Hyperion - Shared Services (Can I restrict a user based on a member?)

In the Shared Services Management Console can I restrict a users access to only certain members in a dimension?
Example: If someone is trying to retrieve data in excel from Hyperion can I restrict that users information to only their geographic market?

To expand on what SeanV told you, Filters are not created in Shared Services, but in Essbase (EAS or MAxL). They are however applied in Shared services

Similar Messages

  • In Shared Services, can we generate a user list?

    Hello,
    We have many users that are part of different groups. Using Shared Services, is there a way to pull out, in a report format, the list of users belonging to a particular group or even to all groups?
    Regards,
    Nathalie

    Try to use LCM.
    Also, please read Re: List of Hyperion users
    Regards
    Alexander

  • How can we restrict the user to a desired "Member access profile" ?

    Dear Gurus,
    In BPC 7.0 my "Team" has 4 "member access profiles" and a user is assigned to that team.
    Can that user have access to just one member access profile ??
    If he can, how do I set it up in BPC 7.0 ?
    NB: I read somewhere that I should not asign "member access profiles" to users directly. Hence I wanted to do it through "Team"
    -Venkat

    Vijaya,
    Sorry, but your answer didn't make any sense to me.
    Here all the 4 member access profiles are different. i.e. they all are restricted with a different dimension member. So, if I assign each of these 'member access profiles' directly to the user, my requirement is met.
    But my question is: how do my "user" pick the required member access profile from a TEAM which has all 4 member access profiles ?
    SAP suggested NOT to assign users directly to member access profiles. Instead it suggested to assign "teams" to member access profiles and assign user to the "teams"

  • Hyperion Shared Services user Management Guide

    Hi ,
    Can any one share the Hyperion Shared Services User Management Guide.
    Regards
    naveen

    Hi,
    For 9.3.1 Try - http://download.oracle.com/docs/cd/E10530_01/doc/epm.931/html_cas_help/toc.htm
    11.1 - http://download.oracle.com/docs/cd/E12825_01/epm.111/epm_security_11111/cas_help.htm
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Hyperion Shared Services (WebHal) user retrieval - slow

    Hi,
    I applied the Hyperion Shared service patch 9.3.1
    After that i am noticing a significant decrease in the user retrieval response time.
    Will deleting the users help me in any way ?
    Could you anyone point me as to how could i increase the response time ?
    Thanks,
    COldFIre
    Edited by: coldfire on Sep 15, 2010 9:17 PM

    Did you notice this behavior with nativ openldap or with an external directory ?

  • Creating data server for Hyperion Shared Services (HSS)

    Hey Gang,
    Has anyone had experience in creating a Data Server for Hyperion Shared Services (HSS) using the java API? I know HSS uses Native Directory, but to be compliant the Hyperion folks recommend using the java API strictly to get access to the users, groups, etc.
    Anyone have experience with this, or perhaps at least how to get ODI to kick off a java file to pull the data needed? What effort would be needed in ODI, is it straight forward or would I have to develop a technology or something to integrate into ODI?
    Thanks.

    Thanks for the quick reply John. I am trying to get user and group information, and also doing some complex manipulation. I need this to verify user access and some other stuff. I will not always have access to HSS and cannot always export the information, thus the need to use the HSS java API.
    I'm trying to pull it out of HSS and put it into an Oracle table in a standard format where I'll use the information and do reporting off of it. I've developed a java class that does migrates the data over, but its crude and I'd like to move it into ODI with some of our projects that are currently doing the same thing with other ERP such as Ebiz and Peoplesoft.
    If I can recode some of the java in ODI, how would I go about doing that. Where would I include the libraries, etc.? is there a tutorial or a place where I can get started on that.
    Thanks for all the help.

  • Security issue-Hyperion shared services console

    Hi,
    I want a user to access worspace planning but not EAS.
    how to do with hyperion shared services console.
    Regards,
    DK
    Edited by: 972210 on Nov 20, 2012 5:19 AM

    Yes, the user has the Provisioning role and can edit and save user roles, but they cannot update native groups that users are assigned too.

