OBIA 7.9.6.4 security for new user

Hi,
I have setup OBIA 7.9.6.4 environement on Linux platform and configured 4 modules financials, Supply chain & Order management, Procurements & Spend and Project.
Then I have created a new user in weblogic LDAP server and assigned to BIConsumers Group, but none of the report are displaying results. so that I can share this user log in details with other user so that they can only open report and should not be able to make any changes to them.
Please advice if anything additional required to done apart steps.
Thanks
Lalchand

Hi,
BI Platform Consumer was already included in both place access to Dashboards and Answers, I have also included the BI Platform Author Role, but still no luck. I am getting below mentioned error
Error Codes: YQCO4T56:OPR4ONWY:U9IM8TAC:OI2DL65P
Odbc driver returned an error (SQLExecDirectW).
State: HY000. Code: 10058. [NQODBC] [SQL_STATE: HY000] [nQSError: 10058] A general error has occurred. [nQSError: 43113] Message returned from OBIS. [nQSError: 27005] Unresolved column: "Fact - Inventory Transactions"."Actual Issue Quantity".Please have your System Administrator look at the log for more details on this error. (HY000)
SQL Issued: {call NQSGetLevelDrillability('SELECT Product."Product Type Description" saw_0, "Movement Type"."Movement Type Description" saw_1, "Fact - Inventory Transactions"."Actual Issue Quantity" saw_2, "Fact - Inventory Transactions"."Actual Receipt Quantity" saw_3 FROM "Inventory - Transactions" WHERE ((TOPN("Fact - Inventory Transactions"."Actual Issue Quantity",5) <= 5) OR (TOPN("Fact - Inventory Transactions"."Actual Receipt Quantity",5) <= 5)) AND ("Time"."Year" = ''2013'')')}
Thanks
Lalchand

Similar Messages

  • GPO not working for new Users (Background)

    Terminal Server 2012 in a hosted environment
    I've set the below policy to set a default background wich can be changed by the users after this.
    The target is an networkdrive. (The Reason behind this is that we have multiple resellers that all have the same networkdrive but pointing to a different store) Lets just say for this example that is P:/Background/ResellerBackground.jpg
    The policy is Linked to the Resellers OU.
    This works perfectly for all the existing users.
    For new users this is not working at all. It does run the policy but it create the profile after running the policies.
    So the above setting gets overruled by the default windows server 2012 background. The RunOnce atribute is set now, so it will not load it again.
    I have read a lot of different sollutions so far, but none are working in this environment. (From changing the default Hive to changing the default picture etc)
    One sollution came close, but not working perfectly either, this is removing the RunOnce atribute from the register, and letting the new users log in again. You do not wanna let new users login twice.
    Before Windows 7/8/2012, in XP it just copied the default user and then the policies ran. So here the problem does not exist. Now it makes the profile after running the policies.
    Anyone having an idea to resolve this issue? 

    Hi,
    Before going further, what’s the value in the wallpaper registry entry
    value data for new users?
    >>One sollution came close, but not working perfectly either, this is removing the RunOnce atribute from the register, and letting the new users log in again. You
    do not wanna let new users login twice.
    If we choose this solution, we can try running cmd command
    gpupdate/force to see whether it can work.
    Another workaround is we can do it from scratch. We can create a new GPO to deploy wallpaper for these new users. The steps are the same as previous ones, just using
    Security Filtering to apply this new GPO to new users, and unlinking and deleting the GPO after the policy getting updated.
    Best regards,
    Frank Shen

  • Data Level security for specific Users

    Hi,
    Can you please suggest some ideas on by-passing the Data Level security for specific users or specific group?
    Currently, we have data level security defined on a group permissions for one group and for people belonging to another group, the security should not apply and they should see entire data.
    But, key thing here is that, the user belongs to both the groups.
    Any ideas helps.
    Thanks,
    Chandu.

    So you are saying you want a user to belong to a group with data-level security filters, but you don't want the filters to apply to that user?
    Why are they in the group then?
    Are the data filter defined with variables or are the hard-coded?
    If variables, you may be able to put logic in initialization block to set the variable appropriately for specific users.
    I'd rethink the security model - when I define data level security filters, I tend to force users to only belong to a single group/role.

