Java: Find users with specific UME actions

Hi everybody
On the Java UME it is easy to find out which roles, groups and actions a specific user has. The same applies for groups or roles - the connected entites can easily be found.
But how can I found out which users have a certain action? If I browse for the action I have not possibility to find the direct or indirect assignment to the users.
Could somebody assist? Thanks in advance!
Beat

Same problem I faced yesterday for my SSO project on the portal:
My method to resolve  was :
1. Take the user/users in scope  Export  them from UME
2. Export roles into a readable format and check out the actions by comparing the user - role - actions relationship in a TEXT file/readable file
3. pick the roles you want to edit , edit in notepad  import the roles( here I copied and created a Zrole  before importing )
for example ( NWDI.ARCHITECT ) to ( ZNWDI.ARCHITECT)
I could not find easier method than the above

Similar Messages

  • Specific UME Actions required for Deployement in CE 7.1

    Hi Experts,
    I need to know how many and which UME action are required for deploying the application in CE 7.11
    For deployement, we usually assign the UME Role called "Administrator" to the ID that we use for deployment.
    If I remove this "Administrator" UME role, an error message is thrown as...
    com.sap.ide.eclipse.deployer.api.APIException: DeployException,cause=ERROR CODE DPL.DCAPI.1023AuthorizationException
    This "Administrator" UME role has some 2978 UME Actions assigned to it.
    For the UME role "Administrator", inside the assigned UME actions, I have tried filtering the UME Actions based on the filter keyword "deploy", which returned some 14 UME actions.
    Now, I have made following Test case and result.
    Test Case:
    1) Remove the Administrator Role from the ID that is used for deployement.
    2) Now Assign all the above 14 UME actions that were found related to "deploy" keyword to a Custom UME role "DeployRole".
    3) Deploy using the same id.
    Result : Deployement fails with the same above mentioned error.
    Conclusion: There can be 2 possible conclusions...
    1) None of the above 14 UME actions provide the authorization for the deployment.
    2) OR There are some other UME actions which might have some dependecies that are required along with the suspected UME actions.
    In short my requirement here is, to find out the specific UME actions that are required for deployment, so that i can remove the "Administrator" UME role and assign the specific UME actions needed for deployment to a my Custom UME role, and assign this Custom UME role to the user ID for deployment.
    Regards,
    Shreyas Pandya

    Hey Nghia Nguyen...!
    Thanks a lot for your reply, i have rewarded you the points.
    I have found out that for deployment following UME actions are required.
    dc_action (Mandatory)
    auth.all.all (Mandatory)
    deploy_action (Not Mandatory)--> if you remove this deploy_action UME action the deployment will still work, but in developer studio, the Deploy result dialog box with OK button, that pops every time after you deploy your project by right clicking your application and choosing "Deploy new Archive and Run" will cease to appear and the application will directly run in the browser.
    Regards,
    Shreyas Pandya

  • Find roles by assigned ume actions

    Hi
    Does anybody know of a way to find out, which roles are assigned a specific UME action?
    In the identity management I can find a specific role and see all the assigned ume actions, but I want to find a specific UME action and see all the roles, that has this ume action assigned.
    Does anybody know how this is possible? May directly in DB?
    Cheers,
    Jacob Vennervald

    I have now tried to make a small java portal application that handles this but I can't seem to find at method to find which ume actions are assigned to a specific role.
    Does anybody have any input?
    /Jacob

  • SCCM 2012 Report that shows the users with specific software installed

    Hi,
    Is there a report in SCCM 2012 that shows the users with specific software installed? The report should show username, machine name and the software name. I am looking for a report that shows the users with the following softwares installed:
    1. Adobe(all versions)
    2. Photoshop(all versions)
    3. MS Project(all versions)
    4. MS Vision(all versions)
    Regards, Lorin Davis

    Take a look at the Asset Intelligence reports in the software section. You may get a list of computers with a product installed, and you might have to use that list to find the primary users based on user device affinity.

  • Use smart mailbox to find email with specific text in attached pdf

    Does anyone known if a smart mailbox can be created to find emails with specific text within a pdf attached document. I know that spotlight can do this and it works fine but it would suite me better to be able to do this in mail.

