User & workstation associated AOT

Just to clarify if I'm correct.
I did some tests with AOT's in our environment.
I'm used ZfD agent 4.0 & 4.0.1 with NWClient 4.83 & above
I create an AOT associated on workstation and one on User (force run & App Launcher enabled)
When I startup the workstation the aot associated to workstation is running perfectly (probably due to the service
"Novell Application Launcher")
Then I log in but the user based AOT doesn't run.
It does when I start NALdesk or NALWIN32
So what I conclude from this is that aot's associated aot's are executed by the service "Novell Application Launcher"
and the ones associated to users don't, they only start via NALdesk NALWIN32 or via InternetExplorer (browser plugin)
Is this conclusion right?
If so why doesnt user associated AOT's run via the service "Novell Application Launcher" and the workstation based do?

Extension to my previous question
I want to run an AOT on certain workstations before the user logs into novell or even when the user doesn't log in into
novell (only local)
In my tests I did I can do this with aots associated to workstations.
BUT now I want to access certain files on a novell server via that aot.
how can I do that (I know that I can give file rights to an aot but following the help files this grant rights to
"files, directories, and volumes when this Application object is associated with a User object or with a Group,
Organizational Unit, Organization, or Country object. Such rights are removed when the Application object is
But this doesn't give rights to workstations.
How can I solve this?
  • Workstation association to Win2003 Server Terminal Services

    I have ZfD6.5sp2 running and have brought up Win2003 Server Terminal
    Services. I have DLU and roaming profiles enabled for the TS user policy
    applied to our users. All is working for user associated app objects
    within a TS session but apps associated to the TS workstation object does
    not work. TS sessions are user privileges but when I change to
    administrator privileges, the workstation associated apps start working.
    Is this working by design? Can anyone confirm this for me?

    Thanks for the reply Jared.
    There are no errors. The workstation associated apps simply do not work
    for user privilege TS sessions.
    Here's what else we have found since. If you login to the TS server
    console as a user with administrative privileges, this connects the
    workstation helper to the workstation object as displayed by
    naldiag.exe. By doing so, inherently, all user privilege TS sessions
    will have the workstation helper connected to the workstation object.
    This causes workstation associated apps to start working for all TS
    sessions. The minute we logout of the TS server console, the workstation
    helper is no longer connected and workstation associated apps will fail
    for all future TS sessions. Can you say, huh? What gives?
    > >TS sessions are user privileges but when I change to
    > >administrator privileges, the workstation associated apps start
    > What error do you get? I am not for sure if I know the answer though.
    > --
    > Jared Jennings - Data Technique, Inc.
    > Novell Support Forums Sysop
    > My Blog and Wiki with Tips, Tricks, and Tutorials

  • Force run for workstation associated apps

    Today I tried deploying the groupwise client as an MSI app. I scheduled the app for between 5:00pm and 5:10pm (just for testing) , associated the app to a workstation with Force Run and Application Launcher enabled. I was logged into the desktop of the workstation so I could watch the process as it happened. had NAL up to make sure the application icon showed up.. it didnt show up until 5:00pm, which is fine (even though Always Show Icon is checked)... the problem was.. it didn't start installing automatically.
    After messing around with different settings, it appeared the only way I could make it work was to check the "force run as user if workstation associated" box was checked. It would then seem to auto-install somewhere in the time slot.
    This doesnt seem right to me... as there must be a point to the force run for a workstation association by itself. Tried bumping the version, etc..
    Thanks for any tips or explanations

    Thanks. So let me see if I understand. The workstation helper starts before you even login to the workstation.. so if you force run an app associated to a workstation, it should run at the login screen.. but only if you have the "distribute in workstation security space" is checked (because its an MSI). Right?
    If its not checked, then the app wont get installed when Workstation Helper starts.. even after the user logs in, because the workstation helper has already decided it cant run it. Correct?
    Thanks for your help.. so many lil quirks and want to get it right

  • Help! Cant log in to BB App World -changed email and now asking for original user name associated email

    I have a bold 9790. I have changed my BB app world email as I cant access that original email anymore, so changed email address, i registered it online in the bb website, when i go to update apps i try and log in to the appworld with my new email it says 'enter user name associated with this smartphone', and just canot log in...PLEASE HELP

    elc088 wrote:
    I have a bold 9790. I have changed my BB app world email as I cant access that original email anymore, so changed email address, i registered it online in the bb website, when i go to update apps i try and log in to the appworld with my new email it says 'enter user name associated with this smartphone', and just canot log in...PLEASE HELP
    Hi @elc088! Welcome to the BlackBerry Support Community Forums!
    If you're referring to BlackBerry ID, then you need to perform a Security Wipe before you can login using your new credentials. Make sure you have a backup because this will delete all of your data.
    Click if you want to Thank someone. If Problem is resolved, so that others can make use of it.