  • Is an iBooks Author tutorial available for new users?

    Is an iBooks Author tutorial available for new users?

    You can also try this site for video training on iBA.  It's around $25/month for unlimted viewing and may be easier for some people than reading a manual:
    http://www.lynda.com/iBooks-tutorials/iBooks-Author-Essential-Training/101460-2. html

  • How do i to totally reset iPad for new users?

    How do i to totally reset iPad for new users?

    Welcome to the Apple Support Communities
    Open Settings > General > Reset > Erase All Content and Settings. After erasing your device, turn it off holding Sleep button

  • How to Define Workbook / Business Ares Security Correctly for new Users

    Hi All,
    Please could you help me understand the Security Model for Workbooks and business Areas as I believe I am very close to understanding it, but missing something important.
    Background Information:
    We are using the predefined Oracle Business Areas (Payables, Receivables, Purchasing & General Ledger) to build our reports on. These are the steps I am taking to try and assign a new user & responsibility access to the existing report.
    1. I create the Report in Discoverer Desktop under the ‘General Ledger Responsibility’ logged in as myself – assume report name = ‘Report_1’.
    2. I create a new Responsibility in Oracle Apps called ‘Discoverer Resource Coordinators’.
    3. I create a new User in Oracle Apps called ‘Joe Bloggs’ and assign the responsibility ‘Discoverer Resource Coordinators’ to the Joe.
    4. Logged in as myself in Discoverer Desktop, Responsibility ‘General Ledger’ I Share the Report (Report_1) to the new Responsibility I just created ‘Discoverer Resource Coordinators’.
    5. In Discoverer Administration, Security, I assign the new Responsibility ‘Discoverer Resource Coordinators’ to the predefined Oracle Business Areas (Payables, Receivables, Purchasing & General Ledger).
    6. In Discoverer Administration I set privileges so that the Responsibility ‘Discoverer Resource Coordinators’ can do all tasks, query data, administer. .etc. etc..
    7. I therefore believe everything has been done and attempt to Login and run the report under Joe Bloggs, but am unable to retrieve any data.
    Help… what am I missing!
    Thanks,
    Lance
    Message was edited by:
    Lance

    Dear All,
    This has now been adjusted according to your recommendations but to no avail.
    Myself and Lance have ensured that this new responsibility has unlimited access to all the existing Business areas to eliminate joins within folders not being recognised, we have also ensured that the workbooks that have been created are shared with the correct responsibility.
    I have thoroughly tested this set up by logging in as this new responsibility within Disco. Client to try and retrieve data in a new Workbook, but even for the simplest of queries this fails.
    It seems that there may be a problem with the Responsibility linking to the EUL, could this be due to the new responsibility being created after the Current EUL was set up?
    Does anyone have any information or knowledge where this could happen?
    Regards
    Si

  • Think it is about time to get internet security for new iMac. appreciate recommendation of product

    am interested in getting security for my imac g5. dont know of a good product. Have eset on my pc's is highly rated.

    There are many forms of ‘Malware’ that can affect a computer system, of which ‘a virus’ is but one type, ‘trojans’ another. Using the strict definition of a computer virus, no viruses that can attack OS X have so far been detected 'in the wild', i.e. in anything other than laboratory conditions. The same is not true of other forms of malware, such as Trojans. Whilst it is a fairly safe bet that your Mac will NOT be infected by a virus, it may have other security-related problem, but more likely a technical problem unrelated to any malware threat.
    You may find this User Tip on Viruses, Trojan Detection and Removal, as well as general Internet Security and Privacy, useful: The User Tip seeks to offer guidance on the main security threats and how to avoid them.
    https://discussions.apple.com/docs/DOC-2435
    More useful information can also be found here:
    www.thesafemac.com/mmg

  • Full true Administrator Privileges and rights for New User?

