FPN - End user permission

Namaste all,
I have followed
https://www.sdn.sap.com/irj/scn/go/portal/prtroot/docs/library/uuid/70191d1e-2bd1-2a10-d9b7-ba19500da527
for setting up FPN. But I didn't understand how to assign end-user permission for a person at the consumer portal. Can somebody guide me how to search for a consumer portal user in the producer portal?
Regards,
Krishna Murthy

You should just be able to navigate to User Administration tab in either portal to see the user. You can assign permissions via the PCD explorer. Locate the PCD object you wish to assign permissions to and right click and choose open --> permissions.
This [help guide|http://help.sap.com/saphelp_nw70/helpdata/EN/f6/2604f005fd11d7b84200047582c9f7/frameset.htm] explains it in more details.
Hope this answers your question.
BRgds,
Simon

Similar Messages

  • End user permission ignored

    Hello,
    I have a problem with an end user permission that seems to get ignored: I wanted to demonstrate the usage of the end user permission and assigned a role to a User (for simplicity's sake as an entry point, no worksets, pages etc. involved) and enabled end user permission on the role for that particular user.
    Now when that user logs in he gets to see the according entry in the navigation bar as expected. However if I disable the end user permission, log out and again log in the user, he stills sees the link. The end user permission setting is simply ignored. Can someone shed light onto this, could there be something wrong with the installation)?
    I don't think this is an issue of permission inheritance (the role permissions are set explicitly anyway) or overlapping permissions due to membership in several groups - the user is only member of the single standard  group 'authenticated users'.
    Regards,
    Sebastian
    P.S. What's the use of a role assignment to a user without end user permission anyway (I mean why the option)? What happens if you don't add permissions on a Role for a certain user at all (I tried it, but the effect is the same as described above - end user permission seem to be irrelevant)?

    Hi Robert,
    thanks for your answer and for the link (and I thought I had read everything). I am not so sure however if I really understand the term 'runtime environment' for a user. I thought runtime vs. design-time meant the difference between the content a user sees when he is actually using the portal and the content an administrator has access to in the portal content catalog, i.e. a meta-environment accessible only through certain tools like the permission editor or similar.
    I don't understand what you want to express with "<i>It's used to restrict ... end user runtime environment</i>" and why the "Page Personalization" is an example.
    I realize that for roles the availability for a user is solely defined by the assignment of that role to the user - end user permissions have no effect on this. Confusing, because I tought this availability (i.e. showing links in the toplevel or detailed navigation) was what was meant by 'runtime environment' but I seem to be wrong here.
    The docu says "<i>for roles the end user permission setting does enable you to define which users/groups/roles are able to preview the role content using the portal design-time tools</i>". Again, I am confused, I thought this was exactly the meaning of design-time environment.
    Great if you or someone else could comment on this..
    Regards,
    Sebastian

  • How to set End User Permission to an iView?

    Hi experts,
    can someone tell me how I can set End User Permission to enabled to an iView?

    Hi there,
    From what I have read you want a user to access an iView without an account. To do this you need to configure the J2EE engine for an anonymous user access and set the iView property for authentication to anonymous.
    Because the user has no account you have to assign any roles you want to use for permissions to the anonymous user account configured for anonymous access.
    There is documentation on help.sap.com on how to configure anonymous access.
    Hope this helps.
    Regards
    Christiaan

  • Administrator and End user Permission

    Hello Everybody,
    How <b>Administrator permission</b> is different from <b>End user permission</b>, i cannot see any major changes if i assign or revoke those.
    2. If i have assigned <b>role assigner permission</b> to a user who does not User administrator or any other administrator rights, how he is able to assign role to other user.
    I have read on help.sap.com, but unable to understand.
    regards
    Santosh

    Hi Santhosh,
    1. The Name itself tells us the Difference .
        "Administrator" ->
           There r 3 types of Admn here
        a) "Content Admn" ( he is the one Who can create Iview / Role ..)
        b) "User Admn" ( he is the one who can Create Users and Assign Roles to the Users)
        c) "System Admn" ( he can change the System Properties ..Like Layout ,sys alias etc )
    and End User is the one who doesn't have any of the Admn Roles . A default user may contain Only EU_ROLE
    2.
       If u r a developer u must have Content Admn
       and for the basis guys must have User Admn and Sys   admn.
    Hope it helps .
    Regds,
    J

