Problem on security profile
Hi,
We have 5 organization units (A, B, C D and E) in EBS for Payables module. We like to setup 2 user responsibilities.
1. Resp A can only views/operates across the organizations A, B and C. It does not have access right on organization D and E.
2. Resp B can only views/operates across the organizations D and E. It does not have access right on organization A, B and C.
What should I do to have the above security setting? Please advise. Thanks a lot
Regards,
Edmond
Hi,
Please try to follow the below steps:
1. Create a Security profile with Orgs: A, B and C. call it SP1
2. Create a Security profile with Orgs: D and E and call it SP2
3. Assign MO: Security Profile [FND -> Security profile Options] - assign at responsibility level either SP1 or SP2 according to the responsibility.
Hope it helps!
Regards,
YUvaraj
Similar Messages
-
Creating a NEW Business Group, NO Security Profile generated
Platform : R12 running on Linux86 --> FRESH install ( NOT Vision db )
Resp : Global HRMS Super User
Problem : No Security Profile generated for NEWLY created Business Group
After creating a NEW business group ( ie. BG1 )
I am able to see both BG1 and Setup Business Group ( I an view both Business Groups via Organization screen)
When I access the Security Profile screen using the same resp "Global HRMS Super User"...
I can ONLY see the default security profile ( Setup Business Group )...
I am NOT able to view the default security profile ( BG1 ) that should have been created when I created my new business group earlier.
NOTE : If I use the VISION db, and do the exact same thing... I can see both Security Profiles.. and both Business Groups.
If I use the FRESH db, I can see both Business Groups... BUT... only 1 Security Profile... ( Setup Business Group )
WHY ??
Someone please HELP !!
Thank-you
Charlie :)hi charlie i tried the same in my vision instance, i am able to view my BG at the security profile level,
when you query the system profiles,have you enabled the display checkbox at the responsibility level and try, or create an new responsibility and try... let me know the navigation you done clearly,
Raj -
HRMS APP-PER-52803:Your business group does not match your security profile
I see this as a common problem, please guide me as to what should be done to rectify it.
While opening \Payroll\Description, it gives message as under:
HRMS APP-PER-52803:Your business group does not match your security profile
Regards
NemoHi,
I feel that "HR: Security Profile" option is not set properly, BZ of that screen is errors out.
Please check the following Profile Options
HR: Security Profile -- Enter the sec profile name which is business Group name
HR: Business Group -- Your Business Group Name
Note: If you set the HR: Security Profile optional first, then system will sets the HR: Business Group profile option too automatically.
I hope this will solves your problem.
thanks
Krishna Prasad Rapolu
Oracle HRMS Consultant. -
How to restrict employees from accessing managers data using custom security profile
Hi,
I am using custom security profile for restricting the employees from accessing supervisors details(PG.SEGMENT2=4). I have written the custom code as below :
Responsibility :US Super HRMS Manager
ASSIGNMENT.PERSON_ID
IN
(SELECT PAF.PERSON_ID FROM PER_ALL_PEOPLE_F PAF,
PER_ALL_ASSIGNMENTS_F PF,
PAY_PEOPLE_GROUPS PG,
PER_PERSON_TYPE_USAGES_F PPU,
FND_USER FNU
WHERE PAF.PERSON_ID=PF.PERSON_ID
AND :EFFECTIVE_DATE BETWEEN PAF.EFFECTIVE_START_DATE
AND PAF.EFFECTIVE_END_DATE
AND PF.PEOPLE_GROUP_ID=PG.PEOPLE_GROUP_ID
AND :EFFECTIVE_DATE BETWEEN PF.EFFECTIVE_START_DATE AND PF.EFFECTIVE_END_DATE
AND PPU.PERSON_ID=PAF.PERSON_ID
AND PPU.PERSON_ID=PF.PERSON_ID
AND :EFFECTIVE_DATE BETWEEN PPU.EFFECTIVE_START_daTE AND PPU.EFFECTIVE_END_DATE
AND PAF.PERSON_ID=FNU.EMPLOYEE_ID
AND PAF.PERSON_TYPE_ID =2
AND PPU.PERSON_TYPE_ID
IN(2,62)
and PAF.person_id = FND_PROFILE.value('user_id')
AND PG.SEGMENT2=8)
and using "restrict the people visible to each other using this profile".
