Essbase - Shared Services - Maxl - User creation

Hi,
I have an issue looking similar to [Automating User/Group creation & Assigning filters in Shared Services|http://forums.oracle.com/forums/thread.jspa?threadID=1009127]
When trying to add internal groups to an external MSAD user, I get following messages:
h3. when adding a group to an external user:
h6. alter user 'x29027' add 'GR_GROUP';
Maxl returns:
h6. Statement executed with warnings.
h6. User x29027 does not exist
=> the system does not recognize the user
h3. when trying to create this user first as an internal user
(based the settings from on another external user)
h6. create or replace user 'x29027' identified by 'password' as 'i09740';
Maxl returns:
h6. Statement executed with warnings.
h6. A user/group with the same name (x29027) exist at Shared Services
=> the system does recognize the user in MSAD!
===> both statements seem to be contradictory!!!
h3. Other remarks/thoughts:
- we have two MSAD links (to two different domains), does this matter?
- no difference when addressing users as x29027@MSAD_FIB (a syntax similar to the HSS security report output)
- any possibilities in creating a user internally first (using the 'as' option; to copy settings from another user) and then moving to external? (like alter user 'Test_EDR4' set type external;)
Thanks in advance
Erik
Environment: Essbase 9.3.1.3. with Shared Services

Hi Erik,
When you create an user in Essbase, the user will be created both in Essbase as well as Shared Service,
where as when you create an user in Shared service, the user will not be created in essbase untill you perform refresh.
In your case you can create the external user in Essasbe by using "Create user 'x29027' type external;'.
By this you will be creating the user in Essbase and the particular user is recognised in Essbase.
Now you can add him to any group.
- Krish

Similar Messages

  • Essbase, shared services, projects, users

    I have installed shared services and cnfigured it
    now installed essbase
    EAS
    Provider services
    and configured in the above mentioned manner
    (DID not start essbase and EAS till now)
    when I log into shared services....i see only bussines rules under projects
    no analytical services under unassigned applications.....
    how can i see essbase server in shared services user management console.......
    it might be a basic funda....i am not getting
    help me in solving this....
    Thanks in advance

    Hi,
    Have you converted essbase from native security mode to shared services security.
    In EAS, right click security and choose "Externalize users"
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Essbase - Shared services security , User provison

    Hi,
    I am new to 11.1.1.2 Hyperion version.(worked on 9.3.1) I have some doubts on the user security in 11 version.
    We have Distribution environment setup like Essbase on linux and remainng applications on windows 2003 server. Essbase is also registerd with shared services. Here are my questions.
    1. If I change the Shared services Admin password (default password) will it effects any other applications?
    *2. How to change essbase admin password (default password)?(from foreground we can change first time only)*
    3. I am trying to login into EAS as well as essbase admin user but under essbase I am not able to create New User. The Create users option on security is disabled seems like already externalised. I am not able to get those users who are created in shared services evnthought using Refresh from Shared servcies+ option in essbase.
    4. If I want to a user with only essbase applicatons provisioned what is the procedure.
    Here i followed the procedure. Created xyz user in shared services and provisioned Only Demo applications. trying to loing EAS with xyz credentials login successfull and prompted for essbase credentials with server name , username (Extername authentication) getting failed. If i provide admin password at essbase server leverl i am able to connect and see all applications.
    Please help me on this...
    Regards
    PrakashV

    Hi,
    Is it the base install of 9.3.1 or is it a later version like 9.3.1.3
    I know there have been a number of security issues being addressed since the base version.
    e.g.
    Security. Users are not de-provisioned properly, causing Essbase applications to remain accessible to
    them. [7197541]
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Automagic User Provisioning Essbase + Shared Services

    Hello All,
    I have recently been able to figure out how to use the Shared Services API for 11.1.2 in a previous post:
    Shared Service API Working 11.1.2
    However, all of the user management and provisioning examples work with native users. Has anyone used this API with active directory or LDAP users? Is there some other way (export/import utility)?
    My problem is that I need to be able to script the user management with shared services and have not been able to find much help. In the past, we ran Essbase in standalone mode and were able to handle this via MaxL generating essbase native user accounts. This will no longer work since we want to use shared services when upgrading to Essbase 11.

    After your comments I looked a bit more closely at the DDL for create user. It looks like i need "type external";
    MAXL> create user 'someuser' type external;
    OK/INFO - 1056060 - User [jdp5209] created.
    This is what i want!
    MAXL> create user 'someuser' identified by 'somepass';
    OK/INFO - 1056060 - User [someuser] created.
    This is not what i want, creates Shared Services native user.
    It seems obvious now, but before, shared services (CSS module to essbase) was "external" so the old external is the new native.
    Sorry, new to shared services! This works. Thanks all

  • Installation of Essbase, Shared services and Planning

    Hi,
    I am using Essbase (64 Bit), Shared server and Planning +mandatory component of hyperion:
    Can i install 32 bit applications Planning, Shared services, Analytic Provider on 64 bit OS (windows 2003 EE)
    Regards
    Kumar

    Cross post :- Installation of Essbase, Shared services and Planning
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Porting the Essbase/Shared Services to other landscape.

