Group Owner unable to see members

Hello All,
    I posted this question a while back but never got an answer so I thought I'd repost it. I've run into an issue where when a security group owner logs into the FIM portal they see the groups they are managing but are unable to see a list of
members of the group. However when I log in as an FIM administration and I look at the same group I see all members. How do I allow the group owner to manage his own group by granting him access to read the membership. Is there a specific Search Scope or MPR
that needs to be enabled besides the following.
MPR's that are enabled
Security group management: Owners can read selected attributes of group resources 
Security group management: Owners can update and delete groups they own 
Navigation Bar Resources that are enabled as BasicUI
Security Groups (SG's)
My SGs
My SG Memberships
Home Page Resources that are enabled as BasicUI
Security Groups (SG's)
My SGs
My SG Memberships
Search Scopes that have BasicUI
My Security Groups
My SG Memberships

Default values here:
Half-seen attributes are: Manager; MiddleName; Mobile Phone; Time Zone
Is this user a part of this group as well? If so maybe try to enable MPR named User management: Users can read attributes of their own
also?
Another way to check what should be enabled is:
In Management Policy Rules view, click Explore.
On Find tab, leave first option selected.
On Criteria tab, select: Read resource, Only permission granting...; Include disabled ...; Requestor: owner. Target Resource: group
Check MPRs listed and check which of them are disabled :)
Security group management: Owners can read selected attributes of group resources
Security group management: Users can read selected attributes of group resources
Group management: Group administrators can read attributes of group resources
If you found my post helpful, please give it a Helpful vote. If it answered your question, remember to mark it as an Answer.

Similar Messages

  • Group owners unable to edit groups

    We migrated from portal version 3.0.9.8.5 to 9.0.2.6.18
    using verison4 of the upgrade scripts.
    Now group owners cannot edit groups.
    However when i login as portal30_admin or assign
    edit any group to group owners they can edit groups.
    Any pointers?

    This is a known bug in this version. You need to open a TAR for the solution.

  • Users and Group Owners are unable to see their groups

    Hello all,
         I have an issue where security group owners are unable see/read any groups that they own. I have enabled the following  MPR's but still nothing please help.
    Group management: Group administrators can create and delete group resources
    Group management: Group administrators can read attributes of group resources
    Group management: Group administrators can update group resources
    Security group management: Owners can read selected attributes of group resources
    Security group management: Owners can update and delete groups they own
    Security group management: Users can read selected attributes of group resources
    Also when a user logs into the portal they are unable to see any Security groups listed under MY SG Membership. However when we check the group membership they are indeed part of the group both in FIM portal
    and AD.

    Reason might be that user's don't have access to group objects at all or are not able to read some of attributes of a group. Also make sure that BasicUI keyword was added to the specific elements of UI used in group management - this includes navbars but
    also search scopes which are used for group filtering. 
    On the MPRs side:
    Make sure that your Security group users set was not modified - maybe people are filtered out from these MPRs.
    Use explore function in MPR  part of a portal to check what actual MPRs are being triggered when user tries to access group object. 
    Tomek Onyszko, memberOf Predica FIM Team (http://www.predica.pl), IdAM knowledge provider @ http://blog.predica.pl
    Hi Tomek,
    Which attributes must a user be able to read in order for this to work? If possible can you provide me with a full list so I can verify that they do have rights to read them.
    I have added the keywork BasicUI to the following sections 
    Under Home Page Resource
    Join a SG
    Manage my SGs
    Search Scopes
    Security Groups (SGs)
    See my SG memberships
    Under Navigation Bar Resource
    My SG Memberships
    My SGs
    Security Groups (SGs)
    As for the security group users set, I have modified it to allow all domain users to be part of this set. When I click View Members all users are listed. 
    "Use explore function in MPR  part of a portal to check what actual MPRs are being triggered when user tries to access group object. "  How would somebody go about doing this?

  • Unable to see Remote App and Desktop Connection in Group Policy Management Editor

    I am unable to see the Remote App and Desktop Connection in Group Policy Management Editor on my 2012 R2 DC. I am therefore not able configure the connection URL in Access RemoteApp and desktops in our Windows 8.1 client environment.
    Within the Group Policy Under User Configuration, Administrative Templates, Windows Components all I see is:-
    RD Gateway
    Remote Desktop Connection Client
    Remote Desktop Session Host
    But NOT
    Remote App and Desktop Connection
    Which I need. Is there anyway of adding this?