I have assigned the security profile to HR user responsibility
But when I query the supervisor name in HR User responsibility , it is not restricting me from viewing supervisor details.
When I query for first time, its restricting me to view others details, but when I close that click on torch button and try searching, its allowing me to access manages details.
Can any one please let me know what setups need to be done for restricting employees from viewing supervisors data.
I have gone through the document "Understanding and Using HRMS Security in Oracle HRMS" but didn't got any idea.
Please suggest.
Thanks & Regards,
Anusha.Hi All ,
i solved the problem by using event 01 of header view and using the table "Extract" .
Regards,
Neha -
Hi,
I want to restrict persons records based on their assignment - organizations.
Approach 1:
For this i have created a new custom security profile in Organizatin Security tab
Security Type : Secure organizations by organization hierarchy and / or org list
Organization Hierarchy : <gave our primary reporting here>
selected radio button - use the org on the users's assingemnts as the top org
In the next block under organization name, gave org 1 and selected Include radio button and next 5 orgs (org 2 to org 6 ) and choosed Exclude radio button (Classification column left blank for all orgs).
Assigned this Security profile to resposbility (for HR:Security profile)
When i login to this responsbility and query in enter & maintain form; I am able to see all persons belong to org 2 to org 6; My expectation i should see only those persons whose assignment has org 1;
Approach 2:
I have created one more new security profile (in the custom security tab); selected Restrict the people visible to this profile , and gave in command box
ASSIGNMENT.organization_id = 100 (org id 100 is for Org 1)
and assigned this to responsbility; When i login to this resp , my expectaion is it will show only persons who assignments having org1. But it shows all other persons, whose assignment having differents orgs (org 2 to org 6)
In both the above two approaches, I am not getting what i am looking for.
I have even ran Secuirty List Maintanence program also
I am doing some thing wrong? Please help on this?
We are on 11.5.10
Thanks!!Hi
Is this still aproblem or has Gaurav sorted it out for you. His explanation looks like it will solve the problem, but there might also be a problem in the coding of the custom code. You should be able to achieve what you want without the custom code, by using the organisation tab instead.
Regards
Tim -
Hi Folks,
Could you please help me out to get list of users under the selected MO: Secuirty Profile.
Requirement:
I have a parameter in which i can select MO: Security profiles those are under responsibility level. So based upon this parameter i need to populate all organizations under selected MO Security Profile and in third parameter i need to fetch all users which are under selected MO: Security Profile.
So please help me to sort out this problem.Pl do not post duplicates - How to Fetch organizations under specific MO: Security Profile
Pl continue the discussion in your original thread -
Hi All,
In R12.1.3, Which profile option has higher precedence in MOAC structure.
If i set the HR:Cross Business Group to NO at resp level and MO: Security Profile, which is associated to Global Security Profile which has two OUs of two different BGs.
For example:
I have BG1 - OU1
BG2 - OU2
Case 1:
Global Security Profile - XXGSP has both OU1(BG1) and OU2(BG2) associated.
HR:Cross Business Group - NO
HR:Cross Business Group - BG1
In Purchasing Responsibility, what could be the behavior when i create PO?. Will it show both OU1 and OU2? or OU1?
Case 2:
Global Security Profile - XXGSP has both OU1(BG1) and OU2(BG2) associated.
HR:Cross Business Group - Yes
HR:Cross Business Group - BG1
In Purchasing Responsibility, what could be the behavior when i create PO?. Will it show both OU1 and OU2? or OU1?
Case 3:
Global Security Profile - XXGSP has both OU1(BG1) associated.
HR:Cross Business Group - NO
HR:Cross Business Group - BG2
In Purchasing Responsibility, what could be the behavior when i create PO?. Will it show both OU1 and OU2? or OU1?
Case 4:
Global Security Profile - XXGSP has both OU1(BG2) associated.
HR:Cross Business Group - Yes
HR:Cross Business Group - BG1
In Purchasing Responsibility, what could be the behavior when i create PO?. Will it show both OU1 and OU2? or OU2?
Regards,
SooryaHi Soorya,
We are in a similiar situation and I was wondering if you have received an answer or how you proceeded?
