Restricting Queries in HR: Compensation Management User Group

I am trying to restrict the Infoset /SAPQUERY/HR_XX_CM_03, which contains salary/compensation queries, assigned to User Group /SAPQUERY/H0, from being accessed by anyone.  In SQ03, user group /SAPQUERY/H0, there are no users assigned but users with access to SQ01 can select the user group /SAPQUERY/H0  and access the queries tied to infoset /SAPQUERY/HR_XX_CM_03.  Why are users able to access the infosets of the user group when no users are assigned to the user group?

Turns out that security authorization for access to SQ01 had an S_QUERY value of 02 which allows for full change.  With this value the user group/user assignments done via sq03 did not work.  Setting S_QUERY to 23 allows for user group assignment to restrict access in sq01

Similar Messages

  • Managing user groups

    Hi, I have just begun to look into Connect as an LMS solution for an upcoming project. I will have a number of user groups - different clients (companes) that I will want to have organized with access permissions. is there an area in Connect where I can manage this? For example can I add 50 people in company A to a preset list and then push an eLearning module/lesson to them?
    If there is a manual you could direct me to that adresses this that would be great as well.
    Best, Steve

    Sorry Just found this, you can delete this thread - sorry! :-)
    Steve

  • Managing users, groups and shares with Mavervicks server

    I recently upgraded from Snow Leopard Server to Mavericks.
    In Snow Leopard, WorkGroup manager was the primary way to create shares, users and groups. Now it would seem that it is optional and in fact, I do not even see how to create a share in WorkGroup except for perhaps a group share which I'm not quite sure how to do.
    For my setup, I have setup Open Directory and create a few Local Network users. DHCP is managed via my airport and the DNS is on but only for server and points to my Airport IP address.
    QUESTIONS:
    Should I be managing users with WorkGroup manager or server app, Whats the advantage? 
    I don't have user profiles (files) stored on the server they are local. That being the case, why does each user have a network folder on the server?
    Thanks!

    Workgroup Manager and MCX are deprecated.  These technologies should only be used if you can not accomplish your tasks with Server.app and Profile Manager.  If you have specific requirements that can not be satisfied in Server.app and Profile Manager you should send feedback to Apple.
    So to your questions:
    Should I be managing users with WorkGroup manager or server app, Whats the advantage?
    I don't have user profiles (files) stored on the server they are local. That being the case, why does each user have a network folder on the server?
    1:  Ideally, no.  Unless...  You are supporting machines prior to 10.8.5 or can not find an equivalent function in Server.app and Profile Manager.  There is no advantage to using it.  Apple will eventually stop distributing it.  It is available now for legacy support only.  If you have a need for MCX management then WGM remains viable.  But, ideally, you should be looking to Profile Manager.
    2:  This is because you created your accounts using Local Home Folder template instead of None - Services Only.  The Local Home Folder template has the unfortunate side-effect of creating a user home folder on the server.  I too dislike this.  If you only want to use the accounts for services, then you should create the accounts using None - Services Only.  By the way, it is safe to delete these home folders if you would like.
    Reid
    Apple Consultants Network
    Apple Professional Services
    Author "Mavericks Server – Foundation Services" :: Exclusively available in Apple's iBooks Store

