Domain Access Denied - Adding new users

Hi Experts,
I am working on SAP BPC 7.0 MS ver SP04 and am facing an error while adding users.
To Add a New domain user when selecting the domain, I am getting a warning message "Access is denied". 
What could be the reasons behind this or are there any specific rights that need to be checked for access to the Domains? I have earlier added users from the same domain and had no warning message and post that no changes have been made to any user settings.
Any help or guidance / tips very much appreciated.
Regards,
Pankti.

Hi,
Earlier when u had added the users, did u add the users to the same application set or was it for different application set??
Can you please check your task profile. Kindly make sure that you have the appropriate authorizations.
Hope this helps.

Similar Messages

  • Cannot find any domain in the add new user screen in BPC NW platform

    Hi,
    While adding new users in BPC NW, I can't see any value in the Avaialable domains dropdown. Hence I am unable to add any users. I am not sure if I have missed any any step during BPC installation.
    Can anyone please help and suggest the cause of this error and also suggest the remedial action.
    Thanks...

    The BPC Installation guide says:
    Make sure that the server is configured on the domain or a trusted domain by going to My
    Computer --> Properties --> Computer Name --> Change. Make sure the correct domain is specified.
    Also...
    In this step, you define the .NET service user that is needed to log on to ApShell and run Server
    Manager.
    Note
    This user must be a Windows domain user that installs the .NET server component, is a local
    administrator on the machine, has initial access to ApShell (no task security is checked for this
    user), is able to browse the Active Directory, and is used to log on to Server Manager. It can be
    any user that exists on the domain on which the .NET server is installed. You can verify the
    settings in table UJA_SVR_DEFAULT.
    a) Stop the IIS and SAP Business Planning and Consolidation instances using the stoposoft.bat
    file. For more information, see Tips [page 27].
    b) Go to transaction SE38 and run program UJA3_WRITE_SYS_USERS.
    c) Assign a single domain user to all user types:
    BPC SysAdminUser Domain\<user name>
    BPC AdminUser Domain\<user name>
    BPC User Domain\<user name>
    Also...
    The user who creates the initial application set must be the domain user specified in the sysadmin
    field of the UJA3_WRITE_SYS_USERS program.
    Also...
    On the .NET server, check the C:\WINDOWS\system32\drivers\etc\hosts file to ensure that a fully qualified domain
    and an IP resolution exists.
    Thanks and best regards,
    [Jeffrey Holdeman|http://wiki.sdn.sap.com/wiki/display/profile/Jeffrey+Holdeman]
    SAP BusinessObjects
    Enterprise Performance Management
    Regional Implementation Group

  • Error adding new users from local server

    Hello, BPC Gurus,
    We use BPC 7.0 MS SP4, MS SQL 2008 (Server name - BPCP01)
    In Administration Console we're trying to add user from local server (server with SQL Database), and warning window is appeared with message "The Server Is Not Operational [BPBCP01]"
    I checked Logging folder and found message:
    ==============[System Error Tracing]==============
    [System  Name] : OSoftAdminSecurity
    [Job Name]     : frmManageUser::GetAllObjectsFromDomainServer
    [DateTime]     : 2010-12-06 16:58:43
    [Exception]
        DetailMsg  : {System.Exception: The server is not operational [BPCP01]
       at Microsoft.VisualBasic.CompilerServices.LateBinding.LateGet(Object o, Type objType, String name, Object[] args, String[] paramnames, Boolean[] CopyBack)
       at OSoft.Consumers.Admin.Security50.ManageDataSet.GetAllObjectsFromDomainServer(String pDomainName, String pLDAPFullPath, Int32 pDomainObjectType, String pObjectValue, String pDomainType)
       at OSoft.Consumers.Admin.Security50.frmManageUser.GetAllObjectsFromDomainServer(String pDomainName, FILTER_TYPE pOptionType, String pOptionValue, String pDomainType)}
    ===========[System Error Tracing  End ]===========
    Any ideas?

