ShareDocuments between user group

Hi Guys,
I have setup intranet sharepoint portal . I have 3 permission group like 1) Full access
2) Contributor 3) Read-only Access and users have been added to all these group.
Now my question is if admin has uploaded the document, checkin and approved then my document is visible to all users under contributor and Read-only Access group.
1) But my requirement is that i need to show some documents to contributor group and some documents with Read-Only Access group?
2) Second my requirement is to enable email notification that is whenever admin has uploaded, checkin and approve the document, the email notification should be triggered to all the user with whom document is visible?
Regards,
Samira
Samira

Hi Samira,
For the first question, you can stop inheriting permissions from parent on the special documents as selecting the document ->Files->Shared With->Advanced-> Stop Inheriting Permissions, then remove the group that you don't want
to share.
For the seacond question, I suggest the users create each alerts on each documents after they get the share email notification. And make sure the alerts is set up for anything changes.
Best Regards,
Wendy
Wendy Li
TechNet Community Support

Similar Messages

  • What  is difference between user group and reference user group?

    hi
    guys,
            what  is difference between user group and reference user group? 
    your regards
      p.suresh

    Hi ,
    Chk the link below for your clarifiacation.
    http://help.sap.com/erp2005_ehp_03/helpdata/EN/5c/c1c81c445f11d189f00000e81ddfac/frameset.htm
    Hope it helps.
    Regards,
    Amit
    Edited by: Amit Kotwani on Sep 2, 2008 2:15 PM

  • Switching between user groups

    Hello,
    Is it possible to switch between two portals without having a user to log
    out of the portal after the user selects a group portal when a user belongs
    to two groups? How can I go about that?
    I am thinking of creating a link webflow item to start, then retrieve the
    groups the user belongs to other than the groups of the portal currently
    logged in. Then switch to the other portal, preferrably without having to
    re-authenticate the user.
    Thank you,
    Makoto

    Yes the 2 portals are of the same web app and a domain. In fact they are the
    same portal app, just showing different content depending on the group user
    belong to.
    Thanks!
    Makoto
    "Kunal Mittal" <[email protected]> wrote in message
    news:21880498.1092324885837.JavaMail.root@jserv5...
    Are the 2 portals part of the same webapp? Same domain? etc.. this willhelp determine different SSO mechanisms.

  • Where to find the user groups in SQL Server

    Hello All,
    where to find the user groups created in Shared Services in SQL Server tables?

    Yes thats correct its stored in Openldap
    Native Directory (OpenLDAP), an open source Lightweight Directory Access Protocol (LDAP)-enabled user directory, is bundled and configured with Shared Services.
    Native Directory functions:
    **Used to maintain and manage the default Shared Services user accounts required by Hyperion products*
    **Is the central storage for all Hyperion provisioning information because it stores the relationships between users, groups, and roles.*
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Defference between usergroup and reference user group

    Hi,
    Please any one tell me the defference between usergroup and reference user group.
    Thanks,
    hcm

    Please make use of forum search.
    Donnie

  • User Exit for placing validation between Customer Group & Material Group

    Hi,
    Following is my client requirement.
    1. A validation check is to be placed in Sales Order of Document Type ZTRD.
    Validation to be placed between Customer Group 3 (CG3)   of Sold to party with Material Group( MG ) of Material.
    If CG3 of Sold to party is different with MG , then system should through Error message & should not allow to save the Sales Order.
    Please suggest me what best to be done. I am a SD consultant.

    A standard way to do this is to use product attributes.In material master you can define product attributes in the sales org 2 view. Next, within the customer master, you can define the product attributes a customer would accept. Finally, in the order type configuration, you can define that if the attributes don't match, the system should display an error message (or a warning message). So, you can do the check you are looking for without doing any ABAP work. See if that could work for you.

  • Cannot share itunes library between users after Lion upgrade

    Before the Lion upgrade, I was able to share my iTunes library between two users on the same computer.  The library is located in HD > Users > Shared.  Both users have read and write access to the folder.  Home sharing is turned on in iTunes from the one user who can open iTunes.

    This can be done with ACLs. I use it to share an iTunes library between my and my wife's user accounts.
    First go to System Preferences -> Users & Groups, and make a new group. Call the group itunesshare. Add the users you want to the group.
    Then, in Terminal, paste in all of this and press return:
    sudo chmod -R +a "itunesshare allow delete,chown,list,search,add_file,\
    add_subdirectory,delete_child,file_inherit,directory_inherit" \
    Then drag the iTunes Library folder into the Terminal window and press return again. Enter the admin password when prompted.
    Your iTunes library will then have full read and write permissions for all users in the iTunesshare group. This includes permissions to any items added to the library at any future time.