  • Authorization check on users workstation basis

    Hi experts,
    I want to explore any log on event on SAP. I want to authorize the user according to users workstation. For example, If a user login into SAP from PC ABC he will get one type authorization. And if that user login to system using same id from another machine , he will get another type authorization. Is it possible ? Please help me on it.

    Hi Asad,
    Users are individually authorised, so you will need to set their authorisations per user.

  • How to identify which role user is associated with?

    How do I identify which role a user is associated with?
    Also how do I identify the privilges for a given role. For eg if SELECT, INSERT, DELETE was granted for a table to a role which dictionary table do I look at?
    I looked at USER_TAB_PRIVS.

    Check this:

  • User's association broken - Unity

    I have this error in CUCM BE Unity
    "This user's association to the co-resident Cisco Unified Communications Manager user has been broken."
    I Click Here to reassociate the orphaned user... but no user names appear.
    Can some help me?

    Hi Matt -
    Here is a link to the BE manual in case you don't have it -
    You did not mention in your post if you had CUCM integrated with LDAP - the guide discusses the differences in how users are created and synchronized, including this caveat "
    You must configure User ID and Directory Extension for the user in Cisco Unified Communications Manager before you can configure the end user in Cisco Unity Connection. You cannot create a Cisco Unity Connection user without a corresponding Cisco Unified Communications Manager user. You cannot delete an end user in Cisco Unity Connection Administration, unless you have enabled LDAP synchronization and the Cisco DirSync service deletes the user in Cisco Unified Communications Manager Administration after you delete the user in the LDAP directory. If the Cisco DirSync service deletes the user for Cisco Unified Communications Manager, you must manually delete the user in Cisco Unity Connection, as described in the User Moves, Adds, and Changes Guide for Cisco Unity Connection. If you do not delete the user in Cisco Unity Connection Administration, Cisco Unity Connection classifies the user as orphaned." Have you tried recreating the user in CUCM and then reassociating in Unity?

  • Finding all groups a user is associated to

    I have a situation where in I would like to know ALL the groups a user is associated to. Is there any standard API to do this?

    I just meant you can write a little procedure that would use the connect by command to build a user rights path per say. This has been very helpful to me because we have thousands of groups so I can see how the group rights filter down.
    You just need a couple of cursors...
    1)select all the groups from member$ that a user is a direct member of
    2)then do a connect by prior group_id = member_group_id start with member_group_id = (the groups returned in the first cursor).

  • How to get all AD User accounts, associated with any application/MSA/Batch Job running in a Local or Remote machine using Script (PowerShell)

    Dear Scripting Guys,
    I am working in an AD migration project (Migration from old legacy AD domains to single AD domain) and in the transition phase. Our infrastructure contains lots
    of Users, Servers and Workstations. Authentication is being done through AD only. Many UNIX and LINUX based box are being authenticated through AD bridge to AD. 
    We have lot of applications in our environment. Many applications are configured to use Managed Service Accounts. Many Workstations and servers are running batch
    jobs with AD user credentials. Many applications are using AD user accounts to carry out their processes. 
    We need to find out all those AD Users, which are configured as MSA, Which are configured for batch jobs and which are being used for different applications on
    our network (Need to find out for every machine on network).
    These identified AD Users will be migrated to the new Domain with top priority. I get stuck with this requirement and your support will be deeply appreciated.
    I hope a well designed PS script can achieve this. 
    Thanks in advance...
    Thanks & Regards Bedanta S Mishra

