Issue with group mapping in ACS.

When we map AD group in ACS with ACS group it coming as AD group and * (As below “ ,* ” ) , Because of this * everybody is able to login irrespective of his AD group.
Please suggest way to only add the NT Group alone without the *.

Actually '*' means something else.
If you have a group on AD say 'Alfa'
when you do a mapping on ACS, you'll see it like this,
'Alfa', * ------- Group x
Above means, if a user a member of Group 'Alfa' on AD, AND can also have any other group membership on AD (meaning of *), then map it to Group x on ACS.
It does not mean map everyone to Group x, even if they are not a member of Group 'Alfa' on AD.
As mentioned by JG above, all the users are able to authentication because of your 'All other combination' or \DEFAULT mapping on ACS.
Map them to .
Then only those will be able to log in, for whom you have the mapping defined on ACS.
http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.1/user/GrpMap.html#wp940538
Check Step 8,
"The asterisk (*) at the end of each set of groups indicates that users who are authenticated with the external user database can belong to other groups besides those in the set."
Regards,
Prem

Similar Messages

  • Issue with heat maps refresh process in EID 3.1?

    Issue with Heat Maps in EID 3.1? Heats maps don't refresh unless you go back to home page and then again go back to the Endeca app.
    In Oracle Sample app if we open the Map tab we will see that Milwaukee is really hot in the heat map. now if we filter the data to just show data from 100 miles within Orlando, FL then the map will get refreshed to show that area but the colors on heat maps do not change.
    Now if we keep the refinements same and go back to home page and again go back to sample app and maps tabs then it will still show area of 100 miles within Orlando, FL which is good but now heat map would have updated and it would show us correct color.
    Now if we remove the refinement then it would show complete US map as hot which is again wrong.
    I have observed this issue in chrome browser as well as firefox.
    Is there anyway to overcome this issue?

    This issue was resolved after applying latest patch from Oracle.

  • Has anyone had an issue with group addressing in OS X 10.9 Mail

    Has anyone had an issue with group addresses in Mail after installing Mavericks?  Both my MBP-15 and my Mac Pro stopped automatically filling in the addresses when I typed the name of the group that I have in Contacts, after updating to Mavericks.  Prior to updating they worked just fine.

    Hi,
    I just found these work arounds.
    https://discussions.apple.com/thread/5490015?tstart=0
    The first is appropriate if you want to send as an undlisclosed resicpient. The second method shows all addresses.

  • User in a windows group - mapping to acs group appears not be working

    I have a user in a windows group, this windows group is mapped to an ACS group but when the user logs in it appears as default group in ACS.
    Any suggestion?

    Hello, I recently implemented this very thing, actually integrated it with Authentication Proxy. Here are some settings to check:
    1. External User Databases - Database Configuration - Windows Database - Configure
    Make sure your domain is listed on moved to the Domain List section
    2. External User Databases - Database Group Mappings - Windows Database - - Add Manual Mapping
    Make sure you have the right AD group mapped to the internal ACS group, you can even set users* if you want to include all users.
    3. External User Databses - Unknown User Policy
    Check the "Check the following external user databases" radio dial and move Windows Database to Selected Databases
    Check “The database in which the user profile is held” radio dial in the Configure Enable Password Behaviour section
    Hope that helps!

  • OBIEE 11g Issue with "group by"