  • Sharing FCP projects between user accounts problem

    Hello!
    I'm working on a project with several other colleagues. Each of us has his own User account on the computer (dual G5 / 10.4.7) because we have different preferecnes regarding keyboard layouts, desktop colour etc. We would like to have our FCP project files accessible to each of us.
    I have tried different approaches to solve this task, but haven't fully succeded yet (I tried creating the project file within the /Users/Shared foler; putting it into a dedicated /Users/FCPProjects folder and applying chmod/chown commands; creating a Editors group with NetInfo and assigning those foders to this group; I even tried to work around this using ACLs).
    The problem is that when we click "Save All" command in FCP, we get three or four OK-only dialog boxes in a row saying "Access denied". The project file is in fact saved (I can see it by checking the Modified time in Finder), but FCP seems not to be aware of this and doesn't want to quit. It's an unpleasent situation because it allways makes us worry about losing our work.
    Could someone please give us instructions on the correct procedures for resolving the issue.
    Thank you
    Best regards
    Mato Ilijic

    matoid,
    ACLs should work for you, and it seems that they are. You shouldn't have to deal with the error dialogue either, so let's see if we can't get rid of it.
    First, let's talk about groups. I have looked at your "step by step," and I notice that you didn't bother to change the group ownership of the "shared" folder that you created. Fine, ACLs still work, but the group ownership of "wheel" might be the cause of your error messages. ACLs are a more advanced system of access controls than the older POSIX system, but POSIX still exists, and might affect your work.
    Let's assume that you have your standard users that will be using FCP placed properly into a common group. For this discussion, I'll call that group "fcpusers." Under the POSIX paradigm, any "shared" folder can be owned by any one of the users in this group, but it must have a group ownership of "fcpusers" in order to work properly for everyone. When it does, every new file or folder created in it will "inherit" that group ownership.
    Now, every user on a given machine will have read access to that shared folder. If a non-member of group "fcpusers" attempts to save a file there, however, an error message is likely to appear. One other possibility is that the file is saved, but with an "unknown" group ownership. This is because of a conflict between the groups the saving user is a member of and the attempted "inheritance" from the enclosing folder.
    I want you to try the following. Please do this exactly as I outline it:
    1) Create a new group in Netinfo Manager. Duplicate the "admin" group. Change the name of the duplicate to "fcpusers," then delete the "realname," "generateduid," and "smb_sid" properties. Change the GID to "101." Select the "users" property, then choose Directory>Insert Value. Type the short name of one of your users. Repeat this procedure for every user of FCP. Select any admin users in this group who will not be using FCP, and click the "Delete" icon. Finally, choose Domain>Save Changes.
    2) Create a new folder in /Users/Shared. For this discussion we will assume that you will call it "FCP_Data." Further, we will assume that one of your FCP users is named "usera" (your terminology ;-)). Open Terminal. Since you seem to be well-versed in the use of Terminal, I will simply post the commands needed:
    <pre style="overflow:auto; font-family: 'Monaco'; font-size: 10px">sudo chown usera:fcpusers /Users/Shared/FCP_Data
    sudo chmod g+w /Users/Shared/FCP_Data</pre>
    3) Before anyone begins saving files in this directory, make sure that their umask is changed using TinkerTool. Also, I recommend that all media gets saved here, too. I'm not sure how close FCP is to iMovie, if it doesn't save all data in a "package," but it is likely that media is being referenced using "placeholders." If this is the case, and media for a given project is scattered all over the file system, there could indeed be ownership issues. If media needs to be on externals, this same "shared" folder can be created there. Just make sure that #1, the volume has "ownership and permissions" in effect, and #2 all media is kept within the "shared" directory structure.
    You must use TinkerTool to change the umask such that members of the group have read/write permission. TinkerTool doesn't specifically say this, but the corresponding umask is "002" (the OS X default is "022"). BTW, umask is subtracted from the "full permissions" value of "666" when saving non-executable files ("777" for folders and executables).
    Once you have a properly configured "shared" folder and a proper umask in place, your users can begin to populate the shared directory. If any existing projects are to be added, they must be copied by a user into the shared directory, not simply moved. Only when a copy is made will the new copy inherit the proper group ownership. Just to be sure, I will include one more set of commands to use, once the shared directory has been populated:
    <pre style="overflow:auto; font-family: 'Monaco'; font-size: 10px">sudo chown -R usera:fcpusers /Users/Shared/FCP_Data
    sudo chmod -R g+w /Users/Shared/FCP_Data</pre>
    Please follow these instructions carefully, then report the results. This should work, and without using ACLs.
    Scott

  • How do I share programs between users on my MacBook Pro.