  • Cannot Manage User Groups for sampleportal

    Hi:
    Hopefully someone has seen this and has a solution. We've installed the sampleportal
    application and have begun to add portal pages and new portlets as a proof of concept.
    We're trying to entitle a portlet to a specific User Group. The groups exist.
    However, clicking on the User Group Mgmt. link yields a NullPointerException. Trying
    to edit a user brings up the Edit User Attributes page with the link to edit the
    password, but another NullPointerException for the Property Sets and Properties associated
    with REAPVisitor1 Edit portion.
    Hopefully someone has an idea. Any help would be appreciated!
    Thanks,
    Chris
    The error text for the User Group Mgmt. is:
    An error occurred:
    java.lang.NullPointerException:
         at com.bea.portal.admin.visitor.servlets.jsp.taglib.GetPropertiesTag.doStartTag(GetPropertiesTag.java:95)
         at jsp_servlet._tools._portal.__edit_user_group._jspService(__edit_user_group.java:1061)
         at weblogic.servlet.jsp.JspBase.service(JspBase.java:27)
         at weblogic.servlet.internal.ServletStubImpl.invokeServlet(ServletStubImpl.java:265)
         at weblogic.servlet.internal.ServletStubImpl.invokeServlet(ServletStubImpl.java:200)
         at weblogic.servlet.internal.RequestDispatcherImpl.forward(RequestDispatcherImpl.java:241)
         at com.bea.p13n.appflow.webflow.servlets.internal.WebflowServlet.doGet(WebflowServlet.java:168)
         at javax.servlet.http.HttpServlet.service(HttpServlet.java:740)
         at javax.servlet.http.HttpServlet.service(HttpServlet.java:853)
         at weblogic.servlet.internal.ServletStubImpl.invokeServlet(ServletStubImpl.java:265)
         at weblogic.servlet.internal.ServletStubImpl.invokeServlet(ServletStubImpl.java:200)
         at weblogic.servlet.internal.WebAppServletContext.invokeServlet(WebAppServletContext.java:2495)
         at weblogic.servlet.internal.ServletRequestImpl.execute(ServletRequestImpl.java:2204)
         at weblogic.kernel.ExecuteThread.execute(ExecuteThread.java:139)
         at weblogic.kernel.ExecuteThread.run(ExecuteThread.java:120)

    Chris,
    Please report this to the support, so that this can be looked into.
    Thanks
    Subbu
    Chris Wolfe wrote:
    Hi:
    Hopefully someone has seen this and has a solution. We've installed the sampleportal
    application and have begun to add portal pages and new portlets as a proof of concept.
    We're trying to entitle a portlet to a specific User Group. The groups exist.
    However, clicking on the User Group Mgmt. link yields a NullPointerException. Trying
    to edit a user brings up the Edit User Attributes page with the link to edit the
    password, but another NullPointerException for the Property Sets and Properties associated
    with REAPVisitor1 Edit portion.
    Hopefully someone has an idea. Any help would be appreciated!
    Thanks,
    Chris
    The error text for the User Group Mgmt. is:
    An error occurred:
    java.lang.NullPointerException:
         at com.bea.portal.admin.visitor.servlets.jsp.taglib.GetPropertiesTag.doStartTag(GetPropertiesTag.java:95)
         at jsp_servlet._tools._portal.__edit_user_group._jspService(__edit_user_group.java:1061)
         at weblogic.servlet.jsp.JspBase.service(JspBase.java:27)
         at weblogic.servlet.internal.ServletStubImpl.invokeServlet(ServletStubImpl.java:265)
         at weblogic.servlet.internal.ServletStubImpl.invokeServlet(ServletStubImpl.java:200)
         at weblogic.servlet.internal.RequestDispatcherImpl.forward(RequestDispatcherImpl.java:241)
         at com.bea.p13n.appflow.webflow.servlets.internal.WebflowServlet.doGet(WebflowServlet.java:168)
         at javax.servlet.http.HttpServlet.service(HttpServlet.java:740)
         at javax.servlet.http.HttpServlet.service(HttpServlet.java:853)
         at weblogic.servlet.internal.ServletStubImpl.invokeServlet(ServletStubImpl.java:265)
         at weblogic.servlet.internal.ServletStubImpl.invokeServlet(ServletStubImpl.java:200)
         at weblogic.servlet.internal.WebAppServletContext.invokeServlet(WebAppServletContext.java:2495)
         at weblogic.servlet.internal.ServletRequestImpl.execute(ServletRequestImpl.java:2204)
         at weblogic.kernel.ExecuteThread.execute(ExecuteThread.java:139)
         at weblogic.kernel.ExecuteThread.run(ExecuteThread.java:120)

  • Professional Users Groups?