  • Hyperion shared services !

    Hi Techies,
    I am working on hyperion shared services 9.3.1 version.
    Can you any one tell me how to assign the database calculation & filter access in shared services.
    What i have did is,
    I have created the 3 users in essbase & migrated those users into shared service mode & also register all applications to shared services as well.
    All applications are reflecting under analytic servers also.
    I have given the Here is some of the roles specific to Essbase in Shared Services.
    Server Roles (Administrator, Create/Delete App, Server Access)
    Application Roles (App Manager, DB Manager, Start/Stop Application, Calc, Write, Filter and Read Roles.
    Poblem is i am not able to assign the database calculation & filter access in shared services.
    Please,please could any one guide me ...
    Thanks in Advance.

    What Sean said.
    It is super non-intuitive. I mostly work in Planning (which handles all of this behind the scenes) and when I, alas, infrequently get to use real, honest-to-goodness Essbase I have to relearn this. It never seems natural.
    You'd think after relearning it three or four times, I'd get it, but nope, it's just "weird".
    Regards,
    Cameron Lackpour

  • Hyperion Shared Services Active Directory

    Gurus, i am an Essbase Developer and currently have an issue where the users in the Hyperion Shared Services Active Directory does not reflect the true number of users actually on the company network.
    Whilst new employees created in the company flow through correctly into Hyperion Shared Services, those who have left the company still show in Hyperion Shared Services, even though they have been deleted from the network. Its as if newly created users synchronize perfectly into the Hyperion Shared Services Active Directory, but the deletion of users does not flow through.
    Has anyone experienced this?
    Thanks

    Hi,
    You are fecthing the user ids from Active Directory just to reduce lot of manual effort of creating native ids for all the user and also a security part its suggested to use Active Directory.
    Now how can you say that id is still active in AD, the user who had left the company his id would be already inactive even though you are able to query the user and provision on his id or add him/her to a group that has provisions will not be able to login as their id is made inactive.
    If you want to remove them automatically from Essbase or Shared Services automatically when their id gets disabled it wont happen as provisioning information etc lies with Shared Services and just to authenticate a valid user AD comes into picture .
    If you want to eliminate users from accessing the system whose id is disabled is to change your AD configuration in Shared Services based on the inputs from your AD team such that where does the disabled id go into (ex : which OU etc..) and configure accordingly which should work.!!! now if you want to eliminate them from Essbase unprovision them/their ids and run security refresh .
    Thanks
    Amith

  • Hyperion Shared Services Error

    Guys,
    I had configured MSAD external authentication in Hyperion Shared Services 9.3.1. I am also able to see the groups and users in the shared services.
    I provisioned one of the group with Essbase Admin, and HSS Admin. but when i tried to login to the Shared services with a userID in that group, HSS is showing the error "User: XXXX, not found"
    CSS.xml file seems to be fine to me. Users in Native authentication are working fine.
    - <css>
    - <hub location="http://HSS-Server:58080">
    <dirPort>58089</dirPort>
    </hub>
    - <spi>
    - <provider>
    - <native name="Native Directory">
    <password>{CSS}4N6lVcgiE/dGr8rFdvQLcA==</password>
    </native>
    - <msad name="XXXXX">
    <vendor>Microsoft</vendor>
    <trusted>true</trusted>
    <url>ldap://MSAD-server:389/DC=xxx,DC=xxxx,DC=com</url>
    <userDN>YYYYYYYYYYYYYYYY</userDN>
    <password>{CSS}VBLEOOfJ6ucg4ybH9z9PvQ==</password>
    <authType>simple</authType>
    <maxSize>100</maxSize>
    <identityAttribute>ObjectGUID</identityAttribute>
    <identityAttributeType>Octet String</identityAttributeType>
    - <group>
    <useGroups>true</useGroups>
    - <objectclass>
    <entry>group?member</entry>
    </objectclass>
    <url>OU=yyy</url>
    <nameAttribute>cn</nameAttribute>
    </group>
    </msad>
    </provider>
    </spi>
    - <searchOrder>
    <el>XXXX</el>
    <el>Native Directory</el>
    </searchOrder>
    - <token>
    <timeout>480</timeout>
    </token>
    - <logger>
    <priority>WARN</priority>
    </logger>
    - <delegatedUserManagement>
    <enabled>false</enabled>
    </delegatedUserManagement>
    </css>
    Any help is much appreciated.
    AB