    Hi ,
    I need to port/refresh the Essbase/Shared Services (11.1.1.1 on Windows) from Development Environment to Test Environments. Both Environments are under different domains and I dont think I can usre LCM. I have already setup the Foudataion/Shared Services and Essbase on Destination Host. Can someone guide me how I can move the Essbase/Shared Services accross these Environment manually. Any document refrence or step by step instruction will be great help.
    Thanks in advance.
    -Samar-

    John,
    I never worked with CSSImportExport. I will be moving Planning Applicatoin, HFM and FMD along with Shared Services and Essbase. Can I use CSSImportExport for HFM/FDM etc. If you can point out to any good working example or doc on CSSImportExport that would be really very helpful to me. In the mean time , I willl be googling arround the internet about it.
    Regards
    -Samar-

  • Essbase Shared Services

    Hi,
    Can any one tell me what are the significant improvements in Essbase Shared Services with the new Essbase 11.1.1 version over the Essbase System 9?
    If anybody know this, Please let me know. It will be a great help to me.
    Thank you very much

    For all those people that like to read about the latest version of Oracle Essbase.
    http://download.oracle.com/docs/cd/E12825_01/index.htm
    Brian Chow

  • Sync Shared Services External users & Provisioning for Essbase Applications

    Hi Experts !!
    i have externalised user authentication in Shared services . I provisioned all users for Essbase and refresh the security from Essbase ,So all users are working fine
    and can login in Essbase and "Excel add-in" as well..
    but there is one user who is still not working for "Excel Add in"..
    Error is "Login failed due to invalid login credentials"
    Please suugest me the solutions
    Thank you.

    Hi John !
    Yes, User can login in EAS .
    Also User is available under Users in EAS ,But no applications are displaying in Analytic Server , While I have given Administration Privileges for Essbase app.
    But still error while login in Excel add in ..
    Error : Login failed due to invalid login Credentials.
    Also ,After Provisioning , How Can we Sync all all Externalized users from Shared Services itself for All hyperion Projects ???
    Thank you

  • Shared Services Console - User is not authorized for the action

    Hi,
    I have installed Essbase 11.11.3 and configured on Linux. I started EPM and then the Shared Services Console. I created a new group Poweruser and assigned a new user to it. I provisioned the group withall the rights of the admin. This all works.
    When I log on with the new user on the Shared Service Console and go to Essbase Studio Server and click on the Essbase Studio Server application it gives me the message:
    User is not authorized for the action
    This is the same message as I get under the user admin. Can anyone tell me what I can possibly do to make it work.
    The service for EAS is started properly. The one thing that is not configured is HBR.
    Patrick

    Hi,
    What are you trying to achieve, provision a user for essbase studio ?
    EAS is a separate product from Studio.
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Neet to locate the shared services native users in SQL server tables

    Hi All,
    We are using Hyperion Shared services to provision users to essbase, planning and HFM(all version 9.3.1). And we are using SQL server 2000 as the database. We created few native users in shared services and provisioned them to HFM, Essbase and Planning. Now we need to find those native users' information in the underlying SQL tables. I followed the documentation and sync-ed the native to relational tables using shared services, but I cannot see the user info for all the users I have created. I would appreciate if you can suggest me how to find the shared services users' and roles information in SQL tables (in the back end).
    Legards,
    Leo

    Hi,
    There are a number of free Ldap browsers that you can download, e.g.
    http://www.mcs.anl.gov/~gawor/ldap/demo.html
    http://www.ldapbrowser.com/download.htm
    Once you have installed then ldap browser you just need to point it to your Openldap
    Host :- machine with OpenLdap running
    Port :- 58089
    Base :- dc=css,dc=hyperion,dc=com
    User DN :- CN=root,dc=css,dc=hyperion,dc=com
    And just the root password which you can change in HSS in 9.3
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Integrate active directory with Planning/ Essbase shared services security

    Hi All,
    we try to set up MSAD integration for Planning and Essbase 9.3.1.
    Everyting works fine but the accounts that pop up are first and last name in the user field instead of the userid used in windows to login. so in windows i login with mroest but now in Hyperion i have to use Marc Roest.
    DC=NL, DC=xxxx, DC=Corp
    ID Attribute = ObjectGUID
    User DN: CN=Adm Hyperion, OU=xxxx, OU=Utr
    Can anyone please help how to use the samID as defined in MSAD instead of the full name as is now?
    Thanks very much in advance,
    Marc

    Hi John.
    Do you know why OpenLDAP database would not migrate to the unique identity attribute say if I use sAMAccountName for the ID Attribute field on the MSAD User Configuration screen in Shared Service? It will not update the identity in OpenLDAP when I browse it, even after all the services have been restarted, including OpenLDAP and Shared Services...
    Any help would be appreciated.
    Thanks
    .-a furstrated programmer...