    Hello,
    I have issues with the physical queries generated by OBIEE engine.
    All the facts are at detailed granular level. when I query the table, group by clause is excluded from the query. following is the sample query generated by OBIEE 11g engine.
    select 0 as c1,
    D1.c2 as c2,
    D1.c1 as c3,
    D2.c3 as c4,
    D2.c2 as c5,
    D2.c1 as c6
    from
    (select distinct T48494.SMBL as c1,
    T48494.EXP_DT as c2
    from
    VW_CONTRACT_DETAILS T48494
    where ( T48494.EXP_DT in (TO_DATE('2012-09-03 00:00:00' , 'YYYY-MM-DD HH24:MI:SS'), TO_DATE('2012-09-19 00:00:00' , 'YYYY-MM-DD HH24:MI:SS')) )
    ) D1,
    (select sum(T48494.TRADED_VOL) as c1,
    sum(T48494.TRADED_VAL) as c2,
    sum(T48494.TOTAL_TRADES) as c3
    from
    VW_CONTRACT_DETAILS T48494
    where ( T48494.EXP_DT in (TO_DATE('2012-09-03 00:00:00' , 'YYYY-MM-DD HH24:MI:SS'), TO_DATE('2012-09-19 00:00:00' , 'YYYY-MM-DD HH24:MI:SS')) )
    ) D2
    order by c3, c2
    I'm getting similar kind of issues(exclusion of group by from query) even when i query other fact tables as well. Is there any global change to be made?
    Regards,
    Kishore

    Does it mean you are expecting a group by on
    D1.c1, D1.c2?
    So query should like
    select 0 as c1,
    D1.c2 as c2,
    D1.c1 as c3,
    D2.c3 as c4,
    D2.c2 as c5,
    D2.c1 as c6
    from
    (select distinct T48494.SMBL as c1,
    T48494.EXP_DT as c2
    from
    VW_CONTRACT_DETAILS T48494
    where ( T48494.EXP_DT in (TO_DATE('2012-09-03 00:00:00' , 'YYYY-MM-DD HH24:MI:SS'), TO_DATE('2012-09-19 00:00:00' , 'YYYY-MM-DD HH24:MI:SS')) )
    ) D1,
    (select sum(T48494.TRADED_VOL) as c1,
    sum(T48494.TRADED_VAL) as c2,
    sum(T48494.TOTAL_TRADES) as c3
    from
    VW_CONTRACT_DETAILS T48494
    where ( T48494.EXP_DT in (TO_DATE('2012-09-03 00:00:00' , 'YYYY-MM-DD HH24:MI:SS'), TO_DATE('2012-09-19 00:00:00' , 'YYYY-MM-DD HH24:MI:SS')) )
    ) D2
    group by c3, c2 ---> added line
    order by c3, c2

  • Special characters issue with Nokia Maps on N95

    Hi there,
    when using Navigation in conjunction with Nokia Maps on my N95, all streets and towns which contain any special character in their name (for example: é, è, ü, ä, ö, etc…) do appear as unreadable garbage on the screen of the N95.
    I only noticed the problem after having purchased the 3 years license Navigation upgrade (EUR 99.99) and immediately notified Nokia. That was back in October. Since then I have called them at least 10 times and ultimately I have asked for a refund as no solution is still available.
    In all these calls with Nokia, the only reasonable argument I heard was that maybe (!!!) the new software update version 20.0.015 released back at the end of November could solve the issue. Unfortunately, for my phone (which is a branded one) the update is not yet available.
    Today, after calling them again, I was told that Nokia’s policies do not foresee refunds and therefore my request has been rejected. I was told to bring my phone to a Nokia Store and see if they can help me (I don’t see how). I was also told that maybe I would have to send-in the phone for repair.
    This is soooo frustrating that despite the 3 months of patience and all the money spent for the N95 (not quite cheap), the navigation upgrade and the phone calls to Nokia, I still have the same issue. I will probably end up filing a complaint with a monthly consumer’s magazine in the hope they will publish my story.
    After all, it may not even be Nokia’s fault but rather the guys who are responsible for the maps, but if Nokia accepts to have a commercial venture with a vendor, than they also accept liability for the joint product. And by turning down my legitimate request for refund, they have proven not to give a **bleep** about people like you and me.
    Forgive me for the long post - needed to release some of the frustration...

