How to prepare permission matrix of users/groups for SharePoint web Application ?

Hello,
I am using SP Groups/users to assign to sharepoint objects.
few SP Groups having AD groups.
Is there any possibility/way to see/prepare user visibility in SP Group when AD Group is associated with SP Group ?
Thanks and Regards,
Dipti Chhatrapati

Hi Dipti,
So you want to find members of AD group in SharePoint 2010. Here are the links for your reference:
Display members of AD groups web part ---
http://sp2010adgroupmembers.codeplex.com/
Getting members of an AD domain group using Sharepoint API ---http://stackoverflow.com/questions/4314767/getting-members-of-an-ad-domain-group-using-sharepoint-api
Get a list of all SharePoint group’s users including active directory group ---
http://christopherclementen.wordpress.com/2012/07/16/get-a-list-of-all-sharepoint-groups-users-including-active-directory-group/
Regards,
Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact
[email protected] .
Rebecca Tu
TechNet Community Support

Similar Messages

  • How to create a valid database User/Group for installing Linux 5,3

    HI:
    I am trying to install E-Business Suite on LINUX and gave me the following error report
    Unable to validate Database User/Group :oralce /dba
    Provide a valid Database User/Group for the installation.
    when I was installiing on Windows, it did not gave me this error.
    How do I have to crate a user/Group to install eBusiness on my Linux/
    Please help
    Ali

    Hi user;
    hi Ali;
    Yes I run as a root userKeep using root
    When I use the following at the terminal
    It gave me a error message
    " Provide a valid Database User/Group for the installation. "
    Here is what I type at the terminalIts seems normal becouse u try to create same user!
    root@vis groupadd dba
    root@vis useradd -g dba -d /home/oracle vis
    root@vis useradd -g dba -d /home/oracle oracle Try this plz:
    groupadd dba << i think this group already created!
    useradd -g dba -d /home/applmgr applmgr << for apps node
    useradd -g dba -d /home/oramgr oramgr << for db node
    As you notice we define 2 different user under /home path!
    Regards
    helios

  • Security permission to user Group for menuitem in ax 2012

    Hi experts,I have a query,
    Query is that i want to give menu item level permission to user group,for e.g i want to show accounts Payable
    all set up parameter to Finance Group,so how it can be done? i don't want to use Roles--->Duties------->Privileges method,
    I want to just create two groups for one ACount Payable set up parameters will be showed on main ,and for
    other group it was disable?
    is that possible with out creating new roles ,duties and then privileges procedure?

    Hi Munsifuv. You might get more help on this and your other AX questions on an AX-specific forum. We can help with connecting Power Query to data sources, but aren't necessarily experts on configuring those sources.
    Thanks,
    Ehren

  • How to create user group for EIS (Executive Information System) KCBA

    Dear Experts,
    How to create user group for EIS (Executive Information System)
    TCode KCBA
    Regards
    Saurabh

    Hi ,
    Check the below link ,hope it will give some inputs for creating groups.
    http://help.sap.com/saphelp_470/helpdata/en/5c/c1c81c445f11d189f00000e81ddfac/content.htm
    Regards
    udayakumar.k

  • How to allow only the specified users/groups to open my pdf files...

    Hi there,
    I'm looking for resources/documents describing how to allow only the specified users/groups to open my pdf files by the Java API...
    I've found a sample code creating a policy in the following document.
    http://livedocs.adobe.com/livecycle/es/sdkHelp/programmer/sdkHelp/wwhelp/wwhimpl/js/html/w whelp.htm?context=sdkHelp&topic=learn_lc_sdk_invokeremoting
    ( API Quick Starts (Code Examples) > Rights Management Service API Quick Starts > Quick Start: Creating a new policy using the Java API )
    But the sample code doesn't set recepients( users/groups ) who can open the pdf file.
    How can I make it ?
    Any samples ? or Does anybody can tell me which Java classes/methods I should use ??
    Policy#addPolicyEntry(PolicyEntry policyEntry) ??
    PolicyEntry#setPrincipal(Principal principal) ??
    or none of them ?
    Any hints are appreciated !
    Thanks.

    I'm not exactly sure what you are tying to do here, but typical approach when issuing one PDF par user/groups scenario goes like:
    1. Create policy for specific purpose and add principal (user/group)
    2. Apply policy on server side
    3. Deliver the file (via email etc...)
    If you are looking for sample codes, try quick start.
    http://livedocs.adobe.com/livecycle/8.2/programLC/programmer/help/wwhelp/wwhimpl/js/html/w whelp.htm?&accessible=true
    If you go "API Quick Start/Rights Management Service API Quick Starts", you might find something useful. I think you need "Creating Policies" or "Modifying Policies" for step 1 above, and "Applying Policies to PDF Documents" for step 2.
    Hope this helps.