  • Regarding end user permission

    Hi Gurus,
    I have three iviews (v1,v2,v3)assigned to a role(RoleAll) which will be assigned to user. The requirement is: certain user can only see certain iviews.
    my notion is:
    another three roles(role1, role2, role3) created, and set the iviews' end user permission enabed to respective role(v1--->role1, v2>role2, v3--->role3), what I expected is : the user with role RoleAll and role1 will see v1.
    user with role RoleAll, role1 and rol2 will see v1 and v2.
    when I implement  like this, the behavior is not as expected.
    Can anyone body guide me?
    Best regards,
    John

    >
    John Wu wrote:
    > I have three iviews (v1,v2,v3)assigned to a role(RoleAll) which will be assigned to user.
    >The requirement is: certain user can only see certain iviews.
    > my notion is:
    > another three roles(role1, role2, role3) created, and set the iviews' end user permission
    >enabed to respective role(v1--->role1, v2>role2, v3--->role3), what I expected is :
    >the user with role RoleAll and role1 will see v1.
    > user with role RoleAll, role1 and rol2 will see v1 and v2.
    >
    Hello,
    Assign iView 1 to Role1, iView2 to Role2 & iView3 to Role3.
    Assign RoleAll to those users who should see atleast one of these iViews.
    Then Assign Role1 to the users who should see iView1. Similarly assign
    Role2 and Role3 to respective users.
    Now use Role Merging concept. Give same merge IDs to all the roles. For
    the user having  two of these roles (for e.g, RoleAll + Role1), will see
    only one merged role...and one iView.
    refer:
    http://help.sap.com/saphelp_nw70/helpdata/EN/53/89503ede925441e10000000a114084/content.htm
    May be you could give it a shot.
    Regards,
    Anagha

  • Unable to see ESS content with an end user

    Hi All,
    When I try to see my ESS content with an end user, it is giving me the following error:
    com.sap.xss.config.FPMConfigurationException: Read of object with ID portal_content/com.sap.pct/srvconfig/com.sap.pct.erp.srvconfig.ess.employee_self_service/com.sap.pct.erp.srvconfig.skills/com.sap.pct.erp.srvconfig.fpmapplications/com.sap.pct.erp.srvconfig.skillsapplication failed.
    Part of the stack trace also says,
    Caused by: com.sapportals.portal.pcd.gl.PermissionControlException: Access denied (Object(s): portal_content/com.sap.pct/srvconfig/com.sap.pct.erp.srvconfig.ess.employee_self_service/com.sap.pct.erp.srvconfig.skills/com.sap.pct.erp.srvconfig.fpmapplications/com.sap.pct.erp.srvconfig.skillsapplication)
    It is coming for all the applications in ESS.
    I think it is a permission issue, so i gave the end user permission to the user in the PCD as well in the directory where all my ess contents have been kept.But still it doesn't work.
    And only when I assign the end user with Admin right, it works which should not be the case.
    Kindly suggest a possible solution for this.Your efforts will be appreciated.
    Regards.

    Hi Friend,
    Could please let me know , how you have solved this issue.
    I am alos facing the same
    " com.sap.xss.config.FPMConfigurationException: Read of object with ID portal_content/com.sap.pct/srvconfig/com.sap.pct.erp.srvconfig.ess.employee_self_service/com.sap.pct.erp.srvconfig.skills/com.sap.pct.erp.srvconfig.fpmapplications/com.sap.pct.erp.srvconfig.skillsapplication failed"
    Thanks in advance
    Seranjeeve

  • End User Permissions

    Hi all,
    can someone please explain to me the meaning or function of the "End-User Flag" in the permission editor of a system which is setup in the portal?
    I'm not sure about the effect of this value.
    Thanks a lot,
    Regards,
    Andreas