    Hey Satyajit,
    Thank you for your valuable reply. It is really a great notion to enable account logon audit and collect those events for the analysis. But you know it is also a tedious job when thousand of Users come in to picture. You can imagine how complex it will be
    for this analysis, where more than 200000 users getting logged in through AD. It is the fact that when a batch / MS or an application uses a Domain Users credential with successful process, automatically a successful logon event will be triggered in associated
    DC. But there are also too many users which are not part of these accounts like MSA/Batch jobs or not linked to any application. In that case we have to get through unwanted events. 
    Recently jrv, provided me a beautiful script to find out all MSA from a machine or from a list of machines in an AD environment. (Covers MSA part.)
    $Report= 'Audit_Report.html'
    $Computers= Get-ADComputer -Filter 'Enabled -eq $True' | Select -Expand Name
    <title>Non-Standard Service Accounts</title>
    BODY{background-color :#FFFFF}
    TABLE{Border-width:thin;border-style: solid;border-color:Black;border-collapse: collapse;}
    TH{border-width: 1px;padding: 2px;border-style: solid;border-color: black;background-color: ThreeDShadow}
    TD{border-width: 1px;padding: 2px;border-style: solid;border-color: black;background-color: Transparent}
    foreach($computer in $Computers){
    $sections+=Get-WmiObject -ComputerName $Computer -class Win32_Service -ErrorAction SilentlyContinue |
    Select-Object -Property StartName,Name,DisplayName |
    ConvertTo-Html -PreContent "<H2>Non-Standard Service Accounts on '$Computer'</H2>" -Fragment
    $body=$sections | out-string
    ConvertTo-Html -Body $body -Head $head | Out-File $report
    Invoke-Item $report
    A script can be designed to get all scheduled back ground batch jobs in a machine, from which the author / the Owner of that scheduled job can be extracted. like below one...
    Function Get-ScheduledTasks
    [string[]]$Name = $env:COMPUTERNAME
    [switch]$RootOnly = $false
    $tasks = @()
    $schedule = New-Object -ComObject "Schedule.Service"
    Function Get-Tasks
    $out = @()
    $schedule.GetFolder($path).GetTasks(0) | % {
    $xml = [xml]$_.xml
    $out += New-Object psobject -Property @{
    "ComputerName" = $Computer
    "Name" = $_.Name
    "Path" = $_.Path
    "LastRunTime" = $_.LastRunTime
    "NextRunTime" = $_.NextRunTime
    "Actions" = ($xml.Task.Actions.Exec | % { "$($_.Command) $($_.Arguments)" }) -join "`n"
    "Triggers" = $(If($xml.task.triggers){ForEach($task in ($xml.task.triggers | gm | Where{$_.membertype -eq "Property"})){$xml.task.triggers.$($}})
    "Enabled" = $xml.task.settings.enabled
    "Author" = $xml.task.principals.Principal.UserID
    "Description" = $xml.task.registrationInfo.Description
    "LastTaskResult" = $_.LastTaskResult
    "RunAs" = $xml.task.principals.principal.userid
    $schedule.GetFolder($path).GetFolders(0) | % {
    $out += get-Tasks($_.Path)
    ForEach($Computer in $Name)
    If(Test-Connection $computer -count 1 -quiet)
    $tasks += Get-Tasks "\"
    Write-Error "Cannot connect to $Computer. Please check it's network connectivity."
    [System.Runtime.Interopservices.Marshal]::ReleaseComObject($schedule) | Out-Null
    Remove-Variable schedule
    Get-ScheduledTasks -RootOnly | Format-Table -Wrap -Autosize -Property RunAs,ComputerName,Actions
    So I think, can a PS script be designed to get the report of all running applications which use domain accounts for their authentication to carry out their process. So from that result we can filter out the AD accounts being used for those
    applications. After that these three individual modules can be compacted in to a single script to provide the desired output as per the requirement in a single report.
    Thanks & Regards Bedanta S Mishra

  • Listing of Users with associated Groups

    Is there an easy way to generate a listing of APEX users and their associated groups? I know how to get the current user and how to determine what groups they are part of, but am looking for a simple query I can run to generate a complete list of Users and their associated groups.

    if you want to return the application groups that a user is assigned to, you can use the WWV_FLOW_GROUP_USERS intersection table. For example;
    SELECT group_name
    FROM wwv_flow_group_users
    WHERE user_id = (SELECT user_id
    FROM wwv_flow_users
    WHERE user_name ='MRITTMAN')
    would list out all of the groups that the user 'MRITTMAN' belongs to
    So to get all users and their groups, remove the where clause..
    (You will need read rights to the view, some dba's deny read rights to these objects in the name of security..)
    Thank you,
    Tony Miller
    Webster, TX

  • J4W 10.5 Login only works for users with associated device

    Hi all,
    I just discovered that using J4W 10.5 and service autodiscovery, the login only works if the user has an Device associated.
    Means that login is not possible if the user has only a controlled device profile.
    We are using 10.5.1 Build 43318 - Is this a known Bug, or is this working with a different version?