    The installation was done with a local user or with a domain user?
    You know that BPC server can not be in the same time also domain controler.
    Are you using Windows authentication or CMS authentication.
    If you are using CMS authentication then again you can not add local users.
    If you are using Windows authentication then you have to go into server Manager
    Options - Define System User Groups
    Domain Type - Local Windows
    System User Group Name - Local Users.
    If you are using Windows 2008 make sure you addrole to have compatibility with IIS 6.because using this module bpc is adding new users.
    Regards
    Sorin Radulescu

  • How can I give access to a new user for WebView Reporting Log In //IPCC Enterprise

    Hi All,
    How can I give access to a new user for the WebView Reporting Log In ?
    I have IPCC Enterpise 7
    Thanks
    Andres

    Two options: 1. In configuration manager on the AW, use the user list tool to add the users domain account and select Webview access permissions. 2. Using standard Microsoft Active Directory tools or the Cisco Domain Manager tool, add the desired AD user account into one of the "WebView" security groups created within the Cisco OU.

  • Recipient Policies failure when adding new users

    Hi,
    I have some trouble adding new users to my Exchange 2007 setup. I get the message "The Exchange server address list service fail to respond. This could be because of an address list or email address policy configuration error" 
    Of course I Googled around to find solutions, but after trying everything, it still doesn't work. System Attendant just seems to run nice. 
    This is the 8231 message I get in the logs:
    Permanent failure reported by policy group provider for 'CN=Recipient Policies,CN=First Organization,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=[org],DC=local':'MAD.EXE', error=8000ffff.  Taking provider offline.   
    After Googling the error I came across al kind of solutions, however, most of them relate to Exchange 2003. 
    Pretty much the issue here; http://social.technet.microsoft.com/Forums/exchange/en-US/f1c07fe1-451f-4cf4-8b8d-3e0d15376307/the-exchange-server-address-list-service-failed-to-respond-this-could-be-because-of-an-address?forum=exchangesvrgenerallegacy
    Is there any way of recreating the Default Policy? It doesn't work through Management Console. Maybe via ADSI?
    Could anyone help? Thanks a lot. 

    Hi Combo,
    Just check if msexchangeSystemAttendant service is running fine. If not please start System Attendant Service.
    Also try restarting the system attendant service and file distribution service and check if they are already started
    Run ExBPA and see if it throws any errors related to Email address policies which might help
    Increase Diagnostic Logging for MSExchangeAL for below parameters to expert and see if it generates any relevant logs in event viewer
    a)Address List Syncronizataion
    b)Ldap Operations
    If nothing works its better remove and recreate email address policies
    Please mark as helpful if you find my contribution useful or as an answer if it does answer your question.That will encourage me - and others - to take time out to help you.
    Regards,
    Sathish

  • Access denied creating new folders/files as administrator, UAC disabled

    I'm having some issues with a 2008 R2 server. It's a standalone server used for file storage only, no domains no AD or policies have been applied to it.
    I have recently been getting access denied errors trying to create new files or folders on the data drive. I'm logged in as local  administrator and have full access to everything. 
    I've spent the last 3 days searching for a solution but so far have not found one. Solutions so far have almost always suggested turning off UAC and resetting permissions on the affected files and folders but that has not solved the issue, UAC was already
    disabled and I've tried creating a new user group and adding the admin account to it, I've also removed all inherited permissions and manually specified all users and groups and 'everyone' as full access to no avail.
    This did happen once before in the past with one network share and I can't remember what I did back then to solve it but somehow I did, but now all files and folders are having the issue on all network shares and drives (the server has 8 hard drives installed).
    I can move and rename files and folders fine without problems but I cannot create any new folders or files of any kind without getting access denied, I'm really stumped at this one and hoping someone here will be able to suggest a fix that I haven't already
    tried. 
    I have scoured the event logs but there's no sign of the issue there either.
    Any help appreciated.