    > I am unable to see the Remote App and Desktop Connection in Group Policy
    > Management Editor on my 2012 R2 DC. I am therefore not able configure
    > the connection URL in Access RemoteApp and desktops in our Windows 8.1
    > client environment.
    http://gpsearch.azurewebsites.net/#8113
    Do you use a central store for ADMX? Is this central store out of date?
    (Means "still contains ADMX from W7/2008R2")
    Martin
    Mal ein
    GUTES Buch über GPOs lesen?
    NO THEY ARE NOT EVIL, if you know what you are doing:
    Good or bad GPOs?
    And if IT bothers me - coke bottle design refreshment :))

  • Unable to see pipe line steps in the SXMB_MONI

    HI,
    i have done the development and quality work for my p i7.1
    i was testing the messages in the Quality System.
    So i went to SXMB_MONI to see the messages.
    After double clicking on the  successfully processed message, it shows
    pipe line steps.
    in that I am able to see
    1.inbound message(CENTRAL)
    2.XML Validation inbound channel Request
    3. call adapter
    4. Response
    but i am unable to see
    1. Receiver Determination
    2. Interface Determination
    3. Receiver Grouping
    4. Request Message Mapping
    5. Technical Routing
    whereas  in the develoment system i am able to see the above all.
    is there any configuration i have to do in the SXMB_ADM?

    can i know that   Configuration objects were created/ imported by using transport mechanisum?
    if created ,
    check the cache status and re activated those objects whatever u r posted in thread.
    if transported :
    u ll follow ,whatever posted by Earlier

  • Unable to see DB13 and ST04 logs in the system.

    Hi All,
    We are unable to see the DB13 logs in our SAP system. The same is happening while trying to look into the ST04 logs for Database Message Logs. In both the cases we find the same kind of log:
    [in DB13 log]************************************************************************
    BR252E Function fopen() failed for '/sapdba/sapcheck/cdvxzfrv.aly' at location file_printout-1
    BR253E errno 2: No such file or directory                                                     
    External program terminated with exit code 5                                                  
    [in ST04 log]*************************************************************************
    BR252E Function fopen() failed for '/sapdba/saptrace/background/alert_PIN.log' at location file_printout-1
    BR253E errno 2: No such file or directory
    External program terminated with exit code 5                                                              
    SAP is running on Varitas cluster on two different nodes. One node is having SAP services and the another one Oracle services on it. Since the last week when we shifted the Oracle services from one node to another for monthly maintenace work, we are facing this problem.
    Our system details are:
    SAP 46C (kernel 46D_EXT) 32 bit
    SuSe Linux 2.6.5-7 64 bit
    Oracle 9.2.0.6.0
    Can someone please help me on it.
    Anil