  • How can we provide access/provide permissions to a user/group for group of folders at single step??

    Hi Nico, Thaks you so much for your reply,, Can you please advice or give me some steps to write script pelase? Regards,Kareem

    Hi All, How can we provide access/provide permissions to a user/group for group of folders  at single step?? I can able to provide access for a single folder at a time. I want provide access to a list of  folders( more than 30 ..) at single step?? Regards,Kareem

  • How to add a default user group for multiple document type's?

    Hi,
    I am trying to add same default user group for different document types when MA is created. Is there any way to setup using a single "Document Security Template"? Or I need to create different templates for different document types?
    Please confirm.
    Thanks,
    Saloni

    Hi Saloni,
    Based on what your specific requirement, it might be easier to do it with scripting.
    If you are doing it using Document Security Templates, you would have to create a Document Security Template for each of the 6 MA types and assign the default group. Create another one and leave the Document Type field blank, so it will apply to the other 4 MA types that don't have a default group.
    Regards,
    Vikram

  • Users group for View not for publish

    Hi guys,
    Does anybody can tell me how can I creat users group for view
    and not for publication?
    It's something like to create Contribute roles, but is not
    related with the permission levels to publish, but with the
    visualization permissions for exclusivy content, for ex.:
    Home (open for all users)-------- IT Dept--------Directory
    Dept ---------Support Dept
    - Johny - Johny - Joseph - Isaac
    - Jack - Jack - JJ - Jason
    - Rose - Rose - Robert
    - Joseph - Lisa
    - JJ
    - Isaac
    - Jason
    - Robert
    - Lisa
    Please somebody help me, It's very, very important!!!
    Thanks in advance for who can help me.
    San.

    Sandra Bercke wrote:
    > Hi guys,
    > Does anybody can tell me how can I creat users group for
    view and not for
    > publication?
    > It's something like to create Contribute roles, but is
    not related with the
    > permission levels to publish, but with the visualization
    permissions for
    > exclusivy content, for ex.:
    >
    > Home (open for all users)-------- IT
    Dept--------Directory Dept
    > ---------Support Dept
    > - Johny - Johny - Joseph
    > - Isaac
    > - Jack - Jack - JJ
    > - Jason
    > - Rose - Rose
    > - Robert
    > - Joseph
    > - Lisa
    > - JJ
    > - Isaac
    > - Jason
    > - Robert
    > - Lisa
    >
    > Please somebody help me, It's very, very important!!!
    >
    > Thanks in advance for who can help me.
    >
    > San.
    >
    You cannot restrict on the users to view a particular folder
    (say IT
    dept) using contribute. Infact there is a setting in IIS
    Webserver which
    allows you to set an Authentication mechanism where users
    when browsed
    to any site on your webserver will be prompted for username
    and password.
    But you might want to try something like this.. not sure if
    this will
    help you...
    1. Create 4 connections in contribute
    a) first connection to "Open for all users" directory on
    your webserver.
    b) second connection to "IT Department" directory on your
    webserver.
    c) third connection to "Directory dept"... etc
    2. This way you can administer 4 sites and send connection
    keys to them
    accordingly...
    Hope this helps.

  • Propagating users/Groups/Roles into partner application

    I am very newbee to portal development. I have a following need.
    I want to use Single SingOn feature of Portal. Once the user logged in to the portal via SSo, there may be several applications(within the portal) to which S/He may have access to. Based on who S/He is, may have different level of authorization to what S/He can do into different applications within the portal. How I can make use of user entered for Single Signon, propagate to the application level inside the portal.
    My understanding so far with the portal is that you can develop a portal which has web clipping portlets, external/internal applications, items etc. When we create the users and groups and assign roles to the users, it is limited to the portal front page that we publish to public.
    My problem is further down, into different applications which I expose with the help of portlet or by any other means. And have control over in that particular application(individual), which portion of the application users should be able to see or take any action.
    Your help is highly appreciated.

    Any one has a clue?

  • How to associate more than one security group for UCM documents?

    When checking in a document we are only able to associate one security group to documents. In our case, a particular document can be seen by more than one group e.g a document can be seen bu both finance and marketing groups.
    How can we associate more than one group for documents?
    Our requirement is related to search. We want to display the documents to the end user based on the security group that is associated with the document. We are planning to use IDM and have all the groups/roles that are possible in the end site (also delivered by same ldap) available in UCM so that when checking in the documents we can associate desired groups who can see these documents.
    Regards,
    Pratap

    One thing before all, is that I suggest that you think through your security model before implementing it in UCM. You should ask yourself questions like :
    - Is security really based on department ?
    - Why two departments need to have access to the same category of document ?
    - Is it really security that I need or classification ? Is it a problem if Accouting have access to Finance or you just don't want Marketing documents in a finance related search ?
    - Maybe what you want is that finance guys to have access to marketing document.
    Without a clear business security model, it's hard to find a UCM security model as it is impossible to associate 2 security groups to one document.

