Shared Services native group provision

hi can someone help me in this issue..
Shared Services.
Some Existing Native groups. Right click on group > Provision > gives error "This operation is not supported".
Have to deprovision to make this error go away. Right click properties OK, changes can be made, but cannot save, giving same error.
help needed urgently..
thanks..

ok thanks a lot john.
one more question for you John.
We need to know who logs in?
When they logged in and how long?
Also can we log what they access ie: reports, planning, analysis
How can we review these logs.
i know we can see the user sessions in view statistics page in planningg. but apart from that is there a way i can know wht all reports, applications etc a user accesses. i need to keep a track. is there some log for this?
thnks,
Ricky.

Similar Messages

  • Converting Shared Services (Native) users to MSAD

    Hi All,
    We are on version 9.3.1.
    We have configured FDM with Shared Services and currently only use native users. This means that our FDM users are all authenticated via HSS.
    We are just about to configure an MSAD directory and convert native users to MSAD.
    We will also be configuring FDM with the same MSAD server.
    Does anyone know how FDM handles user migrations? Will FDM automatically pick up MSAD users once they are deleted from the native directory and converted to MSAD?
    Are there any additional steps we need to be aware of??
    Thanks for your help.
    Seb

    Hi,
    Im ok with the config but Im wondering if FDM will be clever enough to convert native users to MSAD.
    Say we have a HSS user called Test1 with a password of Password (the Use Target System field is checked when creating the user in FDM). This user is authenticated against Shared Services when logging on to FDM.
    During the conversation, native users will be deprovisioned and deleted from Shared Services and their provisioning info will be imported against the MSAD provider. At this stage FDM should not be impacted since FDM security is separate from HSS.
    Once I configure the MSAD provider in FDM, my Test1 user will have a password of say Feb2010.
    Will FDM automatically pick up these config changes? Will FDM security for this user remain unaffected?
    Thanks again for your help.
    Seb

  • Sync Shared Services External users & Provisioning for Essbase Applications

    Hi Experts !!
    i have externalised user authentication in Shared services . I provisioned all users for Essbase and refresh the security from Essbase ,So all users are working fine
    and can login in Essbase and "Excel add-in" as well..
    but there is one user who is still not working for "Excel Add in"..
    Error is "Login failed due to invalid login credentials"
    Please suugest me the solutions
    Thank you.

    Hi John !
    Yes, User can login in EAS .
    Also User is available under Users in EAS ,But no applications are displaying in Analytic Server , While I have given Administration Privileges for Essbase app.
    But still error while login in Excel add in ..
    Error : Login failed due to invalid login Credentials.
    Also ,After Provisioning , How Can we Sync all all Externalized users from Shared Services itself for All hyperion Projects ???
    Thank you

  • Shared Services Application Groups

    Hi,
    We have the following application groups which I assume are default
    APS Servers
    Business Rules
    Default Application Group
    Essbase Studio Server
    Essbase Server
    File System
    Foundation
    Planning
    Reporting and Analysis
    I was playing with creating my own Application Groups in shared services and created my own one and then decided that I didn't have a use for it so I deleted it but it also deleted what I has added to it from the groups above. e.g
    Essbase Server Access
    Our Main Planning application
    Now I go back and try and provision for these I cannot find them anywhere!! How can I get them back??
    Cheers
    Luke

    John,
    Reconfigured the deploy to web server and cluster configuration for Planning, both successful yet if I go into Workspace the Navigate/Application does not appear. Forget if I see Planning or Scorecard I cannot even see the subbox 'application'
    JTS

  • Neet to locate the shared services native users in SQL server tables

    Hi All,
    We are using Hyperion Shared services to provision users to essbase, planning and HFM(all version 9.3.1). And we are using SQL server 2000 as the database. We created few native users in shared services and provisioned them to HFM, Essbase and Planning. Now we need to find those native users' information in the underlying SQL tables. I followed the documentation and sync-ed the native to relational tables using shared services, but I cannot see the user info for all the users I have created. I would appreciate if you can suggest me how to find the shared services users' and roles information in SQL tables (in the back end).
    Legards,
    Leo

    Hi,
    There are a number of free Ldap browsers that you can download, e.g.
    http://www.mcs.anl.gov/~gawor/ldap/demo.html
    http://www.ldapbrowser.com/download.htm
    Once you have installed then ldap browser you just need to point it to your Openldap
    Host :- machine with OpenLdap running
    Port :- 58089
    Base :- dc=css,dc=hyperion,dc=com
    User DN :- CN=root,dc=css,dc=hyperion,dc=com
    And just the root password which you can change in HSS in 9.3
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Export shared service active users (provision for Hyperion)only using MSAD.