    Hi
    End User permissions are available to the user at runtime. This determines what user can see at runtime. To see any object user must have End-user permissions enabled.
    End-user permission affects two area:
    Detail Navigation - If user have end-user permission for an iView then that iView/Page will be visible to user at runtime in Detail Navigation.
    Personalise Option: If user have end-user permission for an iView then that iView is visible to the user in the personalize option available to user through page personalization.
    Regards,
    Ganesh N

  • SCSM 2012 SSP Permission for End users

    Hello Experts,
    I have an issues with SSP - SCSM 2012 SP1.
    As an admin user, I can see theOfferings, see the pending requests, can see the requests I have submitted, Approve them etc. But when I am an end user, browsing from my laptop, I see a blank Home page. I dont see the Service offerings in the
    homepage..even I dont see the Need Help? text. What is the issue? FYI : Silver light is already installed on my laptop.
    Interestingly, I see the Need Help? text with the same end user credential when I am opening the browser inside the server wher SSP is installed.
    But, in both the cases, whether I browse in the server or from my laptop, I dont see the service offerings anywhere when i am an end user. I followed the below article..but no success.. :(
    http://systemcentertech.com/2012/06/28/scsm-2012-portal-service-catalog-empty-for-end-users/
    Please help...
    Thanks!
    Thanks

    Hi,
    Did you add the Service Offerings and Request Offerings to the Catalog Group? Here is another good blog on this you can reference:
    http://www.concurrency.com/blog/scsmportalpermisions/
    My Blog | www.buchatech.com | www.systemcenterportal.com
    If you found this post helpful, please give it a "Helpful" vote. If it answered your question, remember to mark it as an "Answer". This posting is provided "AS IS" with no warranties and confers no rights! Always test ANY suggestion
    in a test environment before implementing!

  • Is there a way for end users to give their manager access to change their Out of Office, without an admin involved?

    Our end users need to be able to give their managers access to enable their out of office. 
    question 1.  Can this be done without giving them full access?
    question 2.  If they need full access, can the end user themselves give this access? (I've tried giving another user "owner" rights, but the user still can't seem to open my calendar from OWA to adjust my out of office)
    question 3.  Can this be done without an Sys Admin being involved?

    You can create a RBAC role for each manager scoped to each of their employees that lets them run the Set-MailboxAutoReplyConfiguration cmdlet on the exchange server. Otherwise they will need full access to the users mailbox which an admin would have
    to grant, the end user can not grant this permission. Then they can open the other users mailbox in OWA and set the OOF
    DJ Grijalva | MCITP: EMA 2007/2010 SPA 2010 | www.persistentcerebro.com

  • SP2013 WF works for admin but not end-users

    A simple SP2013 WF calls a SP2010 WF to send email, simple.  Works for me (admin) but when a SP user edits an item on the list (which fires the WF), the WF gets to the 2010 call, and fails with this error...
    RequestorId: f8c56627-e4e5-5a26-0000-000000000000. Details: An unhandled exception occurred during the execution of the workflow instance. Exception details: System.ApplicationException: HTTP 401 {"Transfer-Encoding":["chunked"],"X-SharePointHealthScore":["0"],"X-SP-SERVERSTATE":["ReadOnly=0"],"SPClientServiceRequestDuration":["61"],"SPRequestGuid":["f8c56627-e4e5-5a26-97ee-ad70ca4d3291"],"request-id":["f8c56627-e4e5-5a26-97ee-ad70ca4d3291"],"X-FRAME-OPTIONS":["SAMEORIGIN"],"MicrosoftSharePointTeamServices":["16.0.0.2930"],"X-Content-Type-Options":["nosniff"],"X-MS-InvokeApp":["1;
    RequireReadOnly"],"Cache-Control":["max-age=0, private"],"Date":["Wed, 25 Jun 2014 02:44:54 GMT"],"P3P":["CP=\"ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT
    NAV ONL PHY PRE PUR UNI\""],"Server":["Microsoft-IIS\/7.5"],"WWW-Authenticate":["NTLM"],"X-AspNet-Version":["4.0.30319"],"X-Powered-By":["ASP.NET"]} at System.Activities.Statements.Throw.Execute(CodeActivityContext
    context) at System.Activities.CodeActivity.InternalExecute(ActivityInstance instance, ActivityExecutor executor, BookmarkManager bookmarkManager) at System.Activities.Runtime.ActivityExecutor.ExecuteActivityWorkItem.ExecuteBody(ActivityExecutor executor, BookmarkManager
    bookmarkManager, Location resultLocation) Exception from activity Throw If Sequence Sequence TryCatch Sequence Microsoft.SharePoint.WorkflowServices.Activities.RetryForDurationPolicy HTTPPost_WorkflowInterop_EnableEvents WorkflowInterop DynamicActivity<Guid>
    Then If Working Sequence Flowchart Sequence RCSEmailCst.WorkflowXaml_4f7b53dc_968d_4e22_a812_3178e7b01bad
    Spent an hour on phone with M$ support, only to be told it's my fault and I have to re-design my WF...if my WF gets any simpler I'll have to use carrier pigeons to get messages to customers!
    I've Googled the error message, results suggest that User Profile Syn is out of whack but M$ support swears up & down our sync is working fine.
    Anyone?
    Edit to add: we have a hosted implementation of SP2013, NOT on-prem