    Which form of Service discovery are you using? Is it _cuplogin or _cisco-uds? Do you use a jabber-config.xml file? What is the directory source selected for Jabber, is it CUCM or AD?
    Recently i had worked on a case with the following Scenario and  opened a Defect for it : CSCup74253
    With the following setup Service discovery fails and user has to manually login in Jabber specifying the IP address of the CUP server Service Discovery method : _cisco-uds or _cuplogin Directory connection type : UDS selected on service profile for the jabber user (no XML used) CUCM and CUP version :  9.1.2 Jabber version:9.7.0 and 9.7.1 End user page in CUCM : under controlled Devices only a Hardphone is selected with owner user id populated on device page of the phone in CUCM.
     This BUG is solved for Jabber 10.5.1.  But in essence if you do not select ANY of the device be it soft-phone or hard-phone under user> controlled devices for that matter Serivce discovery will fail.

  • How do you change your user name associated with the app store on the iphone 3G. When attempting to update, it is using an old email address that has since been changed at the apple site. The problem is that my phone does not seem to recognize this.

    I have exausted my ideas, and turn to the forum, prior to paying for something that may be a 2second simple fix. Please help if you can. Let me know if you need more info to understand my dilema.

    Apps are permanently tied to the Apple ID used to purchase them.  You will always be asked for the password associated with this ID when updating apps, regardless of whether or not you are using this ID for current purchases.  The only way to stop this is to delete the old apps from your phone and iTunes and repurchase them with your current ID.
    Edit: to change the ID used for future purchases on your phone, go to Settings>Store>Apple ID, tap the ID shown, sign out, sign back in using the new ID.  As explained above, you will still be prompted with the old ID when updating apps purchase with the older ID.
    Message was edited by: randers4

  • Is it possible to create user-roles associations at run-time?

    basically I need to be able to add a user to a role programmatically before the role-based content is displayed to the user.
    Example: I have a role called 'Manager' created in the portal. When a user logs on, I detect that the user has the attribute 'job title' = 'Manager' so I add the user to the 'Manager' role and the portal shows the content for the 'Manager' role.

    Hi Umesh,
    Yes, we can add users to the Role programatically.We did that.
    Just see the below code to get some idea...
    IUserFactory userFactory = UMFactory.getUserFactory();
    IRoleFactory roleFactory = UMFactory.getRoleFactory();
    IRole role = roleFactory.getRole(roleName);
    String userId = "";
    //Here userIDS is the list of user-id s to assign.
    for (Iterator i = userIDS.keySet().iterator(); i.hasNext();) {
       userId = (String);
    Hope this helps you.
    [Pl reward points if this is helpful]

  • How can I change the user ID associated with a Unix numerical ID?

    I acquired a used MacMini.  I changed the home directory name and display name but when I use ls -l (in Terminal) I still see the former owner's Unix name.  Is there some way to edit the MacOSX equivalent of the old /etc/passwd so that the numerical used ID maps to my name?  I found a reference to OpenLDAP and Directory Services but nothing too helpful.

    This may not be the last thing you have to do, but....
    System Preferences -> Users & Groups (or if an older system "Accounts").
    Click on the Padlock in the lower left corner, enter you admin password.
    Control-Click on the desired account
    Select "Advanced Options..." from the popup
    Pay close attention to the warnings, as you can totally screw up your Mac.  In fact, do you have a full bootable clone backup (SuperDuper or Carbon Copy Cloner)?  If not, stop now and go make one.
    Change the Account name field.
    Change the Home Directory field to match your new home directory.
    DO NOT MESS with UUID, and I would strongly suggest not changing your User ID, as all your files are currently owned by that User ID, and it is a pain to find and change the ownership of all your files.
    I suggest you logout and login.  Then if things do not look right, reboot.  If you have cron jobs, chances are they will be tighed to the old name, and a who bunch of other things might have stuff tied to the old name, so this is one of those things that may go wrong after you change your username.
    Again, this may not be the only thing you need to change.