    How do I share programs between users on my MacBook Pro. I downloaded mine craft under my user name and I just made my son a new user on the computer but I can't figure out how to put mine craft on his desktop

    Try going to system preferences, then go to users and groups- find the option to allow sharing among users
    I hope this solved your problem(: btw- I love minecraft!!!

  • How to create a New user group for AD-HOC

    when i select a work area for ad-hoc i dont find any exisitng user groups...
    i get a blank screen with an error saying no usergroup
    is there a possibility to copy these across clients?
    pls advise
    thanks

    Hi,
    sorry but my english isn't the best so i try an answer again and hope i'm on the right way:
    Step by step guide for example client 100 and 200 on the same system. System 100 has usergroup test001 and client 200 has not.
    1. call sq03 in client 100
    2. pick the transport truck
    3. pick radiobutton [Export] and and radio button [Transport user groups] fill in the field [User groups] with test001.
    4 Execute and write(copy to clipboard) down the transport number
    5 logon to client 200
    6. call sq03
    7.pick the transport truck
    8. pick radiobutton [Import] and radio button [Transport user groups] fill in the field [Dataset with imports] with the transport number.
    9. Execute
    After that your user group should be in client 200.
    If you want to transport between different systems you have export the transport request first.
    Regards
    Bernd

  • Delegated Admin and non-flat user/group structures

    Hello, I am trying to build a directory structure with several containers under an organization used to store different portions of userdata and group data (i.e. not only ou=people and ou=group, but also a few ou's like them). Server software is from OUCS 7u2 release. Users in "other" containers are populated into LDAP (ODSEE 11) by replication, filling in all the same attributes as a freshly DA-created account has.
    The Delegated Admin interface and other parts of the software accept this and work okay with this setup, displaying user information, allowing logins and so on - except for attempts to edit user accounts in the alternate containers in the DA (i.e. add/remove service packages, change quotas, etc.). First I've verified that this is not an LDAP problem - I can use both command-line ldapmodify and an LDAPBrowser GUI to edit the entries with no hiccups.
    I tracked that when trying to save account information for accounts in non-standard containers, the DA still tries to use a hard-coded path (i.e. uid=USERNAME,ou=people,o=DOMAINNAME,dc=DOMAIN,dc=NAME) despite the fact that the user account is (and DA displayed it from) uid=USERNAME,ou=morePeople,o=DOMAINNAME,dc=DOMAIN,dc=NAME.
    Possibly, this "hardcoding" stems from DA configuration in WEB-INF/classes/sun/comm/cli/server/servlet/serverconfig.properties which does list components of the LDAP structure:
    # Ldap configuration.
    # List of ldap hosts. Form is <ldaphost>:<portnumber>. (Default port = 389)
    # add additional hosts with ldaphost-<consecutive number>
    # Schema type is either "1" or "2".
    # Reconnect interval is in seconds
    # Group and people container is dn from organization dn (e.g ou=people)
    ldaphost-1=oucsldap01:389
    ldaphost-2=oucsldap02:389
    ldaphost-suffix=dc=DOMAIN,dc=NAME
    ldaphost-dcsuffix=dc=DOMAIN,dc=NAME
    ldaphost-maxcount=50
    ldaphost-schematype=2
    ldaphost-reconnectinterval=60
    ldaphost-peoplecontainer=ou=People
    ldaphost-groupcontainer=ou=Groups
    ldaphost-orgadminrole=cn=Organization Admin Role
    While the organization root dn is not explicit here (and shouldn't be), the default people container is... I might guess a coding error logic like this: indeed, the "ou=People" container should be used by default when creating a user via DA; as a likely error, it might also be used when editing existing users - instead of their existing full DN/parent DN.
    Questions:
    1) Does anyone have a working configuration with several user/group containers within an organization like this? Would you care to share details and workarounds, if were needed?
    2) I think that possibly the "shared domain/organization hosting" mode might help here - at least it is expected to have several LDAP trees with their delegated administrators performing as a single e-mail domain. Before I go and reconfigure everything, I'd love to hear if there are any success stories with this route? Is it a proper solution (or THE solution) for such config?
    Thanks,
    //Jim Klimov