    I have been using an N95-8GB since Nov.'07. From my experience with this phone that has a built-in mass memory besides the phone memory. I had trouble retrieving some of the softwares I have installed. For eg. I have saved some themes in the mass memory & I could not find it when I want to delete it. There are some 3rd parties games software inside where I cannot even delete
    This is what I don't like about the phone. I have bought an N82/Black recently as it uses an external memory card.
    Coming back to Nokia maps. Personnaly, I don't think they are that good & I have problem downloading it into my phone from my PC after having downloaded it from Nokia.
    By the way the Nokia map is not even the latest map 2.0. Is still a 1.0
    I used Navfone map software & it works OK in the 8GB. You have to purchase it.
    I have used a couple of N-series phones in the past ie. N-90, N-70, N-71, N-73, N-80/Black, N95, N-95/8GB & now N-82.
    Common with all N-series phones. After you have disconnected when you are done with your call you have to wait for a while before the word "disconnected" disappears.
    The more features it has, the more problem you are gonna to encounter.
    Unless you want to download softwares into your phone & have a good camera thats where the N series phones come in.
    For normal usage, a 40 series phone will suffice.

  • FDM: Issues with importing mapping using excel files

    Hi All,
    I am trying to map ICP Entries using an excel file.
    I have made 2 mapping (explicit) entries, manually and exported it in Excel and then added all the Mappings in the same file, in proper format. when I am importing, I am not getting any error but the mapping is not getting updated and the new entries are also not getting added. so Ideally no Change in the tDatamap table.
    Environment details: FDM Version 11.1.1.3 is getting used. Target App is Essbase 11.1.1.3. able to connect to Essbase, no issues with connectivity.
    Has anyone face this issue.

    The section of the admin guide I reference will tell you how to create a properly formatted excel workbook. Import XLS will work if the excel workbook is set up properly. The import XLS functionality will not change existing records, only add new ones.
    Your template requires that the first cell is the table name. The second row is the table field names and rows 3 through X are the values to be inserted into the table. The named range beginning with UPS needs to highlight all of these rows and columns.
    Quite honestly, if you take the time to review the admin guide, I'm sure you'll find the answer that you need. Please understand that, like you, most of us that post on this board are consultants. We share knowledge to help the community better utilize the product. It's frustrating to hear that none of the answers that I previously provided you were at all helpful.
    Edited by: TonyScalese on Nov 30, 2010 3:23 PM

  • Ipsec Stateful Failover issue with Dynamic-Map

    Hi all, I have an issue with a couple of Cisco ISR 2921 in Ha Ipsec Stateful Failover configuration.
    With static crypto-map, stateful works good, Ipsec sessions are correctly trasmitted from Cisco Active router to Cisco Standby router.
    With dynamic-map and profile, stateful fails, Ipsec sessions are not correctly trasmitted from Cisco Active router to Cisco Standby router.
    I tried different IOS version:152-1.T3, 152-3.T2 and 153-1.T but I have the same behavior.
    Could you help me?
    Marco

    Yes it is supported. It is supprted on VAM, VMA2, VAM2+.

  • Create Business Partner-FPP1-issue with grouping

    HI
    I am trying to create business partner using FPP1 transaction with my own grouping but i am getting error.
    error "You cant create a customer with grouping PS05'.
    here PS05 is my own grouping with number range defined.
    please check the attached screens for details.What is wrong with my grouping? am not sure.
    Any help is greatly appreciated,
    regards
    giri

    Hi Giri,
    Seems like you have done the setting for BP grouping with internal number range which is fine. Please be advised that business partner groupings need to have different number ranges and different data has to be entered for each business partner type.
    If you getting this error in-spite of defining the number range and assigning the number ranges in customizing then perhaps you missed out the assignment of Business Partner (BP) Type since Business Partner types can be used to group business partners.
    When a BP is created, the "business partner type" appears on the initial screen and the control data screen. BP type offers grouping possibilities for business partners.
    You can define and assign BP types in
    Cross-Application Components->SAP Business Partner->Business Partner->Basic Settings->Define Business partner types.
    BP types are defined by a unique partner type number and a description. After this you can proceed to configure field attributes in the "field grouping" as per the selected business partner type.
    Let us know if you get the same error in-spite of maintaining the above mentioned settings.
    Thanks,
    Sagar