    As informed earlier you could refer this link http://www.oracle.com/technetwork/middleware/bi-foundation/hyperion-supported-platforms-085957.html which will have the corresponding version support matrices (In your case 9.3.1 or 9.3.3) which will help you to find out which OS and which browsers can be used.

  • Hyperion Shared Services Console:  EPMCSS-09159 error

    I have assigned Administrative rights in Hyperion Shared Services Console v11.1.2.2.0.66 that are identical to my rights, but they still get the following error when trying to grant access to Native groups:
    "EPMCSS-09159:  Failed to update user relationship to native groups.  User "username" not authorized to update user.  Contact Shrared Services administrator."
    I am able to grant user access to Native groups with the same access.  Let me know if you have any suggestions for me to try.
    Thanks

    Yes, the user has the Provisioning role and can edit and save user roles, but they cannot update native groups that users are assigned too.

  • Hyperion Shared Services Export

    Hello All,
    I need to export Hyperion Shared services, I know about CSSEXPORT.bat utility but i am not sure how to run, we are using Hyperion Planning, Essbase FDM APS, Smart view, FR and some other tools and I need to export either in xml file or CSV, if is there any other option i can use or how i can run from CMD prompt. We used Hyperion System 9.3.1
    Any help would be great.
    Thank you,
    T.Khan

    You can call CSSEXPORT.bat script using following statement
    Call CSSExport.bat importexport.properties
    Make sure your importexport.properties file is present in the same location as CSSExport.bat files
    format of importexport.properties file needs to like this
    Send me your email id and I can send you a document on import/export utlity for version 9.3.1
    #import export operations
    importexport.css=file:/C:/Hyperion/deployments/Tomcat5/SharedServices9/
    config/CSS.xml
    importexport.cmshost=localhost
    importexport.cmsport=58080
    importexport.username=admin
    importexport.password={CSS}MRcYv323uzxGr8rFdvQLcA==
    importexport.enable.console.traces=true
    importexport.trace.events.file=trace.log
    importexport.errors.log.file=errors.log
    Import/Export Utility 3
    importexport.locale=en
    # importexport.ssl_enabled = true
    # export operations
    export.fileformat=xml
    export.file=C:/exportNew.xml
    export.internal.identities=true
    export.native.user.passwords=true
    export.provisioning.all=true
    export.delegated.lists=false
    export.user.filter=*@Native Directory
    export.group.filter=*@Native Directory
    export.role.filter=*
    export.producttype=HUB-9.2.0
    #export.provisioning.apps=(HUB=Global Roles)
    # import operations
    import.fileformat=xml
    import.file=C:/exportNew.xml
    import.operation=update
    import.failed.operations.file=c:/failed.xml
    import.maxerrors=0

  • Re: OBIEE 10.1.3.4.1 integration with Hyperion shared services 11.1.1.3

    I am working on OBIEE authentication using hyperion shared services. To achieve this I did the following steps,
    1) Registered the shared services in Answers using 'Manage EPM workspace'
    2)Modified config.xml to enable HSSauthenticator
    3)Modified instanceconfig.xml by adding external auth tags
    4)In rpd created a init block using custom authenticator.
    When I login into Answers using a username and password from hyperion shared services, it is saying invalid username/password.
    Log file says ' xxxxxx authentication failed in repository star, Odbc driver returned an error (SQLDriverConnectW)'
    Can some one explain me if I am missing anything here?? Is there anyone who has successfully implemented this before.
    Thanks,
    Sandeep