    Thanks Padmaja/Eric for your reply !!!
    File systems are properly mounted and I can see these said files at OS level. Following are the env variable:
    USER=dinadm
    LOGNAME=dinadm
    HOME=/home/dinadm
    PATH=/oracle/DIN/920_64/bin:.:/home/dinadm:/usr/sap/DIN/SYS/exe/run:/opt/kde3/bin:/opt/gnome/bin:/usr/games:/home/dinadm/bin:/usr/bin/X11:/usr/bin:/bin:/usr/sbin:/sbin:/usr/lib/java/jre/bin
    MAIL=/var/mail/dinadm
    SHELL=/bin/tcsh
    SSH_CLIENT=10.234.14.33 1364 22
    SSH_CONNECTION=10.234.14.33 1364 10.234.13.50 22
    SSH_TTY=/dev/pts/0
    TERM=xterm
    HOSTTYPE=x86_64-linux
    VENDOR=suse
    OSTYPE=linux
    MACHTYPE=x86_64
    SHLVL=1
    PWD=/usr/sap/trans/data
    GROUP=sapsys
    HOST=insapr3din01
    HOSTNAME=insapr3din01.pdc.in.ap.holcim.net
    MANPATH=/usr/share/man:/usr/X11R6/man:/usr/local/man:/opt/gnome/share/man
    MINICOM=-c on
    INFODIR=/usr/local/info:/usr/share/info:/usr/info
    INFOPATH=/usr/local:/opt/gnome:/usr
    LESS=-M -I
    LESSOPEN=lessopen.sh %s
    LESSCLOSE=lessclose.sh %s %s
    LESSKEY=/etc/lesskey.bin
    PAGER=/usr/bin/less
    MORE=-sl
    GZIP=-9
    CSHEDIT=emacs
    COLORTERM=1
    NNTPSERVER=news
    XFILESEARCHPATH=/usr/lib/X11/%L/%T/%N%C:/usr/lib/X11/%l/%T/%N%C:/usr/lib/X11/%T/%N%C:/usr/lib/X11/%L/%T/%N:/usr/lib/X11/%l/%T/%N:/usr/lib/X11/%T/%N:/var/X11R6/%T/%N%C:/var/X11R6/%T/%N
    INPUTRC=/etc/inputrc
    LANG=en_US.UTF-8
    QTDIR=/usr/lib/qt3
    no_proxy=localhost
    WINDOWMANAGER=/usr/X11R6/bin/kde
    JAVA_BINDIR=/usr/lib/java/jre/bin
    JAVA_ROOT=/usr/lib/java
    JAVA_HOME=/usr/lib/java/jre
    JRE_HOME=/usr/lib/java/jre
    CVS_RSH=ssh
    G_BROKEN_FILENAMES=1
    GNOME_PATH=/opt/gnome:/usr
    GNOMEDIR=/opt/gnome
    ACLOCAL_PATH=/opt/gnome/share/aclocal
    PKG_CONFIG_PATH=/opt/gnome/lib/pkgconfig
    GTK_PATH=/usr/local/lib64/gtk-2.0:/opt/gnome/lib64/gtk-2.0:/usr/lib64/gtk-2.0
    MODULE_VERSION=3.1.6
    MODULE_VERSION_STACK=3.1.6
    MODULESHOME=/usr/share/modules
    MODULEPATH=/usr/share/modules/versions:/usr/share/modules/modulefiles
    LOADEDMODULES=
    CSHRCREAD=true
    LS_OPTIONS=-N --color=tty -T 0
    SAPSYSTEMNAME=DIN
    DIR_LIBRARY=/usr/sap/DIN/SYS/exe/run
    LD_LIBRARY_PATH=/usr/sap/DIN/SYS/exe/run:/oracle/client/92x_32/lib
    THREAD=NOPS
    dbms_type=ORA
    dbs_ora_tnsname=DIN
    dbs_ora_schema=SAPR3
    ORACLE_PSRV=DIN
    ORACLE_SID=DIN
    ORACLE_HOME=/oracle/DIN/920_64
    ORACLE_BASE=/oracle
    ORA_NLS=/oracle/DIN/920_64/ocommon/NLS_723/admin/data
    ORA_NLS32=/oracle/DIN/920_64/ocommon/NLS_733/admin/data
    ORA_NLS33=/oracle/client/92x_32/ocommon/nls/admin/data
    NLS_LANG=AMERICAN_AMERICA.WE8DEC
    SAPDATA_HOME=/sapdata/oracle/DIN
    waiting for your reply,
    Anil

  • Unable to see the deployed webservices in websevices list

    In SAP EP System some of the APIs are not exposed to clients and those APIs needs to be called thru webservices (like get all Roles names from the SAP-EP system, add a role to user in SAP-EP system, Remove a ole from the User in SAP EP system, get all assigned Roles of a User in SAP EP system, get all users for a role in SAP-EP system, and get users for a group in SAP-EP system).
    To achieve the above functionality, we have developed the portal (.par file) which will call the SAP EP APIs using web services.
    We have developed a piece code (.par file) in net viewer Developer studio 2.0.9; we deployed /tested  this .par file on to SAP EP6 SP2 successfully. Now, we need to test this .par file in SAP EP6 SP13 but we are not able to succeed in deploying this file like how we are doing it in SP2. After successful deployment of the PAR file we are unable to see the particular webservice in the webservices list.
    For deploying the PAR file we followed the following navigation steps:
    1.login into SAPEP as sapadmin.
    2.click the systemadministrator tab.
    3.click the support tab.
    4. select the portalruntime link.
    5.click on the AdministratorConsole link.
    upload window will open where we upload the PAR file.
    For checking the uploaded Webservices we followed the following navigation steps:
    1.login into SAPEP as sapadmin.
    2.click the systemadministrator tab.
    3.click the support tab.
    4. select the portalruntime link.
    5.click on the soapadmin link.
    In case of SP13, we are not able to see the uploaded webservices. But, when we deploy .par file it “says deployed successfully” (not throwing any errors).
    Edited by: praveen bikumalla on Jan 21, 2008 7:38 AM