    I am wondering how to grant full administrator privileges to a newly created user?
    Here is the environment:
    Windows 2012 Server 64bit
    Not part of a domain <WORKGROUP>
    Here is the problem:
    I created a new user we will call them "SecondaryAdmin", and made them part of "Administrators" group as well as the "Remote Desktop Users" group.
    I login through an RDP session as "SecondaryAdmin", I go to a command prompt, and I run IISRESET and it tells me:
    "Access denied, you must be an administrator of the remote computer to use this command. Either have your account added to the administrator local group of the remote computer or to the domain administrator global group."
    Additionally, I have IE Enhanced Security turned off, but if I open Internet Explorer while logged in as "SecondaryAdmin" it still displays the IE Enhanced Security warnings.
    Also, if I try to copy a file to the root "C:\", it gives me "Access denied error" forcing me to continue with elevated administrator privileges.
    If I run the command prompt as "administrator" I can do an IISRESET without error.
    If I run Internet Explorer as "administrator" I do not get the warnings.
    If I run windows explorer as "administrator" I do not get the access denied.
    However, I WOULD NOT trust this "SecondaryAdmin" account to install ANYTHING. Even if you ran the install executable as "admin", often times these install files will fire off secondary scripts that wont be fired off as "admin",
    which may lead to incomplete or corrupt installs.
    This changed from Windows 2008 R2 to Windows 2012.... If I do the same exact thing in Windows 2008, I am able to do all the above things without prompt or error.
    So how can I give a new user true, full, elevated, admin privileges without having to run everything as administrator? Some obscure setting in GPO? Some registry setting (already tried LocalAccountTokenFilterPolicy)?
    What I have tried:
    UAC is OFF
    Firewall is OFF
    IE Enhanced Security is OFF
    Remote Management/Desktop Enabled
    User part of Administrators Group and Remote Desktop Group
    Used "netplwiz" to verify user is Administrator
    Please help!

    Hi Chris,
    I appreciate your answers, however, this is not what I am looking for.
    I want the "SecondaryAdmin" user, who is part of the Local Admininstrator group, to have full Admin access.
    I DO NOT want them to have to do anything special, or have any user intervention.
    NO yes/no dialog boxes
    NO clicking "Run As Admininstrator"
    NO changing shortcuts or executable file properties to always "Run as Admin"
    I simply want the "SecondaryAdmin" account, which is part of the "Administrators" group, to have the same access and run the same seamless way it did in 2008 R2, with no user intervention required.
    This is what I am looking for.
    Kind Regards,
    James

  • No password sent in GRC10 notification for new users

    Hi,
    I have a strange problem in our GRC10 system. 
    We send email notifications to users on completion of user access requests after provisioning is complete.  The notification contains the PROVISIONING variable, so new users should be notified of their initial password in the message.  This works fine on tests against our development system.  The email contains the user ID, the roles assigned, and the password information.
    However when the same process is followed in our Production system, the notification only contains the user ID and roles provisioned - no sign of any password information.
    We're currently running GRC 10.0 SP13.  The plugins are all updated to the same level.  We have the global provisioning configuration set OK, and all SAP Notes that appear to be related to the problem have been applied - but I still can't get emails to be displayed in the email notifications to new users.
    Can anyone offer any hints or suggestions to try?  I have even looked at password-related startup profile parameters as a last desperate straw.  I found 4 differences in settings between our Dev and Prod systems. would theses cause an issue?  the parameters were:
                                                                       Dev             Prod
    login/min_password_digits                               0                  1
    login/min_password_letters                              0                  1
    login/password_downwards_compatibility          1                  3
    login/password_max_reset_valid                     N/A                30
    That 4th parameter doesn't exist in our Dev profile.
    please help - I'm desperate on this one...

    Hi Ian
    I'm starting to run out of suggestions for you.I would probably put a trace on the RFC back to the GRC to see what the system user does. AS well as that check ST22, SM21 and SLG1 logs to see if any error. Already you've confirmed configuration and system match each other so it's down to data and security or program issue.
    In using the trace, may be able to identify the function module/RFC and then do a consistency check on the code to make sure nothing out of the ordinary there.  Depending on your background grabbing an ABAPer would help her.
    Also, as it's your production system do you have multiple app servers and load balancing in play? It's one area where your DEV and PROD may vary. Possibly the password is "leaving" the plug-in but getting lost in the nether as it goes to your GRC. I'm taking a complete stab here and showing my deficiency in Basis and System Admin.
    Otherwise, unless Marketplace has another correction not you probably need to raise an Incident.
    Regards
    Colleen