Thanks,
Cathy -
Override Security Profile for one employee
Hi
I have one employee who works in 'Accounts Department' and the HR user of accounts department can see only the employees of Accounts Department based on the security profile. This is working fine. But theres a different requirement. Some employees are transferred to other departments for 3-6 months for different purposes. During this time also the HR user of accounts department needs to view this employees details due to HR policies and procedures. Can we achieve this? If yes, how?
- GulzarQ 1 - When Employee is transferred from Dept 1 to Dept 2 for 6 months, Should the HR for both Dept 1 and Dept 2 be able to see his details for 6 months?
Q 2 - After 6 months period, employee's organization is again updated to Dept 1, should again HRs of both Dept 1 and Dept 2 be able to see his details even after the 6 months period?
Q 3 - If answer for Q 2 is - "after 6 months period, only HR of Dept 1 should see his details" , how to identify Employee's home department? Will it be the Employee's Organization effective as of Employee's hire date? -
Creation of custom security profile
Hi,
During creation of the security profile, there is field 'internal name' .
What is the significance of this field and how the internal name should be maintained. As this field becomes display once the security profile is created.
Pointers will be appreciated.
Rgds,
MadhanHi Madan
Internal name is used by the system to identify a profile. While creating a new profile e.g. System Administrator_XYZ which is lets say based on the original system admin profile but with limited rights (to be given to a few users), you can extend the original internal name and extend it for e.g. fci.profile.admin.xyz
Hope this helps!
Regards
Mudit Saini -
SQL Query in Custom Security when creating Security Profile
Hello all,
I've created a security profile with Custom security and provided a simple query in Custom Security tab-
PERSON.PERSON_ID = FND_GLOBAL.EMPLOYEE_ID
Custom security option is "Restrict the people visible to each user using this profile"
I am not able to see the record as expected.
If I Hardcode the person ID "PERSON.PERSON_ID = 13449" with "Restrict the people visible to each user using this profile", I am able to see the record.
If I Hardcode the person ID "PERSON.PERSON_ID = 13449" with "Restrict the people visible to this profile", I am able to see the record after running PERSLM and same is in PER_PERSON_LISTS.
Am I correct in checking with FND_GLOBAL.EMPLOYEE_ID?
(This was mentioned in system administrator guide :
"+Oracle HRMS assesses the custom security when the user signs on. In addition, the custom security code can include references to user specific variables, for example, fnd_profile.value() and fnd_global.employee_id.+"
docs.oracle.com/cd/E18727_01/doc.121/e13509/T2096T2098.htm).
I have tried with FND_GLOBAL.USER_ID / FND_PROFILE.VALUE('USER_ID') / :ASG_ID (seeded query has a join with this bind variable) - not happening.
I've given options as below :
Employees = None
Contingent Worker = Restricted
Applicant = None
Contacts = All
Candidates = All
All other options - Defaulted
Thanks,
SumanthResolved this - One cannot see self's employee record in the form for which this is setup.
Hence the below query though correct in syntax did not show any data.
PERSON.PERSON_ID = FND_GLOBAL.EMPLOYEE_ID
My original requirement was that all employees belonging to one's Organization should be displayed, and this is working fine with an updated query for the same.
Thanks,
Sumanth -
REQIMPORT errors when security profile set using 12I
I am submitting the purchase requisition import using the following script in release 12I. The request is submitted but completes with an error.
declare
l_request_id NUMBER;
l_batch_id NUMBER := 1027;
l_ou_count NUMBER;
l_org_id NUMBER := fnd_global.org_id;
l_ou_name VARCHAR2(200);
BEGIN
fnd_global.apps_initialize (1759 -- User ID
,50557 -- Responsibility ID
,201); --Application ID
mo_global.init('PO');
mo_global.set_policy_context('S', l_org_id);
mo_utils.get_default_ou(l_org_id, l_ou_name, l_ou_count);
dbms_output.put_line('OU Name: '||l_ou_name||' OU count: '||l_ou_count||' ORG ID: '||l_org_id);
l_org_id := mo_utils.get_default_org_id;
dbms_output.put_line('Default ORG ID: '||l_org_id);
l_request_id := fnd_request.submit_request
(application => 'PO'
,program => 'REQIMPORT'
,description => NULL
,start_time => SYSDATE
,sub_request => FALSE
,argument1 => 'CONSIGNED MANUAL'
,argument2 => l_batch_id
,argument3 => 'LOCATION' --'Location'
,argument4 => NULL
,argument5 => 'N'
,argument6 => 'Y');
dbms_output.put_line('Request ID: '||l_request_id);
END;
The MO: Default Operating Unit and MO: Operating Unit profiles are setup for the given responsibility with an operating unit value. The MO: Security Profile profile is set to a given profile at the site and responsibility level.