    If we restart the services that is there in Systemconfiguration->servicesconfiguration->Applications i am getting the following error
    Server 1337850:Error in the listener class com.sap.ip.portal.admin.portalanywhere.QueryHandler during the process of handleTopic.

  • Unable to see/Export All existing users of  MSAD-Shares Services

    Hi Dear all !
    Please help me to resolve an issue.
    I have configures shared services in MS Active directory and it users.
    but problem is that i m unable to see all users in User list in shared services under active directory.while i click n "show all" option its showing only 4 pages of records.
    but if i m searching a user which is not displaying in those pages , i got that user..
    Also while exporting the user list i have only users which are displaying in user list (in 4 pages)..not all users details are exported.
    Please, anybody let me know the solution !!
    Thank you.
    vivek

    If you really want to export all users from MSAD, then you should probably be looking into MSAD/LDAP utilities for that purpose. If what you really mean is that you want to export all user and group assignments that you've set up in Shared Services, then take a look at the Lifecycle Management or CSSExport utilities.

  • Unable to see my project template after creating the same

    Hi All,
    I Created one (Multi Org)Organization and enable all the required secutiry profiles (HR: Business Group, HR:Security Profile, HR:User Type,MO:Security Profile),When i am creating the Project Template unable to see the same template its moving to some other Org its showing.
    what i have to check in setups. could you please any one.
    Thanks

    Hi Murali,
    Can you check whether you have setup the following profile options for that responsibility to see the created templates.
    PA: Cross Project User -- Update
    This option allow you to update the project with out assignment on the project.
    PA: Cross Project User -- View
    This option allow you to view the project templates by using that responsibility.
    Best Regards,
    Sreenath

  • User In Planning unit Hierarchy unable to see data form in editable mode

    hi all,
    we are facing a problem in planning unit hierarchy in Hyperion planning, where we have 4 users, Hierarchy is define as
    hierarchy: budget approved
    version: approved
    Entity: Finance
    Senario:Budget
    haroon asghar ( owner)
    adeel javid (Reviewer)
    Naeem asghar (Reviewer)
    Imtiaz (Reviewer)
    Issue is that,after start the budget activity (promotional path) by Admin, the data form editable to Owner haroon asghar
    but after completing his work by haroon,when he promote the planning unit ,the next user in Hierarchy "Adeel javid" unable to see data form in respective planning unit in uneditable data form not only for this user but all rest of the users as well,while i think data form should only uneditable(grayed) for user Haroon Asghar who promote the planning unit.
    we have checked all security rights to the users those are "Write access" but still Adeel javid is unable to enter data,so the budget activity is stop due to this problem.
    when i remove the planning unit then i log in with all user one by one and see all data form required version,scenario and entity were editable to all users mention above
    we want to run budget activity with the above planning unit hierarchy.
    plz any one provide the proposed solution of the said issue
    we are using Product Version     11.1.2.0.00
    Regards
    Anwar

    Reviewers will not be able to write data to the intersection. Reviewers can only review the data and follow-up with a Reject, Promote, Sign off, Delegate, Originate or Freeze.
    Please refer Article ID 1226783.1 in MOS.
    HTH-
    Jasmine.

  • Unable to see the portal content directory in content adminstration

    Hi,
    I am unable to see the portal content directory in the content administration. I am not the super administrator.I have been assigned content admin role. But, I am unable to see the PCD.I see from previous blogs that permission has to be set for my role.
    Can any one help me in telling the procedure to set the permission.If permission is not the issue then do tell me the solution for it.
    Suganya

    Hi Suganya,
    The content admin role normally is sufficient to see / read the portal content catalogue (as far as the standard settings are concerned). But maybe they have been restricted on your implementation by some administrator.
    Some with sufficient permissions on the portal content catalogue has to right-click on the root (portal_content) object, "open", "permissions", and has to provide at least administrative "read" permission to you, some role (content admin for example) which is assigned to you or some group you belong to.
    Hope it helps
    Detlev
    PS: Please consider rewarding points for helpful answers on SDN. Thanks in advance!