  • Functional test fails from OTM with summary error "authentication to user workstation failed"

    I see following exception in log wls_oats.log on OTM server machine. AgentManagerService is running manually on Agent Machine.
    2015-01-23 10:49:06,930 ERROR [OracleActionBase]
    2015-01-23 10:49:30,721 ERROR [TestExecutorBean] Failed to start test
    at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
    at sun.reflect.NativeMethodAccessorImpl.invoke(
    at sun.reflect.DelegatingMethodAccessorImpl.invoke(
    at java.lang.reflect.Method.invoke(
    at com.bea.core.repackaged.springframework.aop.framework.ReflectiveMethodInvocation.invokeJoinpoint(
    at com.bea.core.repackaged.springframework.aop.framework.ReflectiveMethodInvocation.proceed(
    at com.bea.core.repackaged.springframework.jee.intercept.MethodInvocationInvocationContext.proceed(
    at oracle.oats.otm.session.BusinessSessionBean.initializeSessionObjects(
    at sun.reflect.GeneratedMethodAccessor363.invoke(Unknown Source)
    at sun.reflect.DelegatingMethodAccessorImpl.invoke(
    at java.lang.reflect.Method.invoke(
    at com.bea.core.repackaged.springframework.jee.intercept.JeeInterceptorInterceptor.invoke(
    at com.bea.core.repackaged.springframework.aop.framework.ReflectiveMethodInvocation.proceed(
    at com.bea.core.repackaged.springframework.aop.framework.ReflectiveMethodInvocation.proceed(
    at com.bea.core.repackaged.springframework.jee.spi.MethodInvocationVisitorImpl.visit(
    at weblogic.ejb.container.injection.EnvironmentInterceptorCallbackImpl.callback(
    at com.bea.core.repackaged.springframework.jee.spi.EnvironmentInterceptor.invoke(
    at com.bea.core.repackaged.springframework.aop.framework.ReflectiveMethodInvocation.proceed(
    at com.bea.core.repackaged.springframework.aop.interceptor.ExposeInvocationInterceptor.invoke(
    at com.bea.core.repackaged.springframework.aop.framework.ReflectiveMethodInvocation.proceed(
    at com.bea.core.repackaged.springframework.aop.framework.ReflectiveMethodInvocation.proceed(
    at com.bea.core.repackaged.springframework.aop.framework.JdkDynamicAopProxy.invoke(
    at $Proxy130.startTest(Unknown Source)
    at Source)
    at weblogic.ejb.container.internal.SessionLocalMethodInvoker.invoke(
    at Source)
    at oracle.oats.otm.web.TestAction.runAutomatedTest(
    at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
    at sun.reflect.NativeMethodAccessorImpl.invoke(
    at sun.reflect.DelegatingMethodAccessorImpl.invoke(
    at java.lang.reflect.Method.invoke(
    at oracle.oats.otm.web.OracleActionBase.execute(
    at org.apache.struts.action.RequestProcessor.processActionPerform(
    at org.apache.struts.action.RequestProcessor.process(
    at org.apache.struts.action.ActionServlet.process(
    at oracle.oats.otm.web.ActionServlet.process(
    at org.apache.struts.action.ActionServlet.doGet(
    at javax.servlet.http.HttpServlet.service(
    at javax.servlet.http.HttpServlet.service(
    at weblogic.servlet.internal.StubSecurityHelper$
    at weblogic.servlet.internal.StubSecurityHelper.invokeServlet(
    at weblogic.servlet.internal.ServletStubImpl.execute(
    at weblogic.servlet.internal.TailFilter.doFilter(
    at weblogic.servlet.internal.FilterChainImpl.doFilter(
    at oracle.oats.otm.reports.utils.GZIPFilter.doFilter(
    at weblogic.servlet.internal.FilterChainImpl.doFilter(
    at oracle.oats.otm.util.BusinessSessionFilter.doFilter(
    at weblogic.servlet.internal.FilterChainImpl.doFilter(
    at oracle.oats.otm.reports.utils.AlwaysRevalidateCacheFilter.doFilter(
    at weblogic.servlet.internal.FilterChainImpl.doFilter(
    at oracle.oats.otm.util.RequestEncodingFilter.doFilter(
    at weblogic.servlet.internal.FilterChainImpl.doFilter(
    at weblogic.servlet.internal.WebAppServletContext$ServletInvocationAction.wrapRun(
    at weblogic.servlet.internal.WebAppServletContext$
    at weblogic.servlet.internal.WebAppServletContext.securedExecute(
    at weblogic.servlet.internal.WebAppServletContext.execute(

    Below is some of the resolution
    1. First go to OTM ->Tools->Systems ->Edit and verify by adding the password of the agent on the remote server and test.. (This is the password which was used on installing OATS on the remote server) Click ok
    Verify if the above step fixes the issue
    2. Go to the agent system Start->all programes->OATS->Tools->Oracle application load testing agent authentication->Click edit and enter the password and confirm it for the agent.
    Let me know if you still face issues