    I wanted to follow up that reconfiguring the directory structure according to shared domain hosting, with branches for ISW-synchronized accounts as one of the sub-organizations which share the domain, and manually created OUCS-only accounts being in another sub-organization. This works for both messaging components and the DA, as long as UIDs are in ou=People in their organization. Somewhat unfortunately, ISW config seems to allow only one DSEE target branch and puts groups (CN) there as well. Well, for our needs to edit user attributes and service packages via DA, this suffices. Sometimes there are hiccups (Can not save changes), but they are intermittent and harder to trace debug; usually go away with restart of the DA web container. The DSEE LDAP instances are configured with plugins to enforce uid uniqueness across the organization and uniqueness of values of messaging email address attributes (mail, mailAlternateAddress, mailEqiuvalentAddress) to avoid mixups between user accounts in different branches.
    Also, we had a problem with Calendar server after migrating the LDAP entries: since our deployment used the nsUniqueID for calendar user identification, relocation of entries (the way we did it) generated new values for new entries and users got new empty caledar databases. On this POC this was not a major problem, and newer OUCS releases with a davUniqueID attribute should specifically be immune to this problem. However, for others trodding this path I can suggest that they export the LDAP database into LDIF including the unique IDs, recreate the suffixes as needed (the ISW target organization in DSEE should be a separate LDAP database suffix), change the LDIF entry pathnames, and import the LDIF anew. This would wipe old LDAP data and should add old nsUniqueIDs to relocated entries (unlike recreation via ldapadd or relocation via ldapmodrdn).
    We have also hit a problem with DA refusing to render the list of accounts (returning 0 or 25 empty entries in a table). The LDAP logs showed that on the LDAP side all is ok, and expected amount of replies was located. Pattern searches often produced the proper table with a subset of users in DA. Ultimately, we linked the problem to ISW binary base64-encoded attributes (dspswuserlink et al; some of those values also garbaged output of commadmin queries in a terminal) and created an LDAP ACI which forbade our DA-admin user to read,search,compare these attributes. This solved the problem for us. I wonder if a more generic solution is possible, so as to apply this ACI not to an explicitly named admin user but to any users with DA admin privileges (by group or role? which string, to cover them all in advance)? Or, perhaps, nobody except the ISW user account should see these ISW attributes?
    Hope this report helps others who would try to pioneer this path of messaging integration
    //Jim Klimov

  • How can I get Address Book Server to share contacts between users?

    I want to have a Shared Address Book for the users on my installation of OS X Lion Server. Users will keep their own contacts individually but there are certain lists and contacts who need to be shared between users and I can't find any way of getting Lion Server to do this. I know it was a problem in Snow Leopard Server but I hoped it had been fixed.
    Any suggestions?

    Create a new user on the Server called 'ouraddressbook' or whatever. Exit the Server. Into Address Book on your Admin/Client machine create a new Account. Account type is CardDAV, Username and Password the same as the User you created on the Server… 'ouraddressbook' or whatever, and then enter your Server's address as text or numbers. Click creat and the rest is straight forward. Now give the set up details of that new Account to the others who want to share your 'ouraddressbook' with you.The Clients must have, I think, Mac OS 10.6  or upwards to have an Address Book that with co-operate.
    You will see a new group in Address Book.
    If you don't already know, do not add accounts to Address Book or iCal on the Server. Everything is Admin and Client Side. In the beginning I was also adding accounts to iCal and Address on the Server. It works fine but it is just one extra thing that could become corrupted. Let the Server 'serve' the Users you create on it.
    Hit me if you have problems.

  • The lease timeout between avaiability group and the Windows Server Failover Cluster has expired

    Hi,
    I am having some issues where I get a lease timeout from time to time.  I have a Windows 2012 Failover Cluster with 2 nodes and 2 SQL 2012 Always-on Availability Groups.  Both nodes
    are a physical machines and each node is the primary for an AG. 
    From what I understand if
    the HealhCheckTimeout
    is exceeded without the signal exchange the lease is declared 'expired' and the SQL Server resource dll reports that the SQL Server availability group no longer 'looks alive' to the Windows cluster manager.  Here are the properties I have setup
    which are the default settings:
    LeaseTimeout - 20000
    HealthCheckTimeout - 30000
    VerboseLoging - 0>
    FailureConditionLevel – 3
    Here are the events that occur in the Application Event Viewer:
    Event ID 19407:
    The lease between availability group 'AG_NAME' and the Windows Server Failover Cluster has expired. A connectivity issue occurred between the instance of SQL Server and the Windows Server Failover
    Cluster. To determine whether the availability group is failing over correctly, check the corresponding availability group resource in the Windows Server Failover Cluster.
    Event ID 35285:
    The recovery LSN (120881:37533:1) was identified for the database with ID 32. This is an informational message only. No user action is required.
    SQl server logs are too long to post in this box but I can send them if you request.
    The AG is setup to failover automatically but it did not failover.  I am trying to figure out why the lease timed out.  Thanks.