  • Define User/Group for an SMB share being mounted!

    Ave,
    Mac OS X 10.3.9 had a very easy way of defining UID & GID of a share being mounted on a mount point, to define an Owner of the content.
    mount_smbfs -u 70 -g 70 //usr:pwd@ip/share SharePoint
    This would make Apache Web Server the User/Group for the mounted share, and this way PHP could access the files on the mounted share with no problems.
    Leopard has elimited that -u & -g arguments to mount_smbfs, and I can't for the life of me figure out how to define User/Group on a share being mounted.
    Any clues?

    sudo -u www mount_smbfs -f 0777 -d 0777 //usr:pwd@ip/share node fixed it!

  • How can i set up multiple user accounts for my new ipad mini?

    How can i set up multiple user accounts for my new ipad mini?

    The iPad mini is basically a one user device. There are no Accounts. You can set up restrictions so that only you can do certain things.

  • No provisioning of User Group for authorization field in user master

    We are implementing CUP 5.3 workflows. Both in manual proviosing and automated provisioning based on User Defaults the user group gets only provisioned to the Groups tab in SU01. The field User Group for authorization on the Logon data tab remains empty (field CLASS from system table USLOGOND, filling CLASS field in table USR02).
    In User defaults both under user default as on the user group tab the user groups have been defined. In manual provisioning the correct list of user groups get displayed for selection.
    Under field mapping in the Application field I only find User Group in user master maintenance, but not User group for authorization. However I would assume I do not need to use field mapping, as I want to automate this provisioning based on user defaults.
    Am I missing a configuration setting here? If so, where can I set it?
    I would assume the provisioning of this field is possible. RAR reports the user group also based on the User group for auhtorization and not from the Groups tab.

    S.Pados,
    I can assure you that what I said in my last response does provision the User Group For Authorization Check on the Logon Data tab; in fact, I was having the opposite issue where the Group tab was not being provisioned; however, I am ruunning AE 5.2 and you said you are running 5.3; maybe something did change or got lost in the releases; it probably is good to see what SAP has to say about this; I would hate to lose this capapbility when I upgrade to AE 5.3
    As far as using the custom field for multiple applications, would that field not be usable for any of the applications you would select in the request form?; if you are using the same table names in the different SAP systems (selectable by the application field on the request) would the drop down selections be whatever the table has defined for that system? I may not be understanding something here so I am just asking;
    It would be great to have a Group field automatically filled in by another selection to avoid the user involvement; I agree with you there; because of our concerns on users entering the AE request, our shop has decided to continue with the users submitting the request through normal email and the security administrators perform the AE entering; this way we have a better idea on something like the GROUP field; we have an option to include the original email as an attachment for justification of the request
    Sorry I could not be of more help
    Jerry
    Ryerson,Inc.

  • Please help, how to guide the user to deploy a web application easily.

    hello,
    i have created an application which creates a new web application every time it is run. now i am writing the documentation of it and dont know which web server the client may have so i have to write / show to the user general steps that he should follow to deploy the web application after it has been created.
    i have written that the user should deploy the web app by making the following entry into the server.xml file (for tomcat)
    <Context path="/webappname" docBase="webapppath"></Context>
    it is not compulsary that the user should place the web application in the webapps directory of the server hence the above webapppath is used.
    now i want to indicate to him where and before / after which tag and under which host name etc the above line should be added in a manner that he is able to do it properly.
    please anyone can help me how to do it.

    i would like to know if there is any way without Java web start.
    it has to be set manually.
    i.e every user should make this entry in the server.xml so that the context is set.

  • Lion upgrade removes user/group for nagios (nrpe)

    FYI:
    Maybe this'll help someone else. I run nrpe/nagios on a couple of my Macs. Upgrading to Lion from SL the upgrade installer removed the user/group for nrpe. On reboot, launchd could not start the process because getpwnam("nagios") failed. The error was repeatedly reported to system.log (Macintosh com.apple.launchd[1] (org.nagios.nrpe[18251]): getpwnam("nagios") failed) causing launchd to use excessive CPU and battery. Recreating the user/group allows the process to start, which allowed launchd to return to normal CPU levels. Also maybe helpful is that when I turned networking off launchd stoped reporting the error which caused the symptoms to stop (which sent me down a fruitless path).
    This error occurred on both a MBP and a Mac Mini. I've reported in via feedback.
    Thanks for listening... Mark

    I have a similar problem - I need to change my account (short) name so that I can backup both my old computer and new computer on timecapsue independently.  However, the link you provided is only for 10.6 and earlier, not for Lion.  Are the instructions for Lion similar?  For one, I have no directory utility on Lion.
    Thanks for your help.

Maybe you are looking for