    I have recently transitioned to a team that supports Streaming and live content for our company. We use Streaming Media Services, with the intent to move to IIS Media Services.
    Are there professional users groups for this service?  While supporting Configuration Manager I belonged to the Houston Area Systems Management Users Group (HASMUG), and attended events such as MMS and System Center Universe.  I was wondering if
    similarly focused groups exist to support Streaming Services.

    Care to share what the error message said and which OS system you are using?

  • Creating User Groups

    Hi All,
    How can I create User groups in Application Express 4.0.1.00.03.
    I am not able to find the link for creating User groups after logging in as found in the Help:
    1.Log in to Oracle Application Express. See "Logging In to Oracle Application Express" in Oracle Application Express Application Builder User's Guide.
    The Workspace home page appears. Note I have logged in as administrator for Internal Workspace.
    2.Click the Administration icon. - Not able to find
    The Administration page appears.
    3. From the Tasks list, click Manage User Groups. - Not able to find
    The User Groups page appears.
    Thanks & Best Regards
    Arif Khadas

    Hello Arif,
    >> Note I have logged in as administrator for Internal Workspace
    You should login to your working workspace as a developer with workspace administrator privileges. At the Application Builder home page you’ll see the Administration icon, and within it the Manage Users and Groups icon. In this module, you should select the Manage User Groups Task.
    Regards,
    Arie.
    ♦ Please remember to mark appropriate posts as correct/helpful. For the long run, it will benefit us all.
    ♦ Author of Oracle Application Express 3.2 – The Essentials and More

  • WinRMRemoteWMIUsers_ vs. Remote Management Users

    Hi,
    I'm not sure about the differences between these two local groups on a Windows Server 2012 or if they are nested somehow. Membership in one of these group is sufficient to access a remote server via Server Manager. I can see the 'Remote management users'
    group in the PSSessionConfiguration, but I cannot see the WinRMRemoteWMIUsers_. How does it work?
    Many thanks!

    See the following technet info:
    http://technet.microsoft.com/en-us/library/dn579255.aspx#BKMK_WinRMRemoteWMIUsers_
    "The WinRMRemoteWMIUsers_ group allows running Windows PowerShell commands remotely whereas the Remote Management Users group is generally used to allow users to manage servers by using the Server Manager console."

  • SQ01 - User Group Restrictions

    Using transcation SQ01-Sap Query in the HR module is it possible to restrict users to specific queries. I have assigned users to user groups, but this does not appear to prevent users outside of the group running the query.
    All users concerned have access to the transaction with authorisation value '23'.
    Thanks
    Simon

    Hi,
    Did you check what are the restriction given while creating a Query.
    For more info
    http://help.sap.com/saphelp_nw04/helpdata/en/d2/cb42cb455611d189710000e8322d00/frameset.htm
    Cheers
    Soma
    Message was edited by:
            soma pradeep

  • Restrict user group authorization on reporting

    Hi all;
    I've problem restriction of user groups on monitoring reports.
    By using RSSM transaction I gave only one user group to reach the reports but I still see the other groups on report.
    Thanks.
    Korel.

    Hi Chris,
    There is no standard report available for this purpose. However all this information is stored in table UME_STRINGS.
    You can write your own SQL queries to generate such reports. However please note that this table is not normalized, and it's a master UME table. You should use it strictly for READ ONLY purpose.
    For a sample code you which i wrote some time back, you might refer:
    http://forums.sdn.sap.com/thread.jspa?threadID=2088099&messageID=10859334#10859334
    Thanks
    Prashant

  • How to restrict a user group of SQ01 for only execution for some users

    Hi,
       I would like to know if it is possible to restrict the access to SQ01 transaction for some users. I would like that these users have only execution access to some queries associated with an user group.
       Do I have to associate the user group to the users I want to have access to it? How can I do it=
       Do I have to associate the queries created on SQ01 to the users? or it is enough to assign the users to the user group where the queries are defined?
       Do I have to associate the infosets created on SQ02 to the users? or it is enough to assign the users to the user group to which the infosets are associated?
       Thank you,
       Luz D.