  • Creating a default User account for new users

    Today I tried creating a default setting for and account that could be used for all new users.  I did web searches after web serches and not luck.  In the old systems it was simple, but Mavericks made it difficult.  But after much hair pulling and putting several suggestions together it is just as simple as it was before.
    Step 1 Create a new user account
    Step 2 log on to that account and set it up totally, that means background picture, preferences, dock, everything
    Step 3 click on the home incon in a finder window then go to Finder view select view options and at the bottom check show library
    Step 4 go to HD>system library>user templates, you will need to select the file, Command I for info, unlock the lock, click + at bottom select your admin account, give youself read write permissions, go click on the folder you wish/need to change and get info and repeat the step above for each folder.
    Step 5 replace the library folder and any other you wish to change with the one from the new account
    Step 6 you can also place any documents on the desktop or document folder and replace them
    Step 7 create a new user account and verify that the settings and dock are correct.
    This takes about 5 minutes or so and is much easier for the non pro

    I don't always understand how things can be different from one computer to the other running the same systems and following the same steps but I have 2 iMac's and the steps above for the desktop picture worked on one but not on the other, go figure.  So as a fix the default picture was named Wave in the Desktop Picture folder so I changed the name of it to Wave1 and renamed the new photo Wave,  did not change the alias in the CoreService folder, now the second computer creates and new user account with all my perferred settings and background picture.
    As a recap of my orginal post by creating a default user account, setting up the preferences for finder, and setting up the dock, I simply replaced the preference folder in the User Template file and it works perfectly.  Remember that you can do the same with the Document folder or the desktop if you want to place them for all new users. 
    Since I am not a professional computer person I do not feel comfortable using the terminal or scripting so this works very well for the common person to create a new user template.

  • Romaing Profile no longer being created for new Users hwne they login

    After creating an account in WGM and logging into a computer that is joined to the domain, the server is unable to create the roaming profile for the user as it has done for previous accounts. I get the following popup message from Windows which indicates a permission problem I think:
    Windows cannot locate the server copy of your roaming profile and is attempting to log you on with your local profile. Changes to the profile will not be copied to the server when you logoff. Possible causes of this error include network problems or insufficient security rights. If this problem persists, contact your network administrator.
    DETAIL - Access is denied.
    Windows cannot find the local profile and is logging you on with a temporary profile. Changes you make to this profile will be lost when you log off.
    If I create the directory manually under /Users/Profiles and then login to the account the profile is created and it operates normally for that account from there on.
    I haven't changed any permissions on this Directory but I have recently changed the Directory Administrator password as well as the local Administrator password. Could that be the problem?
    17" 2.16 MBP, 2G G5 PM, 23 Al Display, 20 G5 iMac   Mac OS X (10.4.7)  

    Hi there
    Sorry for the delay.
    No, this is still an open issue, the way I fixed it is I decided to start using an LDAP to store dynamic creation of user entries. With LDAP it work perfectly.
    Sorry but I've got no solution at this time
    Rp

  • With the new seession in IE gives session error for new user

    Hi,
    In new opened IE if i tries to login with new user. It is switching b/w the files in the status bar(ie., Header1.jsp and ListServicecall.jsp simultaneously) and at end the session error result will arise.
    But for the second time if i login with the same username/password the page is displaying properly. please Can any one help out.
    Thanks,
    Satish R

    First time if the user logins to IE in the HP Service Desk(SD) page. Some of the pages will iteratively loops and give a session expires error. After that the user logins to the page with no error.
    If i create a new copy of the data from the existing folder and if i try to run then the result will be error for that folder also.
    ie., Assume folder 123 where, first time for every new login user the session expire error occurs. later they'll login without any problem.
    If i rename the folder 123 to xyz/create new copy and rename then, the same problem repeats. First time for the new user it will give session expire error and later he can login to the HPSD page with no error.
    Is it require cookies to be programmed in that program.
    Regards,
    Satish R

  • Outlook Web App error for new user (Exchange 2010)

