacts list.
    https://www.dropbox.com/s/cue09wjj8tidbau/Blocked.png
    After adding the Lync Test Account to my Contacts list, the Lync Test Account is able to IM me.
    https://www.dropbox.com/s/nalju5ia980lc30/Unblocked.png
    I hope these images help make clear that there seems to be a capability present in the Lync 2010 client that I am unable to locate in the Lync 2013 client.  I can't find this
    Manage Private Relationships option anywhere in the Lync 2013 client or any other option that lets me see those People in my company and People in domains connected with my company objects.
    With regards to the EnablePrivacyMode option, I am already aware of it and that is not what we are looking for.

  • How to set permission levels per site collection

    Hello,
    A site collection would have 700 sites , with the same (new) permission levels. Is there a way (apart from programming) to copy these permission levels?
    Thank you.
    Christos

    Hello,
    Check this link
    http://social.technet.microsoft.com/Forums/en-US/bdb82f15-6d9c-47b3-b511-f8e019347895/how-to-set-permissions-to-list-item-sharepoint-programmatically
    Thanks!

Maybe you are looking for