    Hi..
    I m using Hyperion 9.x . and using active directory in shared services.
    while i m using importexport utility to export the active users list with provisioning.
    Issue is :
    Hyperion external authentication have all users of Active directory but i need to export only active users which are provisioned for Hyperion projects .
    I dont need the complete users list .
    Also i m unable to export the provisioning of users in exported file.
    Please can you help me in getting the correct export statement for the above.
    Thank you very much

    Thanks John !!
    I am using the following statement for 9.3.0 but not getting provisioning section in exported file.
    Only users/Groups/Roles are there in exported file.
    Please help me to overcome the problem .
    importexport.css=file:/C:/Hyperion/SharedServices/9.3/AppServer/InstalledApps/WebLogic/8.1/css.xml
    importexport.cmshost=HSS machine name
    importexport.cmsport=58080
    importexport.username=User name **User name i m using is Active Directory user with administrative rights in Hyperion**
    importexport.password=password
    importexport.enable.console.traces=true
    importexport.trace.events.file=C:/Hyperion/common/utilities/CSSImportExportUtility/importexport/trace.log
    importexport.errors.log.file=C:/Hyperion/common/utilities/CSSImportExportUtility/importexport/errors.log
    importexport.locale=en
    # export operations
    export.fileformat=csv
    export.file=C:/export.csv
    export.internal.identities=true
    export.MSAD.user.passwords=true
    export.provisioning.all=true
    export.delegated.lists=false
    export.user.filter=*@MSAD
    export.group.filter=*@MSAD
    export.role.filter=@MSAD
    export.producttype=*
    export.provisioning.apps=*
    Thank you very much
    Vivek Jaiswal
    Edited by: user11966901 on May 25, 2010 8:16 PM
    Edited by: user11966901 on May 25, 2010 8:19 PM
    Edited by: user11966901 on May 25, 2010 8:20 PM

  • CSSimport.bat error: while migrating the Shared Services groups and users

    Hi,
    I am trying to migrate the shared services native users and group from 9.3.1(on server A) to 11.1.1.3(on server B)
    - I have taken the export in CSV format from 9.3.1 using CSSexport.bat.(export.csv) -Successful.
    - I have copied this on the 11.1.1.3 server and changed lil details like removing the admin user etc.
    - When I am trying the import this on 11.1.1.3, I am getting the below error:
    CSSimport importexport.properties2010-10-11 09:36:41,328 Attempting a import operation
    log4j:WARN No appenders could be found for logger (com.hyperion.css.common.CSSLogger).
    log4j:WARN Please initialize the log4j system properly.
    null
    Aborting program...
    - There are not log or error files geting generated - The only error recieved , is given above.
    - I have made the necessary changes to the impotexport.properties file on 11.1.1.3 before starting the CSSimport utility.
    Can you please let meknow what should I do to overcome this error.
    -thanks,
    Ankit

    First thing I would try would be on the 11.1.1.3, try and run an export, if it works then run the import on the same file, this way you will make sure you have the version 11 utility working.
    Once you have done that then you can move on to the 9.3.1 export file.
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Automagic User Provisioning Essbase + Shared Services

    Hello All,
    I have recently been able to figure out how to use the Shared Services API for 11.1.2 in a previous post:
    Shared Service API Working 11.1.2
    However, all of the user management and provisioning examples work with native users. Has anyone used this API with active directory or LDAP users? Is there some other way (export/import utility)?
    My problem is that I need to be able to script the user management with shared services and have not been able to find much help. In the past, we ran Essbase in standalone mode and were able to handle this via MaxL generating essbase native user accounts. This will no longer work since we want to use shared services when upgrading to Essbase 11.

    After your comments I looked a bit more closely at the DDL for create user. It looks like i need "type external";
    MAXL> create user 'someuser' type external;
    OK/INFO - 1056060 - User [jdp5209] created.
    This is what i want!
    MAXL> create user 'someuser' identified by 'somepass';
    OK/INFO - 1056060 - User [someuser] created.
    This is not what i want, creates Shared Services native user.
    It seems obvious now, but before, shared services (CSS module to essbase) was "external" so the old external is the new native.
    Sorry, new to shared services! This works. Thanks all

  • Difference between user directory and native directory in Shared Services

    Hi,
    Please any one can help me......
    I am new to Hyperion, what is difference between Hyperion Shared services Native directory and User/Active directory.
    thanks in advance..............