  • Issue with user mapping and SAP reference system

    Hello Gurus,
    I have this strange system behaviour when preparing my system for single sign-on using user mapping.
    Case 1.
    In the user management property category, I have the following defined.
    Authentication Ticket Type - SAP Logon Ticket
    Logon Method - UIDPW
    User Mapping Fields  -
    User Mapping Type - admin, user
    In the alias editor, I defined the default alias as SAP_PRD
    Result= when I go to identity management to assign the reference system (the default alias - SAP_PRD)...I do not see the system alias there.
    Case 2:
    In the user management property category, I have the following defined
    Authentication Ticket Type - SAP Logon Ticket
    Logon Method - SAPLOGONTICKET
    User Mapping Fields  -
    User Mapping Type - admin, user 
    In the alias editor, I defined the default alias as SAP_DEV
    Result, when I go to the identity management to assign the refernce system (the default alias - SAP_DEV), I see it there.
    What might be my issue? Does it mean I can't assign SAP reference if I am using UIDPW as logon method?
    Please help me.

    Hi Mahesh,
    Thanks for the feedback. I am relatively new to EP...so please I won't mind if you can guide me on how to go about this.
    This is what I did...
    I chose System Administration > Permissions
    In the PCD, I located my system with the alias, SAP_PRD
    It opened up the permission assignment area.
    Now I have these permissions set
    Administrator - Full Control
    Administrators - Full control
    com.sap.caf.eu.gp.roles.superuser - Full control
    Everyone (built in group) - Full control
    Everyone (Everyone role)- Full control
    super_admin_role - Owner
    For all the above End User box is checked.
    I can't find anyone end user group .
    Once I pick UIDPW, the alias disapperars from the reference system list.
    Please help.

  • Issue with Group folders on XServe

    Hi,
    I have an Intel Quad 2.66Ghz XServe with 10.4.10 Server installed. I am trying to set up two different groups. There are two folders on the Shared RAID HD. Group A need to have access to both folders, whilst Group B has access to only one of them.
    I have set up two different groups, and which users apply to which group. I have then set up the shraes on the HD, and with the shares I have applied which group has access to which folder.
    But for some reason when I log on from the workstations, even though I have set up what they have access to, both Group A and Group B have access to all the files.
    Is there something I am missing.
    Under Sharing I go the the folder and then under the Access pane on the right for the Group I assign the group folder and give it Read and Write Access, and then, for the other group folder I do the same.
    There must be something I am missing.
    If someone could please maybe give me a detailed explanation, I can see where I have gone wrong.
    Thanks in advance,

    I also have another issue,
    I am moving everything across from a previous Mac OS Server.
    I have imported all the accounts and groups.
    I noticed under the sharing tab, when I go to the protocols tab, on the previous OS Server could choose inherit permissions from parent, but on the new XServe, this option is greyed out, how is it possible to check this tab.
    Thanks in advance.

  • HP Officejet 4500 Wireless Printing Issues with Online Maps & Financial Institutions

    I have an HP Officejet 4500 Wireless printer that I have wireless connection to my HP G72 Laptop running Windows 7 (64 bit) with Internet Explorer 9.  I am having trouble printing online maps from either Bing Maps or Google Maps.  It seems the print jobs get stuck in the print que and always show an indefinite status of “Printing” in the que but never get printed.
    I’ve tested my other applications including Office 2010 and all other jobs seem to print just fine.  I do use the “Print” button located in each of the online Map sites (Bing, Google).  This is when the jobs get stuck.
    I do also have the HP Bing Bar installed with Smart Print.  The Smart Print feature seems to work with the online maps just fine (seems I’ll just use it instead).
    Another separate printing issue is that I can never get any of my online financial transactions to print from any of my online financial institutions with either the Internet 9 print features or the HP Bing Smart Print feature.  I can never get those to print (have to wait for the PDF statements to be available).
    Any ideas as to why I can print the maps or online financial transaction?  I get no error messages either.