    From what I've been able to find out, this is due to an issue with the procedure sp_server_diagnostics.  It sounds like the cluster is expecting this procedure to regularly log good status "Clean" in the log files, but the procedure is designed not
    to flood the logs with "Clean" messages, so only reports changes, and does not make an entry when the last status was "Clean" and the current status is "Clean".  The result is that the cluster looks to be unresponsive.  However, once it initiates
    the failover, the primary machine responds, since it was never really down, and the failover operation stops.   
    The end result is that there really never is a failover, but the database becomes unavailable for  a few minutes while this is resolved.
    I'm going to try setting the cluster's failure condition level to 2 (instead of 3) and see if that prevents the down time.
    blogs.msdn.com/b/sql_pfe_blog/archive/2013/04/08/sql-2012-alwayson-availability-groups-automatic-failover-doesn-t-occur-or-does-it-a-look-at-the-logs.aspx

  • Planner provisioning for user groups lost in Shared services

    Hi All,
    Everything was fine. All of a sudden, no users were able to login in to planning.
    On investigation it was found that all the planner/planning provision to the groups is lost in the shared services.
    Digged into log for a while and couldnt find out any issues.
    What could be the reason we lost user group security provisioning only to planning?
    Could anyone please help on this?
    Regards,
    GG

    I used to have same experience every time migration happens from dev to UAT or prod etc.
    After migration, registering with shared service will be successful. When i try to sync, migrate user identities (provisionusers.cmd) from shared service all user group info vanishes in planning (Add/Edit access page). i.e hsp_access_control table is truncated or all rows are dropped.
    Then i have to set it up correctly. Guess this happens because usergroups have different id between different environments. When sync'g planning at target, it will not be able to recognize the wrong usergroup id of source system.
    My assumption:
    When provisionusers.cmd is run, planning fetches the usergroup provisioning information from shared services in to hsp_access_control planning repository table. could someone confirm the same?
    Is there any other way to overcome this issue recurring on every time migration happens?
    But the problem today was different: the provisioning is lost in the shared services itself which i havent witnessed so far. We didnt migrate recently, everything was file till 8 AM, but screwed around 8.10 AM. everything was up and running.
    Cheers,
    GG

  • Is it possible to map a Sponsor Group in Cisco ISE to a user group in Active Directory, through a RADIUS server?

    Hi!!
    We are working on a mapping between a Sponsor Group in Cisco ISE and a user group in Active Directory....but the client wants the mapping to be through a RADIUS SERVER, for avoiding ISE querying directly the Active Directory.
    I know it is possible to use a RADIUS SERVER as an external identity source for ISE.....but, is it possible to use this RADIUS SERVER for this sponsor group handling?
    Thanks and regards!!

    Yes It is possible to map Sponser group to user group in AD and if you want to know how to do please open the below link and go to Mapping Active Directory Groups to Sponsor Groups heading.
    http://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_guest_pol.html#wp1096365

Maybe you are looking for

  • Drop Down BY Index Vs Drop Down By Key

    What is the difference between Drop Down By Index & Drop Down By Key. How Do we retrive What value is selected in a drop down regards Nilesh

  • Graph in rtf template

    Dear All I need to insert a graph in report through XML in RTF template. i am not able insert the multiple values in BI Publisher. when i try to insert the 2nd value it is getting replaced with the 1st value. Kindly assist me. Regards Shaizy Edited b

  • HT3798 Ipod Classic will not sync with windows 8 and newest itunes

    I have ipod classic, 160gb, with new computer with Windows 8 and latest version of Itunes - came from xp and previous version of itunes - and never had a syncing problem.  All my songs are in new itunes on new computer, however ipod will not sync.  H

  • How to include images in HTML email

    Hi, from Oracle DB, using UTL_SMTP I am sending emails to customers, it works OK but my problem is that include images do not show when email is open (show typical box with a 'X' in it) , Is there any option to do it??? in HTML? in UTL_SMTP. Others o

  • SQL Developer 1.5 Missing DB Connection Tabs

    After installing SQL Developer 1.5 EA1 in a new directory, I do not have the Sybase, MS SQL, MYSQL tabs when I try to create a new entry in the Database Connection window. Is this a Java problem? I have many database drivers and tools installed on th