When I remove the MO: Security Profile at the site level the purchase requisition concurrent request completes successfully. Only when the MO: Security Profile is set at the site level is the purchase requisition concurrent program submitted using the attached script erroring out.
I can submit the purchase requisition import using the submit request form without any errors. I believe this is because the operating unit field is being populated.
Has anyone run into this issue? Am I missing any commands that define the operating unit used in the concurrent program submission in release 12I?
Any help is greatly appreciated.
CharlesHi,
Only when the MO: Security Profile is set at the site level is the purchase requisition concurrent program submitted using the attached script erroring out.Please see if the guidelines about this profile option in the following documents help.
Note: 784609.1 - How Does R12 MOAC Defaulting Rules and MO: Security Profile Work?
Note: 397362.1 - Multi Org Access Control (MOAC) in Oracle Purchasing
Note: 420787.1 - Oracle Applications Multiple Organizations Access Control for Custom Code
Regards,
Hussein -
Securing WebService with Basic Security Profile
Hi,
I'm trying to write a WebService on EJB 3.0 that is secured with Basic Security Profile. Every message is signed with x509 certificate.
I'm new in Java WebServices and I really don't know how to do it. Can anybody help me?
WebService will be deployed on JBoss 4.2.1 GA with java jdk 1.6Hi,
I'm trying to write a WebService on EJB 3.0 that is secured with Basic Security Profile. Every message is signed with x509 certificate.
I'm new in Java WebServices and I really don't know how to do it. Can anybody help me?
WebService will be deployed on JBoss 4.2.1 GA with java jdk 1.6 -
I gotta problem with security question recovery email I'd, mistakenly I entered wrong email I'd so now I want to edit that I'd plz help me
expresslane.apple.com to get a hold of itunes to reset them by email the only way
-
HT5312 Problem with security question
I have Problem with security question
The Best Alternatives for Security Questions and Rescue Mail
1. Send Apple an email request at: Apple - Support - iTunes Store - Contact Us.
2. Call Apple Support in your country: Customer Service: Contact Apple support.
3. Rescue email address and how to reset Apple ID security questions.
An alternative to using the security questions is to use 2-step verification:
Two-step verification FAQ Get answers to frequently asked questions about two-step verification for Apple ID. -
HT5699 Having problem with security question
Cannot get iTunes card to work having problem with security question
Alternatives for Help Resetting Security Questions and Rescue Mail
1. Apple ID- All about Apple ID security questions.
2. Rescue email address and how to reset Apple ID security questions
3. Apple ID- Contacting Apple for help with Apple ID account security.
4. Fill out and submit this form. Select the topic, Account Security.
5. Call Apple Customer Service: Contacting Apple for support in your
country and ask to speak to Account Security.
How to Manage your Apple ID: Manage My Apple ID
Maybe you are looking for
-
CustomeUpdateUI for native AIR app installer
Hi, We have a native installer for a windows and Mac AIR app. For updates, we use the NativeApplicationUpdater code from: http://code.google.com/p/nativeapplicationupdater/ After an update has been downloaded and launched, AIR shows a dialong prompti
-
InterApplication Navigation in java webdynpro
Hi Gurus , Please guide me for the following scenario : - I have developed an application for InterApplication Navigation i.e one Webdynpro Projcet containing multiple application. My project contained two applications and defined one parameter to
-
I have the ios 5.1.1 restore app downloaded, does any one know how I can install it onto my iPod 4th Gen. please so as to get rid of this ios 6 which, like most people are finding it, rubbish. Thanks.
-
I have an assigment to do which is in Pscedo code and it has to be converted into java usin ann.easyio.Keyboard class for input and ann.easyio.Screen for output. for i from 0 to 2 do output "Enter the name of the employee" set empName to in
-
Facetime is on my dock but won't open.
Facetime is in my applications, is in my dock but will not open. Preferences are greyed out. Would appreciate some help. Thank you. deeel