    Hi,
    Shared Services native directory, as the name suggests, is a user directory (i.e. ldap) that is native to Hyperion. It allows you to create users, groups and define access rights to Hyperion Products. User/Active directory is the directory where users in your company reside. Shared Services can connect to it and retrieve the list of users and groups. You can define the access rights for these users if you configure the system in a way that it works with Active Directory.
    You can use both combined also. Meaning, you can create user groups in native directory and assign native directory users into them and define access rights onto user groups and/or users.
    Cheers,
    Alp

  • Shared Services and Planning Synchronization

    Ok, this is probably useful for a lot of people, but can anyone articulately explain the relationship between MSAD (or whatever the source security system is), Shared Services, and Planning? There are like 5 utiities and or Web Client buttons that claim to sync different parts to each other.
    MSAD is the source system. It is "plugged into" Shared Services. (Are these always in sync, is there some utility to run to sync them?)
    Then there is this Shared Services "Native Directory" what is this? There is a "Sync Native Directory" button in Shared Services, what does this sync?
    Assuming that SS is synced with MSAD, we then turn to Planning. In Planning, there are "Migrate Identities" and "Remove Non-Provisioned Users/Groups" buttons. What do these buttons sync, and is Migrate Identities the same as the ProvisionUsers.cmd utility?
    I want to know the best way to keep all this in sync, MSAD to SS and SS to Planning. Is any of this automatic, and if I need to run manual utilities, which ones do I need to run and which "buttons" do I need to push.
    thanks
    -Patrick

    Hi,
    Ok here goes, I am not really sure which version you are on because there was a bit of a change between 9.2 and 9.3 with regards to MSAD (uses the ObjectGUID instead of SamAccountName)
    Sync Native Directory - Shared Services contains all the product registration details, OpenLdap (Native Directory) stores all the provisioning, sometimes it is possible they could go out of sync which is pretty rare, so the sync native directory makes sure Shared Services and Open Ldap are in sync.
    Migrate Identities - I think this is more of the line of the updateusers.cmd utility where if a user has changed in the directory (this was more of an issue when SamAccountName was used as users group change OUs in the Active Directory) it will update the planning table with the new details.
    Remove-Non Provisioned Users/Groups - I am sure this doesn't actually work and has been removed in later versions, it is meant to clear up users/groups in the planning tables where there don't exist in Shared Services anymore.
    It depends what you mean by is MSAD always in sync with Shared Services, if you are using 9.3 and configured to use the ObjectGUID then it is pretty much in sync as the id is not likely to change, if you are using SamAccountName and a user moves place in the organisational structure then it can go out of sync. There is another ultilty for that :) (update native directory utility)
    If you run the provision users utility after you have provisioned a user in shared services it will add the user to the planning tables and also push the user to essbase.
    All depends what you are finding is it a problem to what utility to you want to use.
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Hyperion Shared Services Error

    Guys,
    I had configured MSAD external authentication in Hyperion Shared Services 9.3.1. I am also able to see the groups and users in the shared services.
    I provisioned one of the group with Essbase Admin, and HSS Admin. but when i tried to login to the Shared services with a userID in that group, HSS is showing the error "User: XXXX, not found"
    CSS.xml file seems to be fine to me. Users in Native authentication are working fine.
    - <css>
    - <hub location="http://HSS-Server:58080">
    <dirPort>58089</dirPort>
    </hub>
    - <spi>
    - <provider>
    - <native name="Native Directory">
    <password>{CSS}4N6lVcgiE/dGr8rFdvQLcA==</password>
    </native>
    - <msad name="XXXXX">
    <vendor>Microsoft</vendor>
    <trusted>true</trusted>
    <url>ldap://MSAD-server:389/DC=xxx,DC=xxxx,DC=com</url>
    <userDN>YYYYYYYYYYYYYYYY</userDN>
    <password>{CSS}VBLEOOfJ6ucg4ybH9z9PvQ==</password>
    <authType>simple</authType>
    <maxSize>100</maxSize>
    <identityAttribute>ObjectGUID</identityAttribute>
    <identityAttributeType>Octet String</identityAttributeType>
    - <group>
    <useGroups>true</useGroups>
    - <objectclass>
    <entry>group?member</entry>
    </objectclass>
    <url>OU=yyy</url>
    <nameAttribute>cn</nameAttribute>
    </group>
    </msad>
    </provider>
    </spi>
    - <searchOrder>
    <el>XXXX</el>
    <el>Native Directory</el>
    </searchOrder>
    - <token>
    <timeout>480</timeout>
    </token>
    - <logger>
    <priority>WARN</priority>
    </logger>
    - <delegatedUserManagement>
    <enabled>false</enabled>
    </delegatedUserManagement>
    </css>
    Any help is much appreciated.
    AB