    Hi,
    Did you access the network drive from a workstation? If so, what is the system operation on the workstation? Please give everyone group “full control” share permission to check the results. You could try to create a new shared folder and give local administrator
    “full control” ntfs permissions and share permissions to check if the issue still exists.
    Best Regards,
    Mandy
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • Adding new Users ,Roles in existing application except jdev

    Dear All,
    I am creating a test application to workaround with adf security, I created some users, enterprise roles and application roles, gave proper mapping to the adf resources(jsf and taskflows), and every thing is working fine. I am doing all this thing in integrated wls server. But suppose if the user wants to create some new users, roles then how will he do this things ?
    I accessed the integrated wls console but got no hints in deployments section-> application->security tab.
    Is there any other way..?
    Regards,
    Santosh
    Jdeveloper 11.1.1.1.2.0

    Hi,
    there is no unified API in ADF Security to manage identities. If you work with the WLS integrated LDAP then you can use OPSS (see Fusion Middleware documentation) and access the JPS factory and provider. If you identities are stored in other system (RDBMS, OID etc.) then you use APIs exposed by these technologies (You may also want to check with Oracle Identity Management to see if there are APIs they expose for this). Because ADF Security does not provide its own identity store, changing users and roles is not in the domain of it (I should say "not yet" as it is on my wish list)
    Frank

  • Access printer by new user Deskjet 1100 series

    I've added a new user to my computer and can't access the printer from the new user's desktop.  

    Attempt this again now, as it should be resolved on the server side. If not let me know.
    Jon-W
    I work on behalf of HP
    Please click “Accept as Solution ” on the post that solves your issue to help others find the solution.
    Click the KUDOS STAR on the left to say “Thanks” for helping!

  • Access Denied for anonymous users

    Hi everybody,
    we have three different anonymous users on the portal. One can access his content without problems. For the other two when trying to access KM-Content like News we get following message
    "Access Denied. The item you are attempting to access requires permisions that you do not have.
    Contact the premissions owner...."
    We gave the permissions in CM to the anonymous users directly and also to the anonymous group.
    The authentication scheme to all pcd objects are on "anonymous" and access ricghts have been granted for all pcd objects. Everything like for the first anonymous user.
    Any suggestions on this?
    Regards

    Hi,
    Try to give permision to Everyone group, all users including anonymous users are present in this group.
    Greetings,
    Praveen Gudapati
    p.s. points are always welcome for helpful answers

  • Error adding new users in Portal 9ias Release 2

    We have just built a new OracleIAS Server using 9.0.2 with Portal installed. Everything works just fine with Portal until I try to add a new user. When I go into the administration section and click on "Create New Users" it returns a page cannot be displayed error.
    The URL it is trying to access is: pls/orasso/orasso.wwsso_app_admin.ls_login
    I cannot find anything in the error_log files for the IAS Server.
    1) Where would I find the errors logged by this process?
    2) Anyone ever seen this before?
    3) Any fixes?
    Richard

    We have just built a new OracleIAS Server using 9.0.2 with Portal installed. Everything works just fine with Portal until I try to add a new user. When I go into the administration section and click on "Create New Users" it returns a page cannot be displayed error.
    The URL it is trying to access is: pls/orasso/orasso.wwsso_app_admin.ls_login
    I cannot find anything in the error_log files for the IAS Server.
    1) Where would I find the errors logged by this process?
    2) Anyone ever seen this before?
    3) Any fixes?
    Richard Richard,
    I'm having the exact problem. I opened a TAR with Oracle, but do not have a resolution for it. Please let me know when you have a solution. I tried starting and restarting the OC4J_DAS service but still have the same problem.
    Thank,
    Long

  • OBIEE access denied for some users only

    Hi All,
    we are using OBIEE 10.1.3.4 version on windows envorinment .The users can access the OBIEE reports using 'PORTALPATH' session varible in RPD.For some of the users are got "access denied" while they are accessing for thir particular dashboard.Eariler these user got access this dashboard with out any errors.We dnt changed in our system anything from last three months.
    We have no idea why we are getting these error for particular users only.Its Prod issue we need to reslove these error ASAP.
    we are getting these error"acess denied for user to path/shared/shared/_test/testdashboard
    Error Codes:09XNZMXB"
    but last one year its working without any issues .From our side we dnt did any changes in production like RPD level,Catalog level and config file changes , we have no idea why suddenly we are getting these kind of error for some users only not for all users.
    Could u please advice me how to reslove this PROD issueASAP.
    Thanks,

