Room role and user assignment
Hi ,
We are on EP6 SP10 and have a strange issue involving
collaboration rooms.We are having MS-AD UME.
Now after changing from one ldap to another , some users
are displayed as ldap id's in the rooms while some are not.
They are displayed properly with name itself.
Why is this so? Is this because they have been deleted in the
ldap but not in the room , something like that.
Also there is no way to remove these id's from the room too,
this generates a runtime error.
Any help on this would be appreciated
Regards
Vineeth
Hi Vineeth,
Why is this so? Is this because they have been deleted in the
ldap but not in the room , something like that.
Sound reasonable, if this is in fact your situation.,
Also there is no way to remove these id's from the room too,
this generates a runtime error.
Ýou could try to remove the users from the corresponding group via the UME. For each room, there is a group created in the UME with the name "ROOM_[roomname]_MAIN" and the ID "ROOM_[roomid]_MAIN". Open that group and try to remove the user entries in question from there.
Hope it helps
Detlev
Similar Messages
-
Table that stores the business role and user id mapping
Hi,
i want to know the table that stores the Business role and the business role and user id mapping in CRM system.
Thanks in Advance.
Regards,
PricyHi Mary,
There is no direct table but there is a way to find it.
HRP1263 is the table where business roles are stored when maintained at org level. These are stored against the Position.
For getting user ID and position linkage refer table HRP1001.
In HRP1001 table use below criteria to get the User and Position.
OTYPE = CP
SCLAS = US
SOBID = User ID
ENDDA = 31.12.9999
Get the OBJID
Query the HRP1001 table again with following
OTYPE = CP
OBJID = OBJID from above Query
ENDDA = 31.12.9999
SCLAS = S
SOBID = Thats Position.
Pass the position to HRP1263 as below.
OTYPE = S
OBJID = POSITION
PROFILE - Thats business role assigned for the given position and user.
Hope this is helpful.
Regards,
Naresh -
Moving roles with user assignment
Hi There,
Need your help...
We have roles and users created in QA for training, now we want to move roles from QA to Production with user assignment.
Users that are created in QA for training have also been created in Production, is it possible to move the roles from QA to Production with the user assignment.
Thanks and Regards,
Azher.Table PRGN_CUST does'nt contain any entries, its an empy table in QA.
USER_REL_TRANSPORT entry with value NO locks system from TR imports with User assignment. So you have to ensure your target system-Production does not has that entry in PRGN_CUST.
TR is geting created in Local change request which cannot be moved to Production.
This TR request are created in Local Change request only when you do not specify a target system/group . All you need to do is specify the "Target" while creating the TR in PFCG (subsequent screen after you hit Create request) and release your TR via SE10. Once released, the TR would be added to the import queue of Production. You/your Basis team can import it manually via STMS_IMPORT (Extras>Other requests>Add TR and CTRL+F11 to import). If there are any errors please have Basis team to review the transport logs.
P.S: You can only transport direct user assignments of roles via PFCG transport option described in my post. In case of indirect user assignments that were created using Organizational Management (HR-Org), you will have to use transport functionality in Organizational management.
Thanks
Sandipan -
Is it possible to export and import the roles and users tables?
Hi,
is there any possibility to export and import the role and user definitions?
We have a SAP MDM repository with a lot of roles and users and also with a lot of changes.
And now I'm searching for a fast and efficient way of managing the roles and users.
Thanks and Regards, MelanieHi Melanie,
There is no export/import functionality for roles and users. The only way to manage these in an automated way would be to write a program that uses the Java or ABAP APIs. Both APIs expose functionality to create, update and delete roles and users.
Hope this helps,
Richard -
Configuring roles and users (adf security) application context wise.
Dear All,
I referred this tutorial (http://biemond.blogspot.com/2008/12/using-database-tables-as-authentication.html) which shows how to hook up adf security with database schema but at domain level which will be common to all applications in that domain. I want to make it different to each application. (i.e each application will use differene database schema for storing user credientials i.e enterprise roles,application roles and users.)
Can any one please point me to proper way..
Regards,
Santosh
jdev 11.1.1.2.0Dear Frank,
<i>
Instead you have a single identity management system and have the application policies being different for the applications.Using ADF Security, users and groups can have different privileges in different applications
</i>
suppose i have 3 applications that use adf security, the users will be common to all applications. right..?Roles and group can be different for applications.
application polices means roles and group..?
So how it(application polices) can be made different for applications? is it inbuilt or some configurations needed ?. Can you point me to some blogs or tutorials for more reference.
Bet: Incase i hook up adf security with database schema.
Regards,
Santosh. -
Identify system defained roles and user defained roles
Hi,
I have an issue.
Oracle Version : 9.2.0.1.0
Operating system: Windows 2000 server
How can we identify system defained roles and user defained roles?
Please help me to solve this.