  • Changing group owner disables wiki/blog

    For quite some time now the procedure for creating new groups with a single owner/moderator has worked well. I 1) go in to the directory app on the server, 2)create the group, 3) change the owner to the teacher who will manage the wiki/blog, 4) add the teacher to the list of users allowed to create wikis (in web services). Then everything works like a charm. As of a few weeks ago (and I have not run any updates--still on 10.5.6, etc.), as soon as I change the group owner from Directory Administrator the wiki/blog generates a no group with that name is hosted on this server. Changing the owner back to directory admin fixes this but I need the teachers to be owner/moderators. Any suggestions on what might be causing this problem?
    Thanks,

    Is there any solution to this problem? I am trying to set up the group owner but can't. I am set as the group owner in the group list and set as moderator in the list of users allowed to create wikis but when I go into the wiki site I am unable to change settings.

  • Group owner "wheel"

    I recently installed an oss app, I was unable to make an alias of it, so I checked its permissions.
    Its group owner was "wheel", now I'm just curious why it was set as wheel. btw, the user owner is my main account, who is not in group wheel.
    So is there any drawbacks to adding myself to group "wheel"?, any drawbacks to changing group ownership to admin, root, or $Name?

    Here are some of my permissions:
    mac $ pwd
    /Applications
    mac $ ls -l
    total 480
    drwxr-xr-x    3 mac   staff    102 Jan 24  2007 0xED-1.app/
    -rwxr-xr-x    1 mac   wheel  13780 Sep 15 15:47 0xED.app*
    drwxrwxr-x    4 root  admin    136 Jan 11  1970 Acrobat Reader 5.0/
    drwxrwxr-x    3 root  admin    102 Sep 11 17:31 Address Book.app/
    drwxrwxr-x    3 mac   admin    102 Aug 15  2007 Adobe Help Viewer 1.0.app/
    drwxrwxr-x    6 mac   admin    204 Oct 31  2003 Adobe Reader 6.0/
    drwxrwxr-x    5 mac   admin    170 Nov 13 15:50 Adobe Reader 9/
    seems like other should be r-x
    root # ls -ld  WhatSize*
    drwx------   3 mac  admin  102 Apr  7  2006 WhatSize.app/
    Used the gui alias command...
    root # ls -ld  WhatSize*
    drwx------   3 mac  admin  102 Apr  7  2006 WhatSize.app/
    -rw-r--r--   1 mac  admin    0 Nov 20 16:31 WhatSize.app alias
    root # 
    Robert

  • Set group owner using REST API

    I'm trying to use the REST API to set the owner of a SharePoint group. I can successfully create the group using REST, but I can't change the owner. I've tried the following.
    1 - Specifying a group owner while creating the group
    Endpoint: .../_api/web/sitegroups
    Method: POST
    Headers:
    Content-Type: application/json; odata=verbose
    Body:
    { '__metadata': { 'type': 'SP.Group' }, 'Title': '<title>', 'Description': '<description>', 'Owner': { '__metadata': { 'type': 'SP.Principal' }, 'Title': '<owner_title>'}}
    This returns a 500 error: "The specified name is already in use. Please try again with a new name". In other words, the owner title I specified already exists, which is correct - I'm trying to make an existing principal the owner of the new group.
    2 - Merging a new group owner into an existing group
    Endpoint: .../_api/web/sitegroups(<group_id>)
    Method: POST
    Headers:
    Content-Type: application/json; odata=verbose
    X-HTTP-Method: MERGE
    Body:
    { '__metadata': { 'type': 'SP.Group' }, 'Owner': { '__metadata': { 'type': 'SP.Principal' }, 'Title': '<owner_title>'}}
    This returns a 500 error with a Microsoft.SharePoint.SPException: "Exception from HRESULT: 0x80131904". The trace logs don't shed any light on it.
    3 - Using the owner endpoint directly
    Endpoint: .../_api/web/sitegroups(<group_id>)/owner
    Method: POST
    Headers:
    Content-Type: application/json; odata=verbose
    X-HTTP-Method: PUT
    Body:
    { '__metadata': { 'type': 'SP.Principal' }, 'Title': '<owner_title>'}
    This throws various 400 errors. If the current owner of the group is a user, I get the error "The required property 'Email' does not exist in the message" - i.e. it wants SP.User properties. If the current owner of the group is another group, I get
    the error "The required property 'AllowMembersEditMembership' does not exist in the message." - i.e. it wants SP.Group properties.
    I've tried various adaptations of the three approaches above, such as specifying additional SP.Principal properties or passing SP.User or SP.Group objects instead, but with no success. Any ideas?