    Hello,
    Recently, our new  user can't get on OWA because their regional setting page is returning "An unexpected error occurred and your request couldn't be
    handled." 
    with "Url: https://mail.shdm.org:443/owa/languageselection.aspx" 
    I've search many site and i've not been able to find a working solution.
    I've check the redirection, everything seems ok
    here is the complete detail message
    An unexpected error occurred and your request couldn't be handled.
    Request
    Url: https://mail.shdm.org:443/owa/languageselection.aspx
    User: [email protected]
    EX Address: /o=SHDM/ou=Exchange Administrative Group (FYDIBOHF23SPDLT)/cn=Recipients/cn=promoteurs790
    SMTP Address: [email protected]
    OWA version: 14.3.195.1
    Exception
    Exception type: System.ArgumentNullException
    Exception message: Value cannot be null. Parameter name: value
    Call stack
    Microsoft.Exchange.Clients.Owa.Core.Utilities.RenderDirectionEnhancedValue(TextWriter output, String value, Boolean isRtl)
    Microsoft.Exchange.Clients.Owa.Core.LanguageSelection.RenderTimeZoneSelection()
    ASP.languageselection_aspx.__Render__control1(HtmlTextWriter __w, Control parameterContainer)
    System.Web.UI.Control.RenderChildrenInternal(HtmlTextWriter writer, ICollection children)
    System.Web.UI.Page.Render(HtmlTextWriter writer)
    System.Web.UI.Page.ProcessRequestMain(Boolean includeStagesBeforeAsyncPoint, Boolean includeStagesAfterAsyncPoint)
    Hope that someone can help!
    Alexandre

    Hi,
    I have seen this same error before. That issue resolved by Exchange 2010 SP3 RU7.
    So please refer to KB 2961522
    and install Update Rollup 7 for Exchange 2010 SP3 to solve this issue.
    Best Regards.
    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact [email protected]
    Lynn-Li
    TechNet Community Support

  • Safari and Chrome will not display some pages right for new user account

    Not sure this is a Safari issue actually. Behavior is also in Chrome, but not Firefox. If I need to post elsewhere please advise.
    24"imac running 10.5.8. 2gb ram, software update run,
    Setup a new user account. Machine will have 2 users.
    When I login as the new user, in both Safari and Chrome, some pages - google, ebay, amazon, cnn, yahoo, do not display correctly. Mainly empty space, a few graphics all wrong. They do display correctly in Firefox.
    I assumed it was the user. So I added a 3rd user. Same behavior. Tried giving the new user admin rights. Same problem.
    For the admin account, everything's fine on those pages, both in Safari and Chrome.
    It feels like the new user is not getting access to something it needs, but it also feels like more than a font problem. Thanks for any suggestions. Dan

    Thanks for your thoughts. Here's what I've learned. The browsers display correctly for the new user after SafeBoot. I removed all startup items, to no avail. Removed all fonts from the new user account, nothing. Removed all fonts from the admin user's library, nothing. Then I removed all fonts from the HD library, and that fixed it for the new user. Now I just have to figure out which one it was.
    So in summary, a bad font in the HD library was affecting Safari and Chrome (but not Firefox) in new user accounts, but not in the admin user's account. Nice. D

  • Created mailbox for new user in Exchange 2010, user not visible in AD.

    Hi everyone!
    This morning I created a mailbox for a new user on my Exchange 2010 box.
    Everything works fantastically but I am unable to view the new user in AD except by searching.  If I run a search the results say the user exists in my Users container, and I can view the properties of the user account from the search results, but I
    am unable to actually see the user profile object in the Users container.
    I notice in EMC that the mailbox has a user icon on the mailbox icon instead of the regular standard icon - I'm not sure what this implies.
    Can anyone offer some advice as to why this happens and how to resolve it?
    Thanks!

    Hi,
    AD objects store in the Domain partition Database.
    Its replication Scope is :Domain Wide
    Its replication model is: Multi Master
    There are two possible cause.
    1. AD replication latency if you have several DCs.
    You could wait for AD replication or force replication, Click
    refresh on ADUC.
    2. You create the new user
     in other OU, not  Users.
    You could run this command to get
     the user’s DistingushedName attribution.
    Get-mailbox –identity
    [email protected] |fl
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

Maybe you are looking for