    After some digging, I found that Spotlight returns the pdf attachment (found within the library/mail/download folder), but not the actual email. The only time it returns the email is if the search text or numerics are coincidentally within the written contents or subject line.
    Yes, i have tried setting up smart mailbox search criteria using the entire message contents but this does not find emails where the text exist within the pdf.
    I've checked spotlight pref.'s and all categories are checked off.
    Essentally, i need the smartbox search criteria to return results where the search text is found within the pdf attachment if possible. If this is not possible, i'll continue using spotlight searches outside of mail.
    I appreciate any help you can offer.

  • MII 12.1 Unknown Java AS user with permissions of deploy

    hi,
    I have to update a PRODUCTION Environment with Support Packages (unfortunately without a ready Quality one as mirror for testing them).
    So, I'm trying to install again the same software someone else used for PRODUCTION, in a Quality server.
    on
    SO: Microsoft Windows Server 2003 R2 Standard x64 Edition SP2
    I installed successfully SAP NetWeaver CE 7.1 EHP1, but after launching JSPM to install SAP MII 12.1, I'm requested to insert login of an
    Java AS user with deployment permissions.
    In details I undestrood that the path to be followed, after activating Java AS and checking read rights of OS user on JSPM packages folder,
    it should be:
    1- launch the JSPM with OS <SAPSID>adm user;
    2- insert Java AS user credentials with deployment permissions when requested (to log in to JSPM Server).
    3- ...
    n- ...
    on step 2, even inserting user administrator and master password of NetWeaver installation, I cannot proceed.
    Shouldn't it have those rights. How are them called and where can I assign them?
    Looking at the logs of JSPM I found something like this:
    Info: Connecting to Deploy Controller on host localhost port 50004 with user ce1adm.
    Error: com.sap.engine.services.dc.api.ConnectionException: ERROR CODE DPL.DCAPI.1144 NamingException.Cannot get initial context.
    Reason: Exception during getInitialContext operation. Cannot establish connection to the remote server.
    Info:DC API is trying to connect to 'localhost:50004'
    Error: Exception ::SessionImpl::getContext():get ctx. NamingException,cause=Exception during getInitialContext operation. Cannot establish connection to the remote server.
    Even if I try to "add" components starting from NetWeaver installation, I'm requested with a Java EE Administrator I cannot identify.
    any ideas of what's happening?
    regards

    I solved the issue.
    Simply, if you don't assign to the server an host name, it gets standard "localhost" and during jspm login system is somehow confused.
    The problem it was related to a not reachable AS java and not to users rights.
    regards

  • AD accounts find users with all capital letters

    Hello ,
    I am a noob , am searching online but can't find exactly what i need.
    So am posting here in hope some one will help me. :)
    I what to make a short powershell script that finds all users with capital letters from the second letter on.
    Example
    first name = Bob last name =Red    corect
    first name = BOB last name =RED  wrong
    i want to extract all the wrong names with capital letters in text file
    So my question is that possible and how can i do it in server 2008 r2.
    Thanks in Advance for any answers

    This is obviously not an Exchange question, but a PowerShell question.  You should probably post it in the scripting forums for completeness.
    That being said, you can try using -cmatch against a regex.  I used  -cmatch '[A-Za-z]+[A-Z]+' to test a name with later capital letters, and it appeared to work.
    [PS] C:\Scripts> "Willard" -cmatch '[A-Za-z]+[A-Z]+'
    False
    [PS] C:\Scripts> "WILLARD" -cmatch '[A-Za-z]+[A-Z]+'
    True
    [PS] C:\Scripts> "WillARD" -cmatch '[A-Za-z]+[A-Z]+'
    True
    [PS] C:\Scripts> "WillarD" -cmatch '[A-Za-z]+[A-Z]+'
    True
    [PS] C:\Scripts> "WiLlArD" -cmatch '[A-Za-z]+[A-Z]+'
    True
    So for your test, and using the Exchange commands (you can change them to the Windows 2008 AD commands), you'd run:
    Get-User | ? { $_.DisplayName -cmatch '[A-Za-z]+[A-Z]+' }

  • 'Could not find user' with EAP-TLS in ACS

    Hi all,
    we are running ACS 4.2(1) Build 15 on a Win2003 member server and use the ACS for EAP-TLS with certificates (Microsoft-PKI) for WLAN authentication (WLC 4402, 6.0 and 4.2). We are using both machine and user authentication.
    Sometimes machine authentications fail with following message in AUTH.log:
    AUTH 11/01/2010 09:11:28 E 1395 1904 0x31cb External DB [NTAuthenDLL.dll]: Could not find user host/<xxxxxxxx>.com (0x5012)
    But some minutes/hours later the same machine can authenticate successful. Other machines never have this problem, no problems at all with user authentications.
    Does anyone have an idea where I can proceed with troubleshooting? I haven't found any related messages in server event logs. Are there any other logs where I can find reasons for these problems that are occuring only sometimes?
    Thanks
    Kai

    AUTH.log and RDS.log are two log file you need to look into on ACS side. Make sure the log level is set to "Full"
    You might need to check the log on AD side to see why it could not find this host.
    Comparing the logs between the working and non-working cases might be helpful.