Regards,
Mat.Check yourself these views
DBA_ROLES
DBA_ROLE_PRIVS
USER_ROLE_PRIVS
ROLE_ROLE_PRIVS
ROLE_SYS_PRIVS
ROLE_TAB_PRIVS
SESSION_ROLES
For default predefined roles in the database, take a look at the below url.
http://youngcow.net/doc/oracle10g/network.102/b14266/admusers.htm#i1008784
Regards,
Sabdar Syed. -
Extraction of roles content and user assignment
Dear all,
we want to transfer some CCA-rights to BI into a table, which will be referenced in a role in BI.
Purpose is to tranfer the authorization concept from ERP to BI.
I have to write for this some function module, which might be a bit complex but not impossible.
Has anyone experience with this?
Regards
Harald.HII,
To search for roles with no users assignment u can run a report RSUSR070 AFTER EXECUTING TCODE SA38 in the progran field enter the name of the report and click execute button u get roles by complex selection criteria then scroll down and in the selection according to user assignments select without user assignment then cli ck execute button u will get the roles with no user assigments............
Thanks and regards -
Hi,
Can anyone tell me where the user to collaboration room role assignments are stored? UME? KM? Portal DB?
It would really help me understand the room architecture. Also if a user gets deleted out of our LDAP (not via the portal) I would like to be able to make sure they do not have any "old" room roles assigned to them.
Thanks in advance,
SimonHi
We are having EP6.0 with MS-AD UME ,
Now after changing from one ldap to another , some users
are displayed as ldap id's in the rooms while some are not.
They are displayed properly with name itself.
Why is this so? Is this because they have been deleted in the
ldap but not in the room , something like that.
Any help on this would be appreciated
Regards
Vineeth -
Previously I had created a role and added a user. The user
waited several weeks to try to login and now is receiving a message
that his role is no longer valid. When I login to administer the
site his role is not listed and when I re-created the role I can't
add him because his name is 'grayed' out and indicates that he is
currently assigned to the previous role.
Has anyone else had this problem? How can I fix it?When selecting "Database", a Planning Create will create (or recreate) the Planning application in Essbase. This will erase any Planing supporting detail, account annotations, etc. It will also (IIRC) blow away the Essbase database.
A Planning database refresh updates Essbase with metadata changes (if any).
You know, I've never tried doing a Create->Security Filters.
Now if you mean Administration->Manage Security Filters->Create -- that will just update the filters with whatever the latest and greatest dimensional security is. If you selected all of the filters, it is as if you did a Administration->Manage Database->Security Filters. The idea being you might want to target it if you have many users/large filters.
I think the first time that user logs in you will see the username in the Administration->Manage Security Filters list.
Going backwards, re your first question -- provision the username in SS with access to the Planning app (however you do that, groups, individually, etc.), and give him Essbase server access. Have him log in. All should be good to go.
Regards,
Cameron Lackpour -
Restrict Moving roles with user assignment
Hi There,
Need your help...
How to restrict to move roles from dev->QA with user assignment. (want to disable the user assignment restirction)
Thanks and Regards,
GnanaprakasamUnfortunately this is not the default installation setting, so you need to go into the security settings customizing and change the USER_REL_IMPORT switch to 'NO'.
This does however NOT make the checkbox disappear in the transport source system. It prevents the import in the target... so you must set it and transport it there first, then it works.
Cheers,
Julius -
Roles and user (SUIM)
how to find the roles of a transaction and who use(d) the tcode
Hi Rishi,
The role contains the authorizations, users need to access the transactions, reports, web-based applications and so on, contained in the menu.You can assign a role to an unlimited number of users.
Regards,
Satish -
Authorization group in Z-Table and user assignment
Hello,
I have created Z table which stores sensitive data and have created maintenance view. I want particular users only to have change access to this table through SM30 and for that I have created my own autorization group. Now my question is: How I can assign user names to this authorization group? how does it work? Is this through Role assignment to user profile? I dont have any basis support help for me for this task and hence trying to do it myself in sandbox system.
Since this is not my domain step by step help will be appreciated.
Thanks.
Agasti..HI,
useful link
http://www.richardsantos.net/2009/03/16/sap-how-to-create-and-use-the-authorization-objects-in-abap/
Thanks
Sudheer -
Problem with role and user; user can't see the table
Hello forum,
I've created a role:
CREATE ROLE enr_service;
GRANT CONNECT TO enr_service;
GRANT ALL ON Locataires TO enr_service;
GRANT ALL ON Batiments TO enr_service;
GRANT ALL ON Sportifs TO enr_service;
GRANT SELECT ON Epreuves TO enr_service;
and also a user:
CREATE USER ENR1 IDENTIFIED BY password QUOTA UNLIMITED ON USERS;
GRANT enr_service TO ENR1;
ALTER USER ENR1 DEFAULT ROLE enr_service;
ALTER USER ENR1 DEFAULT TABLESPACE USERS;
I can connect to the database with this user but when I try to query a table he's been granted access to I get an error message:
SELECT * FROM Sportifs;
ORA-00942: table or view does not exists
I can't see what I've done wrong. Any help is appreciated.