    Well its Prod (you have a dashboard called testdashboard in Prod?) anyway - someone might have changed the presentation catalogue permissions on the dashboard. All it takes is for someone to remove 'Everyone' or change a Group permission and it could effect.
    If they changed the Parent folder and cascaded the changes down this might cause this issue.
    You have a folder called 'Shared' - check the groups that the people are in have 'Traverse' , 'Read' or higher. Also chek dashboard permissions themselves from Settings-Manage Interactive Dashboards - Check the Padlock icon.
    Are you users getting allocated into the correct WEBGROUPS ? Is this assisngment done explicitly in the webcat or via an RPD Variable ? Have you checked NQQueryl.log to make sure any init blocks are completing successfully?
    Either persmissions have changed or group memebership is not completing.
    Good luck
    Alastair

  • Adding New User Account

    My parents use an iMac w/Intel Core 2 Duo running Leopard (10.5.4). When they set up the machine initially they set up a single account (we'll call it UserA) - which is the administrator account and the account that both of them use. I know this is a bad practice but this is where I am working from. It had not been a problem for them up until now as my mother's primary use for the computer had been Safari and using RDC to connect to her Windows box at work.
    However, my mother is looking to have her own account set up so that she can have her documents, mail, ect. set up separately. The problem comes in with the apps that they share (i.e. iPhoto, iTunes). I would like both user accounts to see iTunes and iPhoto the same way. The have built up their music and photo collection collectively and would both like to be able to access the same libraries. I have gone as far as creating a new user (UserB) for my mother (as a standard account). I copied her documents from the administrator account (UserA) into her documents folder. What is the best approach to sharing iTunes and iPhoto libraries across the two user accounts? Thank you.

    there are several ways to do that.
    1. the easiest is to enable sharing in both itunes and iphoto. This will allow user A to see libraries of user B and vise versa. However, they won't be able to add stuff to each other libraries. also, this will only work when both of them are logged in at the same time. so you'll have to enable fast user switching in accounts preferences and keep both users logged in.
    2. second easiest. if you have an external drive (or a partition of an internal drive) you can move itunes and iphoto libraries there and turn off ownership on that partition. select the partition, eneter command+i and in the info popup check the box "ignore ownership on this drive" at the bottom.
    after you've moved itunes and iphoto libraries you need to point the apps to the new locations. hold option and start iphoto. You'll get a dialog asking you to choose the library. do the same for itunes.
    3. you can use the method from [ Király 's post in this thread|http://discussions.apple.com/thread.jspa?messageID=2719139&#2719139].
    Skip step 3) that he describes - it's not needed in Leopard.

  • Java API for adding new User in OID

    I am search documentation for sample code to add a new User to the OID via Java API, I could not find any. Is it not possible to do so? if it is, can someone point me to the right location.
    Thanks