    Hi  ,
    According to your description, my understanding is that the SharePoint workflow 2013 does not work for end-users in your environment.
    For your issue, it can be a permission for the user initiating the workflow. Please make sure  site feature Workflows can use app permissions is activated. Go to Site actions > Site Settings >
    Site features > Workflows can use app permissions.  Make sure the user is one member of a SharePoint Group.
    Also please  provide more detail information about the error message  to determine the exact cause of the error. You can have a look at the blog:
    http://ranaictiu-technicalblog.blogspot.com/2013/03/sharepoint-2013-workflow-debugdiagnosis.html
    Best Regards,
    Eric
    Eric Tao
    TechNet Community Support

  • Minimal access for the end users to access a page sharepoint.

    I have a list Projects which i have put in a different aspx page by the name ProjectPage.
    I have end users accesing that page where i have applied certian styles for dsplaying in a customized way.
    However, i need to configure their permissions in such a way that they should be able to access any page other than the project page.
    They should not even see the site actions bar and should not be able to access the _layouts/viewlsts.aspx page as well as settings page form the address bar.

    Hello,
    To restrict application page, either you can hide them from UI (but still be accessible by putting direct url) OR create a custom permission and uncheck "view application page" option. Refer this link for more info:
    https://social.technet.microsoft.com/Forums/office/en-US/bc3e9e2e-e606-47a1-ace3-94aadd860e44/is-there-any-way-i-can-disable-site-actions-menu-for-readonly-users?forum=sharepointgeneralprevious
    Hemendra:Yesterday is just a memory,Tomorrow we may never see
    Please remember to mark the replies as answers if they help and unmark them if they provide no help
    (On vacation from 16th Oct to 28th Oct 2014)

  • End users get blank result from VC model calling an R/3 BAPI.

    Hello everyone.
    We have build a VC model calling a Z*BAPI that we built in the R/3 backend.  Everything works fine through DEV and QAS.  However in our production environment when an end user attempts to run the VC application and search for a record they get a blank table result.  However if one of our core support team users runs the application it returns the search result successfully.
    There are no authorizations on the BAPI itself.
    I have tried to trap a security trace (ST01) in PRD but have not been able to capture a security trace for a failed attempt.  There is no dump (ST22) and nothing in the sys log to indicate a problem (SM21).
    Can someone tell me or point me to where I can determine all the authorizations an end user needs in order to run a VC model using a R/3 BAPI?
    We are running on EP 7.0 and ECC 6.0.
    Thanks,
    -Jon