    As we chatted on email.  There doesn't seem to be any combo that will set the owner.  Only way to do it is to use the CSOM XML method and post to client.svc\ProcessQuery:
    POST
    http://weburl/_vti_bin/client.svc/ProcessQuery HTTP/1.1
    X-RequestDigest: 0xAE382F0A8F11688BA9BE66739F84443892CE5E5452BA3E2622F6013D9D97EA8A8D9476463EDC503F700EB24F45024150D0DEEB2F40B160CD88BA7C7B4769BECD,15 Jan 2014 00:11:02 -0000Content-Type: text/xml
    Host:
    www.sanspug.org
    Cookie: FedAuth=blah
    Content-Length: 612
    Expect: 100-continue
    Accept-Encoding: gzip, deflate
    XML body is:
    <Request AddExpandoFieldTypeSuffix="true" SchemaVersion="15.0.0.0" LibraryVersion="15.0.0.0" ApplicationName=".NET Library" xmlns="http://schemas.microsoft.com/sharepoint/clientquery/2009">
    <Actions>
    <SetProperty Id="45" ObjectPathId="32" Name="Owner">
    <Parameter ObjectPathId="33" />
    </SetProperty>
    <Method Name="Update" Id="46" ObjectPathId="32" />
    </Actions>
    <ObjectPaths>
    <Identity Id="32" Name="740c6a0b-85e2-48a0-a494-e0f1759d4aa7:site:a1452dcc-8fc4-4631-8ada-97cb204810f1:g:9" />
    <Identity Id="33" Name="740c6a0b-85e2-48a0-a494-e0f1759d4aa7:site:a1452dcc-8fc4-4631-8ada-97cb204810f1:g:7" />
    </ObjectPaths></Request>
    The ids are randomly generated and can be anything you want, as long as they correlate (setproperty and method objectpathid is the object you are updating).  The most important part is the
    “Name” parts. The first part is the typeid of the object (in this case is means SPGroup), the second part as you can see if the site guid id.  The response does in fact return json if you tell it too:
    Chris Givens CEO, Architecting Connected Systems
    Blog Twitter

  • User unable to see the dashboard

    Hi,
    We have built different dashboards (orders, sales, expenses etc). and we have give access to users whcih are under fin group.
    one user able to see orders and sales and not expenses.
    Later i tried giving "user name" along with group access to "Expenses" dashboard. Still, he is unable to see the dashboard.
    Please let me know your thoughts on this and how to resolve this.

    Check the security settings for the user at folder level @Administration>Setting>Manage Presentation Catalog

Maybe you are looking for

  • Delivery Address

    Hi All, There are duplicate entries of address created for same plant and storage location combination. (All values in the fields are same in both the entries). Also, if address number of these two entries are say 5001 and 5002, while creating Schedu

  • I cannot open Firefox at all... receive "Profile Missing" -- what next?

    MAC desktop being used. When I click on my Firefox app it looks and looks then brings up a window: Profile Missing. Obviously, I cannot do much without opening Firefox. What do I do next?

  • Help Please! Computer With iTune Library Died

    My computer (XP) died which had my primary itune library. I was able to copy the content of the hard drive off the computer and load it on my laptop (Vista). How can I transfer the itune files and recreate my itune library on the new laptop? Thanks i

  • Exportpdf formats - excel, csv or txt

    How do I use exportpdf online to export to excel, csv or txt?

  • Satellite C650 - Windows Photo Viewer freezes every time in use

    Hello all, my C650 is a brand new purchase and so far I haven't been able to view any photos; on a memory stick, in "My Pictures" or in any form using the Windows Photo Viewer. Once I double click on the picture icon, the image enlarges to full scree