Sebastianuser2019788 wrote:
Hello forum,
I've created a role:
CREATE ROLE enr_service;
GRANT CONNECT TO enr_service;
GRANT ALL ON Locataires TO enr_service;
GRANT ALL ON Batiments TO enr_service;
GRANT ALL ON Sportifs TO enr_service;
GRANT SELECT ON Epreuves TO enr_service;
and also a user:
CREATE USER ENR1 IDENTIFIED BY password QUOTA UNLIMITED ON USERS;
GRANT enr_service TO ENR1;
ALTER USER ENR1 DEFAULT ROLE enr_service;
ALTER USER ENR1 DEFAULT TABLESPACE USERS;
I can connect to the database with this user but when I try to query a table he's been granted access to I get an error message:
SELECT * FROM Sportifs;
ORA-00942: table or view does not exists
I can't see what I've done wrong. Any help is appreciated.
SebastianThat's probably because ENR1 doesn't have any table named SPORTIFS and he didn't qualify the table name with the schema name ... -
Customised Oracle application and access to roles and users...please advise
Hi Gurus!
We are developing a customised Oracle application where we have users and roles...user - role mapping is done in the system administration module of the application.
Now, we are also developing Oracle discoverer reports based on this. Using 10g (10.1.2.0.2) for that.
When I am creating an EUL, I select 'New EUL for Oracle Applications users only' option, but, I do not have any 'FND schema' to specify. That's where I'm stuck up!
I want to give access to the 'roles' in tha same manner as I would give to the 'responsibilities' in Oracle Apps. But, I don't know how to do it here.
Can someone guide me on this?
Thanks and regards,
AparnaHi Aparna
It would appear that you posted the same question on the Discoverer forum. Here is the answer that I posted there:
If your application is not E-Business Suite you cannot install Discoverer into Apps mode. This mode is reserved for applications which are E-Business Suite, which basically tells Discoverer to use authenticate users using the FND tables owned by the APPLSYS user.
In your case, even though you appear to be using Oracle applications, because you want to take advantage of your roles you will have to install Discoverer into standard mode. As you are creating your EUL you need to uncheck the box which says grant access to PUBLIC and make this a private EUL. Then you will not have the headache of worrying about setting up new users. You simply manage what a role can do (Tools | Privileges) and what a role has access to (Tools | Security).
Now, when any any user connects to Discoverer their role will be evaluated and access will be restricted.
You can do the same thing using a PUBLIC EUL, except you need to reduce what that user can do (Tools | Privileges) to an absolute minimum, and then take control of this using roles. For example, you could have a set of functional roles, one each for say AP, AR, GL and so on, but you could further break this down by privilege, thus you could have roles called AP Viewer, AP User, AR Viewer, AR User and so on. The User roles would have full access while the Viewer roles would have a much reduced set of privileges.
You are basically setting up the Library approach that I discuss in my Discoverer 10g Handbook and in my white paper which you will find on my downloads page here: http://learndiscoverer.com/downloads/downloads.htm.
I hope this helps
Best wishes
Michael Armstrong-Smith
URL: http://learndiscoverer.com
Blog: http://learndiscoverer.blogspot.com -
Link to Business Role and User Account
How to link an user account with a business role so that the user account can work with the new UI?
Hi,
Go to transaction PPOMA_CRM. Search for your business role say SALESPRO in the Position Search.Double click on the role so that its details are visible on the right hand side.Then search for your user from the user search.When it comes in the left side bottom, drag and drop it to the position on the right side.
Regards,
Rohit
Maybe you are looking for
-
If I have, say 200 photos in an EVENT and I use 50 of them in an ALBUM, and months later I'm happy with the ALBUM and want to trash the extra 150 photos, is there an easy way to know which 150 photos to trash? My idea is to not have hundreds of photo
-
The WEBUTIL object group is not available in this Form WebUtil cannot work
I Attacth Lib Webutil create buttom on click CLIENT_HOST('cmd /c DEL c:\test.mmx'); while run form then click buttom alert error formsweb.cfg [webutil] #WEBUTIL_CONFIG=C:\DevSuiteHome_1\forms\webutil.cfg #WebUtilArchive=frmwebutil.jar,jacob.jar WebUt
-
Need Help for Pivoting Columns in table
I have a data like below in the table col1 col2 col3 col4 a b 10 jan-11 aa b 20 feb-11 aab b 30 mar-11 Need desire o/p like col1 col2 jan-11 feb-11 mar-11 a b 10 aa b 20 aab b 30 Can anyone help me on this? decode is not the option here because my ta
-
Syncing tones to iphone makes me erase my phone.
So I've followed this https://discussions.apple.com/docs/DOC-3792, and when i go to sync my tones, I get a message saying "This phone is already synced with another itunes library, do you want to erase this iPhone and sync with this itunes library?"
-
TS2634 My Ipod Touch fell and cracked. It works but, can I get it fixed?
My Ipod Touch fell on cement and now, It is not looking in good shape..It cracked. So, i was wondering if i could find some answers. Can i get it fixed or do i need to buy a new one and lose all my progress?