  • Create new user with specific UID

    I have posted this question in the 10.4 group but I need to do it on Leopard, too.
    Creating a new user from the Accounts GUI creates users with UID's 502 onwards. How do I create a user from scratch with a specific UID, e.g. 1234?
    I know that modifying user 502 won't work because trash files etc. are set up with 502 in their path names.
    Any help, links to help etc. appreciated.

    Peter,
    In Leopard, UIDs can be changed just as Baltwo described. I do not know if this will also change the UID of files in the user's HOME folder, but you can do that yourself. In fact, it would be a good idea to do so, manually, in any case.
    Go ahead and change the UID for the user as described. This should be done from a different, admin account. Then, open /Applications/Utilities/Terminal. Type the following, followed by a <RETURN>:
    <pre style="overflow:auto; font-family: 'Monaco'; font-size: 10px">sudo chown -R username /Users/username</pre>
    In the above text, you will replace all instances of "username" with the short name for the user in question. If the short name is "fred," for example, you would type the following exactly:
    <pre style="overflow:auto; font-family: 'Monaco'; font-size: 10px">sudo chown -R fred /Users/fred</pre>
    When you press <RETURN>, you will be asked for your admin password. Enter it (it will not be echoed) and again press <RETURN>.
    Scott

  • Find users with Role A and Role B but not Role C

    Hi all.
    How can I find users that have a combination of roles? The find user and user reports only have one line for selecting a role the user has. Is there a report that lets you select multiple roles? It would be really handy!
    Thanks,
    Jim

    If you haven't found it, there are likely no such reports, but it is easy to do that in a custom report. The problem is that its really badly documented how to make a custom report. But, it's really not that difficult if you know what to do. I will, when I get some spare time, post a guide here on how to make a custom report, the way I, and some other people, think it should be done.
    Roughly a custom report consists of three parts, a listing object, to make the report turn up in the report list, a report form, and the report WF. The trick is to know the correct subtypes, attributes and such.
    But take a look here Sunday, and there will possibly be a nice custom report guide posted.

  • Find workstations with specific group in local administrators group

    Hello,
    Is there a simple script that will search the workstations in a domain looking for the existence of a specific domain group nested in the local administrators group ?  Our desktop group can up with the idea of using domain groups nested in the local
    admin group to grant administrator privileges to specific computers.  They can list the members of the domain group easily but they have no easy way to know on what workstations they have added the group to.  Output I am looking for is simply a list
    of computers that have the specific group in the administrators group.   Any advice would be appreciated.
    Bobby

    Thisis donethrough Group Policy.  It is a special aspect of gP to set and mamintain groups on local machines.  You can protect a machine fromchanges and allow users to be added and removed.
    If you are just look ing to list tehcontents o a local group then get the module "Local Administration" in the Repository. It has all of the tools you need.
    You can also use WMI to retrieve Group memmbership.
    ¯\_(ツ)_/¯

  • Powershell to find users with SendAs permission on Public folders

    I have been having great difficulty getting this to work and I am baffled as to what it is I am missing!
    We have a lot of public folders and some users have SendAs permissions - we want to find them.
    I have found various suggestions on line like these two lines -
    Get-PublicFolder -Recurse -ResultSize 10 | Get-PublicFolderClientPermission | Select Identity, User, AccessRights
    this works and lists the folders and all user permissions but my attempts to filter it fail
    Get-PublicFolder -Recurse -ResultSize 10 | Get-PublicFolderClientPermission | Select Identity, User, AccessRights | Export-CSV "PublicFolderPermissions.csv" -NoTypeInformation
    this I is claimed to work (and I would expect it to) but instead fills my CSV with folder and user information but the AccessRights value (clearly displayed in the first example) is replaced by this
    "Microsoft.Exchange.Data.MultiValuedProperty`1[Microsoft.Exchange.Management.MapiTasks.PublicFolderAccessRight]"
    So I tried this
    get-publicFolder -recurse -ResultSize 10 | Get-PublicFolderClientPermission | foreach-object  {write-host $_.Identity, $_.User, $_.AccessRights}
    which works but any attempt to redirect to a file, export to csv or add-content to a file either outputs nothing or outputs everything but gives the accessrights as "Microsoft.Exchange.Data.MultiValuedProperty`1[Microsoft.Exchange.Management.MapiTasks.PublicFolderAccessRight]"
    does anyone have any idea how I get the information I want into a CSV (where I can then filter it) or filter the results by SendAs and save to CSV?
    Obviously the -ResultSize 10 if for testing and will be replaced with Unlimited.
    I assume  my filters on SendAs always failed because rather than passing along $_.AccessRights as the string I see on screen I get the string I see in the CSV so nothing matches SendAs.
    I am clearly missing something obvious so any help would be appreciated.