  • Essbase - Shared Services security problem

    In a Shared services enabled Essbase server,
    For a user/group can we define different access levels (say Read on one & Write on the other) to different databases belonging to the same application (BSO)?
    If not, Is there any alternative?
    Appreciate your thoughts.
    Thanks,
    Ethan.

    Of course you can.
    If you're on v11, the steps are as follows:
    1) Create a group (I am going to assume groups and usernames).
    2) Provision the group Essbase server access and Read access to My Very Favorite Essbase Database In The Whole Wide World (MVFEDITWWW) -- Sample.Basic. You could get fancy and create a two level group hierachy with the upper level group provisioned ot Essbase server access and the second group Read access to Sample.Basic if you wanted to.
    3) Expand the application groups and drill into Sample. Right click on Sample and pick Assign Access Control.
    4) An Application tab will open up with a Database drop down. Select Basic and check off the box that relates to your group. It will have the role of Read.
    You have just assigned access to Sample.Basic.
    Follow the same steps for Sample.Intl, etc., etc.
    Regards,
    Cameron Lackpour
    P.S. I believe the above holds true for 9.3.1 but the interface looks a little different. I never did it there -- all of my System 9 work was, alas, Planning only.

  • How to connect Essbase/Shared Services 11.1.1.1.3 to LDAP

    Hi,
    I just installed Essbase 11.1.1.1.3 with Shared Services. I have never connected it to a corporate LDAP environment before. I remember in the past version 6/7 etc.. there was a CSS file that needed edited. Is that still the case or do I have to go into Shared Services and configure etc...
    Thanks

    Hi,
    You configure it all through shared services, have a read of :- http://download.oracle.com/docs/cd/E12825_01/epm.111/epm_security/ch05s05.html
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • One more on Shared Services - Removing Users w/o De-Provisioning

    What happens if a user is removed before it is de-provisioned?
    4-5 users were removed without do any de-provisioning first. Now the users are still appearing in certain areas, but not in default to remove them. Not sure if adding the users back in will tie them to their old SIDs and can then de-provision and remove them entirely or if would have to go through some other effort to remove them completely (which is the end goal). Any guidance on this is very appreciated.
    Thanks!

    You could try using the updatenativedir utility which comes supplied with Shared Serevices found in a rather odd location:
    <hyperion home>\common\utilities\SyncOpenLdapUtility\UpdateNativeDir.zip
    Take a backup of both your HSS Database and OpenLDAP Database before running it, just in case.
    I have never had any bad experiences using it.
    Run it with the -noupdate option to see what it change.
    Have a read of the whole readme, Some Text from the readme....
    Utility to update Hyperion Native Directory with updated data from external
    providers
    Description
    This utility will update external user and group identities in the Hyperion
    Native Directory for those objects that have moved in the external directory.
    This utility will also delete user and group entries from the Hyperion Native
    Directory that cannot be located in the external directory. If the external
    directory cannot be reached due to connectivity issues those user and group
    entries in the Hyperion Native Directory will not be deleted by the utility.
    Please ensure the you provide the same external authentication configuration
    file (CSS.xml) as configured in the Hyperion Shared Services.
    The data related to all the external providers in the search order is
    synchronized. User and group information such as membership, provisioning,
    cache will be deleted from Native Directory if the user or group is not found
    in the external providers.
    After this utility is run, we need to restart HSS so that the cache is
    refreshed and the data updated. The other option is to wait for cache to refresh.
    ...

  • Converting Shared Services (Native) users to MSAD

    Hi All,
    We are on version 9.3.1.
    We have configured FDM with Shared Services and currently only use native users. This means that our FDM users are all authenticated via HSS.
    We are just about to configure an MSAD directory and convert native users to MSAD.
    We will also be configuring FDM with the same MSAD server.
    Does anyone know how FDM handles user migrations? Will FDM automatically pick up MSAD users once they are deleted from the native directory and converted to MSAD?
    Are there any additional steps we need to be aware of??
    Thanks for your help.
    Seb

    Hi,
    Im ok with the config but Im wondering if FDM will be clever enough to convert native users to MSAD.
    Say we have a HSS user called Test1 with a password of Password (the Use Target System field is checked when creating the user in FDM). This user is authenticated against Shared Services when logging on to FDM.
    During the conversation, native users will be deprovisioned and deleted from Shared Services and their provisioning info will be imported against the MSAD provider. At this stage FDM should not be impacted since FDM security is separate from HSS.
    Once I configure the MSAD provider in FDM, my Test1 user will have a password of say Feb2010.
    Will FDM automatically pick up these config changes? Will FDM security for this user remain unaffected?
    Thanks again for your help.
    Seb

Maybe you are looking for