    Sandeep,
    I am fairly certain that this integration actually works in the other direction.
    That is from the Oracle Hyperion Workspace portal you need to log in and once you are in Workspace from the file menu an option for "Oracle Interactive Dashboards" should be available if all is configured correctly with the integration. That link will open up OBIEE and take the user directly into the dashboards without having to get prompted by the OBIEE login screen.
    If you have the BIC2Go image (Dan Vlamis' team, vlamis.com) for Oracle BI 10g you can see this integration's configuration and see it working correctly.
    I hope that helps

  • Register with Hyperion Shared Services

    All,
    Where within the FDM application can you register with Hyperion Shared Services.I am receiving the error message...
    Error: This application is not registered with Hyperion Shared Services. Please contact your administrator.
    regards,
    ciara

    Hi,
    Not an answer to the original question as that has been answered but just to clarify from version 11.1 FDM uses Shared Services, you can also get versions 9.3 of FDM to use OpenLdap (this is used by Shared Services) to validate users.
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Troble configuring Hyperion Shared Services with SQL Server 2005

    I recently installed SQL server (SQL SERVER 2005) in my machine and then am trying to install Hyperion (9.3.1) products. I started with Shared services. It was installed successfully. Problem is occuring when am trying to configure Shared service with SQL database using Hyperion Configuration utility (9.3.1)
    The error which is popping up is
    Unable to connect to the database for the product Hyperion Shared Services.
    Things which I tried from my end
    1. Made sure TCP IP Protocol was enabled in SQL server configuration server.
    2. hypuser was created in SQl server.
    3. hypdb was created in SQL server.
    4. Was having dynamic IP address so install Loopback adapter to obtain Static IP address and port.
    5. Port and IP address was correct.
    Let me know where I am going wrong.
    Any help will be greatly appreciated.