     Hi,
    Please use the following tips/instructions to fix:
        http://h10025.www1.hp.com/ewfrf/wc/document?docname=c02221706&cc=us&lc=en&dlc=en
    Good luck.
    BH
    **Click the KUDOS thumb up on the left to say 'Thanks'**
    Make it easier for other people to find solutions by marking a Reply 'Accept as Solution' if it solves your problem.

  • Issue with Grouping.

    Sorry for length of htis post.Only way to describe issue was with example.
    I have a report which lists details at Store levels.
    Input Data is as follows:   [ Simplified ]
    Store Name Store Id   Details
    Bath            0001        0001aaaa
    Bath            0001        0001bbbb
    Bath            0001        0001cccc
    Chelsea       0678        0678aaaa
    Chelsea       0678        0678bbbb
    Chelsea       0678        0768ccc
    Derby          0500        0500aaaa
    Derby          0500        0500bbbb
    Derby          0500        0500cccc
    etc.
    I grouped the Report by Store Name. 
    There is no summation - or data manipulation required.
    The reason for Groupng is simply to allow:
    a) To Group and Sort Report by Store Name
    b) To throw page after each Store
    c) To facilitate Group Tree. 
    Expected result.
    Bath            0001       
    0001aaaa
    0001bbbb
    0001cccc
    Throw page
    Chelsea      0678 
    0678aaaa
    0678bbbb
    0768ccc
    Throw page
    Derby          0500       
    0500aaaa
    0500bbbb
    0500cccc
    Throw page       etc
    Actual Result:
    *Bath            0001*
    *0001aaaa*
    *0001bbbb*
    *Throw page*
    *Bath            0001*
    *0001cccc*
    Throw page
    Chelsea      0678 
    0678aaaa
    0678bbbb
    0768ccc
    Throw page
    Derby          0500       
    0500aaaa
    0500bbbb
    0500cccc
    Throw page etc
    So Bath [ in this example ] has two Groups.
    Bath is shown twice in the Group tree.
    One Group Displays all Subdetails - Except one   
    The second Group Displays only One line of sub details.
    This only occurs for one store  [ out of 200 or so ]  
    Initially this occured for one store. Which was arbitary [ i.e. Not nec. the first alphabetically ].
    In the end I enforced the sort order in the SQL which produced the data.
    This had the effect of moving the issue to the first store [ alphabetically ] but stil onlu one store.  
    Obvious stuff.
    I have checked the data. The value 'Bath' is derived from the same field in all cases.
    [ It picks up store name from a lookup table to decode the Store number for a more meaningful display ]
    So there is no possibility that this is data related.  
    This issue has been driving me mad.
    I eventually had to use a work-around; where I grouped by Store Number instead;
    This had the expected effect. Although the Group Tree is not as user friendly and the group is not in alphabetic order.
    The users use store name & store number with equal familiarity - so they are happy for now.
    But I need to know what happened here.
    Edited by: Joe Coen on Jun 9, 2009 1:29 PM

    Well, I waded my way through it, and (provided I got the right end of the stick), I'd start with the following to figure out what's going on.  My thinking is that there are two groups - probably different storeNumbers, but with the same (or similar) names:
    Have group on StoreName, and also another on StoreNumber - that way when you get to the Bath groups, you can see what StoreNumbers they relate to.  This might highlight the fact you have a "Bath" and a "Bath       "  (leading/trailing spaces), or two "Bath" stores. I know you say you've checked the data, but it's worth double-triple checking before you go mad.
    You could also check for the trailing spaces by having a formula to group on (rather than the store name) that takes the form of ">>>""<<<" - this would highlight any leading/trailing spaces.