    That has got me close to it I think but identity returns something like "******.net/Microsoft Exchange System Objects/Info" where "Info" is a public folder under a folder called "Postroom"
    This does at least restricts the results to users having SendAs permission so that is a lot of progress
    Get-publicfolder does translate the returned identity to a path so that should help
    Unfortunately piping to export-csv does not return the desired results
    redirect to file does save the information though so that should be helpful
    Many thanks
    Yes, took all night but I now have enough information to work on

  • SQL Query - To Find Users with end dated responsibilities

    Oracle Apps ver: 11.5.10.2
    Oracle DB - 9i
    How can i list users and the access assigned to them for a specific division irrespective of the responsibility being end dated at responsibility level

    Hi Sakshi,
    Try out this query if it can help you !
    SELECT a.user_name, a.description, c.responsibility_name, c.creation_date as ASSIGNED_DATE>FROM apps.fnd_user a,
    >apps.fnd_user_resp_groups b,
    >apps.fnd_responsibility_vl c
    >WHERE a.user_id = b.user_id
    >AND b.responsibility_id = c.responsibility_id
    >AND a.creation_date < = '01-JUN-07'
    ORDER BY a.user_name;Thanks,
    Anchorage :)

  • Directory service : find user with admin rights

    Hi,
    I'm just taking over an existing LPAD server and i need to know which user on the directory has admins rights.
    I'm playing around with ldapsearch, but i'm not able to get the right search string.
    Os is Solaris 10 5/09 s10s_u7wos_08 SPARC.
    Any thoughts ?
    Thanks,

    Hi,
    Can the user execute the program through explorer? In Windows Server 2003, the Users group does not have Read and Execute permissions to the command processor (Cmd.exe). 
    You could refer to the article below to resolve the issue:
    "Access is denied" error message when you run a batch job on a Windows Server 2003-based computer
    http://support.microsoft.com/kb/867466
    Best Regards,
    Mandy 
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • Event Viewer: How to search and find event with specific text in the EventData

    Hello,
    When I use "Find..." option in the windows event log, it does not search within event's detail or text in <EventData> xml node on the event.
    Is there any easy, out of the box way to find all events that include an specific phrase in the <EventData> ?
    Thank you,

    Hi Allan,
    I‘m writing to check if the suggestions were helpful, if you have
    any questions, please feel free to let me know.
    If you have any feedback on our support,
    please click here.
    Best Regards,
    Anna
    TechNet Community Support

Maybe you are looking for

  • How to skip first screen that is not selection screen.

    Hi Experts I am working on a module pool program where in I am required to call a transaction with skip first screen. the first screen of this transaction is self made screen with screen painter with input boxes and a submit button with an OK_CODE. n

  • [SOLVED] Need to change root password - current one doesn't work

    Hey everybody, Not sure where to put this, so I apologize if it's in the wrong forum. I just installed Arch on my Dell netbook and all is well, except for issues with the root password. I am having a great deal of difficulty getting it to work. I kno

  • Support of XQuery

    Hi, I am wondering about XQuery support, ideally out of the box. Please could you help on it, provide some pattern? Thank you!

  • Duplicates After Syndicating

    Hi SDNers, I facing a problem while Syndicating. I created a Maps for both Importing and Syndicating. In Import Map based on one field I am Importing data. If multiple fields having same field then those records should merge and only 1 record as to C

  • Reinstalled new cmos battery,not error message,code 0176 and 1271

    can anyone help me,i installed a new cmos battery and now the IBM thinkpad T42 is coming up with two error messages, i've looked at what they are , 1 is for time and the other is a security message saying the system has been tampered with, it ask's f