    I suggest you do a web search on SQ01 and SQ02. That'll bring along SQ03 as well.
    There's so much information available on the web that there's no reason to repeat it here.
    [try google|http://www.google.com/search?hl=en&safe=off&q=SAPsq01sq02&meta=]
    Jurjen

  • How do I get system users/groups to appear in the Workgroup Manager list?

    When I open the Workgroup Manager and select the Users tab, it only shows users set up in the Workgroup Manager -- same when I browse Groups. But, I also have a couple system users/groups set up not in the workgroup manager, but through the OS's System Preference interface for Users.
    Is there a way to automatically have System users appear in the Workgroup list?
    I also can't add users to System groups, since the groups also won't appear in the Workgroup Manager (like adding a user to the group Admin or Staff -- default system groups).
    I'd just like the option to "show System users and groups" somewhere.
    Thanks.
    Patrick

    Hi
    If I understand your post correctly then launch WorkGroup Manager and select Preferences from the WorkGroup Manager Menu. Enable the Show "All Records" tab and inspector option and click OK. In the Users/Groups/Computer tab you should now see the addition of another icon - it looks like a bullseye. Select this and under the filter field selecting 'AccessControls' will show you a long list. Scroll down and select Users. Now go back to the Users tab and you should see all users visible and invisible. You’ll see the same thing for Groups.
    You will see different Users and Groups depending which directory node you are in. In the LDAP node you should only see Directory and System Administrator as well as VPN MPPE Key Access User in addition to any user you have created within that node. In the local Net Info node you should see users such as Amavisd User, Clamav User, Cyrus IMAP User etc. You’ll also see UIDs and GUIDs amongst a wealth of other information if you select a user or group and select the Inspector tab.
    You can modify record attribute and values as well as adding your own. You can even use WGM in the same way you would use Net Info Manager locally if you wish.
    Tony

  • Is there a way in 10.8 Profile Manager to assign certain users the sole right of adding/removing users to user groups?

    Hello,
    I want to assign certain network users the ability to login via browser to the profile manager for 10.8.x server and add/remove other users from user groups.  Think teachers managing their class rosters, if the class was a group and the users their students.  I do not want any other admin funtionality beyond that for them.
    Suggestions?

    Well thank you for being so polite.  Yes, on looking on my 10.8 server, I have the same thing.  How annoying.  I have no idea how to answer your question.  If the management abilities are no longer in Workgroup Manager then there's a change that the server doesn't pay any attention to the settings, so manually changing settings in LDAP won't have any effect either.
    At least I can verify that it's not just you who gets that result.  I wonder what happened and how we're meant to do this now.

  • Nested AD User Groups in Workgroup Manager not working in Mavericks

    The setup is the traditional Golden Triangle, so Active Directory for users and groups, Open Directory for Managed Preferences. Both Apple clients and server are running 10.9.0
    While I can successfully manage the Mac's via OD computer groups, the OD user groups with nested AD groups no longer appear to work. If I nest an AD user it works fine, but not the AD users group.
    This is a new AD and new OD, no migrations. This is a setup I've done countless times over the years, but since Mavericks has been introduced, I can no longer make this work.
    Any help would be greatly appreaciated.
    Thanks,
    Alex Price

    Hello
    I have been having the same problem, when adding an AD Group to an OD group the users in the AD group are not managed, but if i add the user to the OD group it works fine, (with about 5000 active users this is not an option) this has been a problem with 10.9 and has not been fixed with 10.9.1, i assume we need a update to Workgroup manager?
    Maverick server is useless at the moment, cant upgrade the clients to Maverick if i cant manage them, are Apple just tring to make my job more difficult than it needs to be, i was happy that they provided Workgroup Manager for Mavericks because Profile Manager is simple not an option, but it would be good if it worked properly, its not a small problem so you would think apple would make it a priority.