    Hi Shay,
    When you ask "Have you tried adding the user to the permission list?".  Can you be more specific.
    Are you talking about the medium level security zone permissions in System Administration -> Permissions -> Portal Permissions -> sap.com/NetWeaver.Portal/medium_safety
    For the following objects in the medium_safety folder, assign End User permissions:
    com.sap.vc.mmcompiler
    com.sap.visualcomposer
    com.sap.visualcomposer.portalconnector
    If so we have set the permissions to the Authenticated User Group to be "none" and "end-user".
    We have also assigned end user rights to the Everyone group to the following PCD folders...
    Assign End User permissions to VC Role for the following content:
    pcd:portal_content/templates/pages/portalpagetemplate
    pcd:portal_content/templates/pages/wdProxyPage
    pcd:portal_content/templates/layouts/fullWidth
    pcd:portal_content/templates/iviews/wdProxyiView
    It still does not work unless the person has content admin assigned.  Is there any other permissions (ACLs, PCDs, security zones, etc.) that a person needs in order to use a VC model?
    -Jon

  • HT3743 Apple end-user agreement and jailbreaking

    Hi, im not planning on jailbreaking but just wanted to understand where in the end user agreement does it state that jailbreaking voids the warranty?
    Thank you

    Not sure what country you are in or which device you have, but it is pretty much the same across the board. From the USA iPhone 5 warranty:
    http://www.apple.com/legal/warranty/products/iphone-english.html
    This Warranty does not apply: (a) to consumable parts, such as batteries or protective coatings that are designed to diminish over time, unless failure has occurred due to a defect in materials or workmanship; (b) to cosmetic damage, including but not limited to scratches, dents and broken plastic on ports; (c) to damage caused by use with another product; (d) to damage caused by accident, abuse, misuse, liquid contact, fire, earthquake or other external cause; (e) to damage caused by operating the Apple Product outside Apple’s published guidelines; (f) to damage caused by service (including upgrades and expansions) performed by anyone who is not a representative of Apple or an Apple Authorized Service Provider (“AASP”); (g) to an Apple Product that has been modified to alter functionality or capability without the written permission of Apple; (h) to defects caused by normal wear and tear or otherwise due to the normal aging of the Apple Product, or if any serial number has been removed or defaced from the Apple Product.

  • DPM 2012 Failed to update permissions used in end-user recovery

    Hello everyone,
    I'm going to try the clearest way possible to describe the problem.
    Our test server is Windows Server 2012 with DPM 2012 SP1 CU2 (BKP-SRV01) with a Remote SQL server 2012 (PBASC)
    I protected a share folder on a DC on Windows Server 2008 R2 (PAD)
    When I activate End-User Recovery I get a warning in the monitor tab that say this
    Failed to update permissions used for end-user recovery on pad. Permissions update failed for the following reason: (ID 3123)
    DPM is unable to enumerate contents in pad_PartageTest on the protected computer BKP-SRV01. Recycle Bin, System Volume Information folder, non-NTFS volumes, DFS links, CDs, Quorum Disk (for cluster) and other removable media cannot be protected. (ID 38 Details:
    the end user recovery is working, but i do not know if it affect other things. I also get that message when i try to browse on the DPM server when creating a protection group
    When I go see the DPM Server / File and Storage Services / Shares on Server Manager i get  "Failed to retrieve folder permission" in the properties of the Protected server share.
    I tried to search for almost 2 days without finding anything about that particular issue.
    Is there a way (clean way) to fix the issue?
    Thanks in advance for the help!

    Closing for housekeeping.
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread. Regards, Mike J. [MSFT] This
    posting is provided "AS IS" with no warranties, and confers no rights.
    That's not very helpful. I've got the same issue :(
    Comes up for servers where a protection group related to it errors out (recovery point failure usually).