  • Issue with Transporting Mapping

    Hi,
    There is a strange issue that we are facing while importing a mapping from one PI server to another.
    Source PI server : PI 7.1
    Target PI server : PI 7.1 EHP1
    For the first time the softwarecomponent was import successfully. However eventually there were certain changes in the mapping and the mapping was transported to the target system.
    While doing so we encountered an issue stating :-
    The source structure, target structure, or a function library has been changed or could not be
    found in the Enterprise Services Repository. The mapping definition contains elements or attributes
    that does not exist in the changed structure, or function that were changed in a function library.
    The relevant entries will be deleted
    calculate122222222222222 function not found
           Signature of field  'a'  has changed
           Signature of field  'b'  has changed
           Signature of field  'c'  has changed
    Howerever there is no such udf in the original software component. Also there is no Udf with name calculate.
    There is no common udf for all the 3 target fields as well.
    There is only an RFC lookup that is common among the 3 fields, but without any field 'calculate'
    Kindly advice in case anyone has encountered such an issue.
    Regards,
                Milan Thaker

    > calculate122222222222222 function not found
    This is a default name, when the function is not found. You don't find the real function name in the error message.
    If you use a standard function and this is no longer available after import -> OSS ticket.
    If it is a global UDF, import it before the mapping.

  • Performance issue with grouping components

    Hi Guys,
    I am building a dashboard in Dashboards 4.1 using Live Office connections. The initial summary view contains multiple charts, labels, customized image components, etc. which have all been grouped into one component. The user needs to able to filter the dashboard based on "Dept Name", "Employee Type" and "Month".
    Now, to filter on "Dept Name", there are 5 different check boxes provided for each department inside a pie chart. Based on the selection, all the data in the dashboard will change. The way I am thinking of achieving this is by creating 5 copies of the initial grouped component and then setting dynamic visibility on each based on the check box selection. I will also change the data mapping for each copy of the grouped component.
    Similarly, I am thinking about doing the same for the filter for "Employee Type" & "Month"
    My question is - Is this a good method to achieve the task ? Will it cause any performance issues ?

    copying the same set of components 5 or 7 times will result in a model that is slower to load and mat be slower to use. If possible try to limit the number of components to one set and move the data around the spreadsheet instead. This can be hard in some cases, and depending how you do it could also affect performance.
    I have found that the more objects you copy on the canvas the more liable to corruption the file gets as well.
    As always, designing a dashboard is a balance between complexity and usability.

Maybe you are looking for

  • I am unable to cancel my Adobe Creative Cloud membership

    The help FAQ tells me to go to a page that looks different than the FAQ shows, and when I try to contact via chat, it does nothing. Going to maybe have to call tomorrow, but I'm frustrated that you don't have the option available to do it myself, tha

  • How to get today date in mm/dd/yyyy

              How do i get today date in mm/dd/yyyy format ?           Thanks           Michael           

  • Positioning of Screen

    I have a little card game, when I run it the screen is in the top left hand corner of the screen? Is there any way I can make it start in the middle of the screen? Thanks, Johnny C

  • Howto change or delete TEST_ARCHIVE_STORE in XMLDAS

    Hi Experts, we configured the archiving in the Adapter Engine of SAP XI 7.0 and used (for testing purposes) the Filesystem TESTARCHIVE_STORE Now we want to use a WEBDAV System but unfortunatly we cannot reasign / unasign the TESTARCHIVE_STORE to WEBD

  • Having Trouble With Image Preloads

    Can somebody please tell me what I'm doing wrong? Check out my homepage - http://www.huppbrian.us The links on there are all supposed to rollover, and they do... kinda. Hold your mouse over one of them, and you'll see the appropriate rollover behavio