  • Restrict metadata field during an update to a specific user group

    Hello everyone,
    I am having some trouble figuring out the best way to restrict permissions to change some metadata fields for 2 different groups of users.
    I have two user groups, A and B. Group A will be checking in documents that the B group will then review for accuracy and quality. Group B will then update an optionlist field called "Status" with either "Recommended" or "Not Recommended".
    This is not a workflow situation as the scope requires that all documents are immediately available for searching. I currently have a CheckIn and Search profile for the content permitting read write access to groups A and B. The "Status" field is hidden on the CheckIn page. Can anyone please suggest a good way to restrict the field "Status" on an Update page to just "B" users? Groups A and B should be able to update all fields with the exception of the B restricted "Status" field.
    Thanks!
    Edited by: user6750815 on Jun 2, 2010 4:11 PM

    Hey rMac,
    I understand it this way you have one profile for A and B user groups. On this profile Status field is hidden.
    If this is your problem you can approach it from two places, while making the rule for hiding the Status field, use rule activation condition. Make it active only for users with Role A . This way even with single profile some of the user with Role B will be able to see the Status field.
    otherwise you can put similar code in Restrict Personalization Link where in you make this hidden field editable and compulsory for Users in B.
    cheers,
    sapan

  • WLCS USer/Group Management

    Hi,
    I am having a problem with the WLCS3.1 UserManagement part.
    The application we are buildin basically consists of two pieces, Internet
    and extranet( site
    accessible to our customers/partners by logging in).
    The internet part has couple of forms that our prospect customers submit and
    this user profile information gets stored in Oracle.
    The second piece isour extranet, which works in sync with our Customer
    Relationship Management appliction. The users information is put into
    Netscape DirectoryServer(NDS) by our CRM application ans we just use it for
    authentication and single sign on into both the application.
    Since the User Management system works in conjunction with the WebLogic
    Server's security realm (which happens to be LDAP for us), we cannot store
    user/groupes anymore into oracle by using JSP taglibraries.
    My question is, if we can store just the user (and password) in NDS LDAP and
    the
    GROUP and profile in WebLogic and personalize the content based on this
    info.?
    If so, what is the best workaround for this..
    Any help is greatly appreciated.
    Thanks
    -sarath

    Hi Tracy,
    Are you trying to create property sets?
    If you are trying to create a user/group property set, then you do that with the EBCC tool. See the "Site Infrastructure" tab and
    use
    File --> New --> Site Infrastructure --> User Profile to create a new one. See "Creating a Property Set Definition" at
    http://edocs.bea.com/wlp/docs70/dev/usrgrp.htm#998997 .
    Tracy Ward wrote:
    How do you assign Property sets in the user group management - the set shows in users and groups - but not in the management window--
    Ture Hoefner
    BEA Systems, Inc.
    4001 Discovery Drive
    Suite 340
    Boulder, CO 80303
    www.bea.com

Maybe you are looking for

  • Importing PL/SQL function in Discoverer Admin

    Gents I'm trying to import a PL/SQL function. In fact this functions is in a package. When I try to import in Discoverer Admin, I'm not able to see this package and the function. It's possible import a function from a package in Discoverer? Must a gr

  • AVCHD to Final Cut Pro to Avid - how?

    I filmed AVCHD material using a Sony HDR-SR12E. First, I put the footage in Final Cut Pro via the special logging dialog (is there a way to adjust the codec FCP puts the footage in?). After editing the footage in FCP, I would like to export the mater

  • My ipod 2g is not showing on my pc and when i try to restore it it says that it can't connect to update server

    my ipod is not working(the itune  say it is in recovery mode) and it ask me to restore it but when i try to restore it the itune says that it can't connect to updateserver ps: i tried to disable my norton software and delete the textin the host file

  • Video too dark

    I downloaded a few tv shows and movies and all seem too dark, especially the black & white movies. I know its not just the monitor because the playback is the same on all monitors and on my HDTV monitor when played back through AppleTV. Interestingly

  • My big library gets Itunes 7 and my whole pc very slow

    Hello, Since i installed Itunes 7.0.0, i notice that when i launch it, my whole pc is getting very slow. My mouse doesn't move properly. Il still have the problem with 7.0.1 and 7.0.2... Then, i thought that i had a big library (nearly 20.000 songs).