  • Can't submit generic Incident in SM Portal if User is End User

    Hi 
    I have a Testuser who is in the End User Role and i can't submit the generic Incident on the Service Manager Portal if any relationship field (Assigned to , Related Items...) is filled out in the template by default (if blanc it works). 
    I already changed
    p_GetRestrictrictionsOnOperationsInProfile
    p_AddRestrictrictionToOperationInProfile
    p_RemoveRestrictrictionFromOperationInProfile.
    Error in the SMPortalTrace.log is:
    Error,2014-01-21 15:32:55.8929841,Failed to create request.,Microsoft.EnterpriseManagement.Presentation.DataAccess.DataProviderException: Microsoft.EnterpriseManagement.Presentation.DataAccess.DataProviderException: The user Domain\testuser1 does not have sufficient
    permission to perform the operation. ---> Microsoft.EnterpriseManagement.Common.UnauthorizedAccessEnterpriseManagementException: The user Domain\testuser1 does not have sufficient permission to perform the operation.
       at Microsoft.EnterpriseManagement.Common.Internal.ConnectorFrameworkConfigurationServiceProxy.ProcessDiscoveryData(Guid discoverySourceId, IList`1 entityInstances, IDictionary`2 streams, ObjectChangelist`1 extensions)
       at Microsoft.EnterpriseManagement.ConnectorFramework.IncrementalDiscoveryData.CommitInternal(EnterpriseManagementGroup managementGroup, Guid discoverySourceId, Boolean useOptimisticConcurrency)
       at Microsoft.EnterpriseManagement.Common.EnterpriseManagementObjectProjection.CommitInternal(Guid discoverySourceId, Boolean useOptimisticConcurrency)
       at Microsoft.EnterpriseManagement.Common.EnterpriseManagementObjectProjection.CommitInternal(Boolean useOptimisticConcurrency)
       at Microsoft.EnterpriseManagement.ServiceManager.Portal.DataProviders.CreateRequestProvider.CreateRequest(TemplateReader requestDataObject)
       --- End of inner exception stack trace ---
       at Microsoft.EnterpriseManagement.Presentation.DataAccess.DataProviderCommandMethod.Invoke(CoreDataGateway gateWay, DataCommand command)
       at Microsoft.EnterpriseManagement.Presentation.DataAccess.CoreDataGateway.Execute(DataCommand command)
       at Microsoft.EnterpriseManagement.Presentation.DataAccess.Server.DataAccessService.Execute(TransportDataCommand command)
       at SyncInvokeExecute(Object , Object[] , Object[] )
       at System.ServiceModel.Dispatcher.SyncMethodInvoker.Invoke(Object instance, Object[] inputs, Object[]& outputs)
       at System.ServiceModel.Dispatcher.DispatchOperationRuntime.InvokeBegin(MessageRpc& rpc)
       at System.ServiceModel.Dispatcher.ImmutableDispatchRuntime.ProcessMessage5(MessageRpc& rpc)
       at System.ServiceModel.Dispatcher.ImmutableDispatchRuntime.ProcessMessage31(MessageRpc& rpc)
       at System.ServiceModel.Dispatcher.MessageRpc.Process(Boolean isOperationContextSet)
    Anyone an idea how to solve that Problem ?
    Thanks

    Hi Choo Hong
    Thanks for the reply. 
    The User is only in one role and the Generic Incident template is checked. 
    I can see and fill out the generic Incident template.
    The Problem appears when i submit the Incident, and this only if in the template a Group or User is preassigned as Assigned to User (If Assigned to is Blank i can submit the Generic Incident via Portal)
    Regards

Maybe you are looking for

  • I am having a problem viewing YouTube videos in the latest version of Firefox.

    I'm on Firefox 34.0 on a Windows 7 laptop. Up until recently I had no trouble viewing videos on YouTube. I would enter "youtube.com" into the browser address and it would take me to http://youtube.com. But now it takes me to "http://m.youtube.com/?",

  • Hyper-V 2012 R2, integration services issue on multiple VMs

    Hello, I came to you because we encounter a technical issue on one of our Hyper-V (2012 R2). Our backup (Veeam backup in last version) are still failing with error : Guest processing skipped (check guest OS VSS state and integration components versio

  • T.CODE 'F110'

    Hi, I want to know if i can make partial payment on transaction 'F110' Thanks.

  • E-Mailing in OBIEE - URGENT

    Hello, I am trying to schedule Answers and Publisher reports to be e-mailed to a set of recipients based on the below criteria. The recipients for the reports will be stored in tables (and available in the RPD) as explained below. Can I send e-mails

  • How can I take off icloud storage??

    Well I click 5gb for free by accident and now it takes off five gb and I dont want that because I have a 8gb and nowi can't download any music because I don't have any room!