    As informed earlier you could refer this link http://www.oracle.com/technetwork/middleware/bi-foundation/hyperion-supported-platforms-085957.html which will have the corresponding version support matrices (In your case 9.3.1 or 9.3.3) which will help you to find out which OS and which browsers can be used.

  • Security from shared services

    Hi all:
    Essbase has been activated the security of users using shared services, but do not want to use more, according to documentation that is not possible.
    how to do it? , or should be reinstalled essbase to cancel the utility?
    thanks

    So the first error is because the user can't be migrated -- this sort of makes sense.
    Have you tried creating a dummy user, like TestUser1, in Shared Services, and then provision him to Essbase server access, and maybe read access to Sample.Basic? Does that work? I would leave out all group membership just to prove that you can do that.
    If that works, have you tried creating a simple group (groups can have multiple levels of inheritance which can be really powerful but can get SNAFU'd as you are seeing) in Shared Services and assigned it to Sample.Basic? If that works, create another native user like TestUser2 and assign him to that group.
    I guess I'm getting at an incremenatlist approach to see what breaks. If nothing works, then I would go for the scorched earth policy and try again with Essbase.sec -- you won't have much to lose.
    Regards,
    Cameron Lackpour

  • Remove users from Shared Services/ EPM

    Gurus
    I have some users who have gone to different department and some who are no more with the companies. I was just wondering if there is a script I can run in the EPM Environment/ Shared Services to remove users and the provisioning in bulk.
    Thank you for your response.

    Hi John,
    I got it.
    What I did was that I exported the GROUPS under APPLICATION GROUP -> FOUNDATION > SHARED SERVICES -> NATIVE DIRECTORY -> GROUP. Created a CSV file and deleted the user and then imported back again.
    This is how it works right?
    ALSO, can I totally erase the user. The above process deleted user from group. But if I need to delete the user overall from everywhere in the EPM app, is there a way to do so?
    OR do I need to ask the server team to remove the user from MSAD.
    Thanks

  • Failure to register with Shared Services

    Planning 9.3.1 At Time = 0, we had created groups in Shared Services that were provisioned to our planning app. We could see the groups and corresponding uses come through into planning. Now at Time = 1, we notice that in Shared Services our planning app does not appear in the Planning projects folder. In Application Settings, the Shared Services URL still shows up in the Shares Services URL field, but attempting to Register with Shared Services yields the msg "Unable to Register with Shared Services".
    Note, between T=0 and T= 1, we did not do any migration or configuration changes that I'm aware of.
    Any thoughts on how to fix?
    Thanks

    I solved the problem myself. I had to unregister with Shared Services, then reregister, and then the app reappeared in the Planning projects in Shared Services. Not sure why the app go confused with Shared Services in the first place.

  • 'register with shared services' option missing while configuring eas

    I am facing some issues while configuring a new epm system:
    While configuring eas 11.1.2.0, I am not getting the option' Register with Shared Services'. but otherwise, the configuration is successful. As a result, I don't see the Business Rules option in Shared Services/Application Groups. But we are able to use eas console and do see business rules node in eas console.
    How do I get configurator to show this option?
    I was able to configure and register all other Hyperion applications.
    Thanks,
    Edited by: 784749 on Mar 28, 2012 12:35 PM
    Edited by: 784749 on Mar 28, 2012 12:59 PM

    One way is to use the registry tool though make sure you backup the shared services database before running the utility.
    It is located in <MIDDLEWARE_HOME>/user_projects/<instancename>/bin
    to change the status for EAS for HSS then run the following
    epmsys_registry updateproperty BUSINESS_RULES_PRODUCT/system_tasks_configuration/@hubRegistration Pending
    Now if you run the configurator again it should let you select just Essbase Administration Services, you dont need to select the child components.
    It should then registry with Shared Services.
    Cheers
    John
    http://john-goodwin.blogspot.com/

Maybe you are looking for