       * This method adds employee details into directory
       * @param emp Employee details to be added
       * @param password Password for the employee
       * @exception GroceryAppException if  directory operation fails
      public void addEmployee(Employee emp, String password)
        throws GroceryAppException {
        Map attrs = new HashMap();
        List  objclass = new ArrayList();
        // Object classes that the employee must use
        objclass.add("top");
        objclass.add("inetOrgPerson");
        objclass.add("orcluserv2");
        // create other attributes and their values
        // Add all attributes that you need to set
        attrs.put("uid",emp.getEmpId());
        attrs.put("cn",emp.getFirstName());
        attrs.put("sn",emp.getLastName());
        attrs.put("postaladdress",emp.getAddress());
        attrs.put("mail",emp.getEmail());
        try {
          // create the Directory Entry with the specified attributes
          dirManager.addDirectoryEntry("cn="+emp.getFirstName()+"cn=Users,dc=oracle,dc=com"
                                             , objclass, attrs);
        } catch (NamingException namingEx) { // for Directory errors
          throw new GroceryAppException("Error while adding employee entry to directory :" +
                                      namingEx.getMessage());
      }And the Directory Manager
       * Creates an entry in Directory with the specified attributes and objectclass,
       * with the specified Distingushed Name.
       * @param dn Distinguished name of the entry to be created
       * @param objCls Object classes that the entry must use
       * @param map Attribute,value mappings of the entry
       * @exception NamingException if adding entry fails
       public void addDirectoryEntry(String dn, List objCls, Map map)
         throws NamingException {
          // Create attribute list, ignore case of attribute names
          Attributes attrs = new BasicAttributes(true);
          if( !objCls.isEmpty()) {
            Attribute objclass = new BasicAttribute("objectclass");
            // Iterate thriough the collection and add the object classes to the attribute
            Iterator objclsIter = objCls.iterator();
            while(objclsIter.hasNext()) {
              // Add the object classes
              objclass.add(objclsIter.next());
            // Add the object class attribute to list
            attrs.put(objclass);
          // Iterate through other attributes and add to attributes list
          Iterator attrsIter = map.entrySet().iterator();
          while( attrsIter.hasNext() ) {
            Map.Entry attr = (Map.Entry)attrsIter.next();
            attrs.put(new BasicAttribute((String)attr.getKey(),attr.getValue()));
          // add the directory entry to the directory with the attributes
          dirctx.createSubcontext(dn, attrs);
       }

  • DPS - adding new users

    I have previously added 5 new users in the Account Administration area without problem.
    Today, I have tried to add another address which is also registered and verified as an Adobe ID, but whenever I submit it, I am getting the message 'Sorry! An error has occurred. Please try again'.
    Any suggestions?

    Is the new user's Adobe ID already verified to use with DPS? If so, that could be the problem. Use a valid email address that hasn't been connected yet with DPS.

  • Adding New Users Remotely

    I have a lab of 24 iMacs all running 10.6.3 is there a way to add a new users account to each computer with an id and password? I tried using +Change Client settings+ but that has not worked. I even rebooted but it still did not work.
    Here is a copy of the task I used
    *Enable Remote Desktop.*
    *Enable Remote Desktop menu.*
    *Create users: High School (highschool).*
    *Set privileges: highschool (access: allowed. privileges: all).*

    If the client is already in ARD, the change client settings should work, however you could do this with a couple of unix commands as well.
    to create your user:
    +sudo dscl . -create /Users/highschool RealName "High School"+
    then run kickstart with the appropriate flags.
    +sudo /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources/k ickstart -activate -configure -access -on -users highschool -privs -all -restart -agent -menu+
    The two commands together will create your user and grant them ARD rights, however it does NOT make the account an administrator... to do that you need to append the admin group.
    +dscl . -append /Groups/admin GroupMembership highschool+

Maybe you are looking for

  • How to Turn Off Screen, but NOT Auto-Lock phone?

    I have an iPhone 5S.  I have auto-lock set to 5 minutes.  I often want to shut the screen for a short period (less than 5 minutes) to conserve the battery and to put it in my pocket while making sure I don't do something on the phone.  As such, I pre

  • Socket with Python

    Hi guys, I'm trying to make a socket connection between Flash and Python but, I'm getting a Security Error with policy file. Tried this: Python: import socket serverSocket = socket.socket(socket.AF_INET, socket.SOCK_STREAM) serverSocket.bind(('', 202

  • How to export a JSP page into other formats

    Hi All! Actually, I am generating some dynamic reports using the JSP technology. However, i also want them to be exported into other storable formats like .Doc, .xls or .pdf. Is there any way of doing it? plz help. its urgent. Someone told me this co

  • Trigger button click programatically after a specified time

    I'm trying to make an application that doesn't require the user to make a click on a button, in order for the action to occur. I need this action to occur every 500 ms, but the thing is I don't know how to do this programatically, since I'm new to la

  • Sub-report formatting Question

    Post Author: matthewh CA Forum: General New(ish) to Crystal, running XI and enjoying it. I have a simple landscape report showing the last 7 days summary of jobs from a database that records our daily production, and it simply reports 12 fields acros