    Finally got it fixed firewall settings needed to be change : This document helped me a lot to troubleshoot the issue
    An error has occurred while establishing a connection to the server. When connecting to SQL Server 2005, this failure may be caused by the fact that under the default settings SQL Server does not allow remote connections. (provider: Named Pipes Provider, error: 40 - Could not open a connection to SQL Server) (Microsoft SQL Server, Error: 2)
    This problem may occur when SQL Server 2005 is not configured to accept incoming local and remote connections, which is disabled by default in SQL Server 2005 Express Edition, SQL Server 2005 Developer Edition and also SQL Server 2005 Enterprise Edition. To solve the connection forbidden problem, SQL Server 2005 needs to configure to allow incoming local and remote connections.
    Firstly, ensure that SQL Server 2005 is configured properly to allow incoming connections on the instance of database server, else enable and turn on the local and remote connections setting.
    Click Start button, then go to Programs or All Programs, then select Microsoft SQL Server 2005, followed by Configuration Tools. Click and run the SQL Server Surface Area Configuration.
    On the “SQL Server 2005 Surface Area Configuration” page, click Surface Area Configuration for Services and Connections.
    On the “Surface Area Configuration for Services and Connections” page, expand Database Engine tree, click Remote Connections.
    Select Local and remote connections, or Local connections only which applicable only if there is no remote system tries to connect to the SQL Server, useful when you just trying to connect and authenticate with the server after installing.
    Select the appropriate protocol to enable to local and/or remote connections environment. To ensure maximum compatibility, select Using both TCP/IP and named pipes.
    Click Apply button when done.
    Click OK button when prompted with the message saying that “Changes to Connection Settings will not take effect until you restart the Database Engine service.”
    On the “Surface Area Configuration for Services and Connections” page, expand Database Engine, then click Service.
    Click Stop button to stop the SQL Server service.
    Wait until the MSSQLSERVER service stops, and then click Start button to restart the MSSQLSERVER service.
    Secondly, SQL Server Browser service has to be enabled to allow for local and remote connections if SQL Server 2005 is running by using an instance name and users are not using a specific TCP/IP port number in the connection string.
    Click Start button, then go to Programs or All Programs, then select Microsoft SQL Server 2005, followed by Configuration Tools. Click and run the SQL Server Surface Area Configuration.
    On the “SQL Server 2005 Surface Area Configuration” page, click Surface Area Configuration for Services and Connections.
    On the “Surface Area Configuration for Services and Connections” page, click SQL Server Browser.
    Select Automatic as the Startup type to start SQL Server Browser service automatically every time system starts.
    Click Apply button.
    Click on Start button to start the service immediately.
    Click OK button.
    Finally, if remote computer needs to connect and access SQL Server, an exceptions in Windows Firewall included in Windows XP SP2 (Service Pack 2), Windows Server 2003 and Windows Vista needs to be created. If you’re using third-party firewall system, the exception rules also needed to be created to allow external remote connections to the SQL Server 2005 and SQL Server Browser Service to communicate through the firewall, else connections will be blocked. Consult the firewall manual for more details. Each instance of SQL Server 2005 must have its own exception, together with an exclusion for SQL Server Browser service.
    SQL Server 2005 uses an instance ID as part of the path when you install its program files. To create an exception for each instance of SQL Server, you must identify the correct instance ID. To obtain an instance ID, follow these steps:
    Click Start button, then go to Programs or All Programs, then select Microsoft SQL Server 2005, followed by Configuration Tools. Click and run the SQL Server Configuration Manager.
    In “SQL Server Configuration Manager”, click the SQL Server Browser service in the right pane, right-click the instance name in the main window, and then click Properties.
    On the “SQL Server Browser Properties” page, click the Advanced tab, locate the instance ID in the property list.
    Click OK button.
    Then create an exception for SQL Server 2005 in Windows Firewall.
    Click on Start button, the click on Run and type firewall.cpl, and then click OK. For Windows Vista, type firewall.cpl in Start Search box and press Enter key, then click on Allow a program through Windows Firewall link on left tasks pane.
    In “Windows Firewall”, click the Exceptions tab, and then click Add Program.
    In the “Add a Program” window, click Browse button.
    Click the C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe executable program, click Open button. MSSQL.1 with is a placeholder for the instance ID that is obtained from previous procedure. Note that the path may be different depending on where SQL Server 2005 is installed.
    Click OK button.
    Repeat steps 1 through 5 for each instance of SQL Server 2005 that needs an exception.
    For SQL Server Browser service, locate the C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe executable program, and click Open button.
    Click OK button.

Maybe you are looking for

  • Error message when connecting through USB

    "One of the devices attached to this computer has malfunctioned, and windows does not recognize it." I've tried plugging it into several different ports and restarting my computer. I have the latest edition of iTunes on my PC. I was able to connect i

  • Save As Dialog Different on Exit vs. File - Save As...

    I started by opening a raw file through Camera Raw into a 16 bits/channel document.  My intent was to edit it a little and save as a JPEG. Photoshop CS5 Adobe added the ability to save a 16 bits/channel document as a JPEG, without first having to con

  • Error Code A12E1 and Creative Cloud Update Loop

    Possible Windows Solution - this applies to Windows systems only. Problem: 1) You try to open the Adobe Creative Cloud and receive notification of an update. The options are to Update or Quit. When you click Update, the process starts and then quits

  • Unknown kernel panic,.... panic log doesn't mention any piece of hardware,.

    anyone able to decipher this,....? panic(cpu 0): Uncorrectable machine check: pc = 0000000011D58C80, msr = 0000000000141000, dsisr = 40000000, dar = 0000000025190004 AsyncSrc = 0000000000000000, CoreFIR = 0000000000000000 L2FIR = 0000000000000000, Bu

  • How to pause a video on a slide

    Hi everybody, so i have inserted a video into a captivate slide. Its a mp4 that goes about 6 sec. Video starts well, but after its finished the video disappears. I want Captivate to automatically stop it after 5 sec and freeze (there is a person walk