This discussion is archived
10 Replies Latest reply: Sep 12, 2013 11:58 AM by Sh!va RSS

Assign Access Control to LDAP group

user5449503 Newbie
Currently Being Moderated

Hi everybody,

 

we are using Hyperion EPM 11.1.2.2, and when we try to assign Access Control to LDAP group it does´t seem possible. Only for Native group we can. Any explanation?

 

By other way, how can we obtain a list with all access control assigned for any Application?

 

Thanks in advance

  • 1. Re: Assign Access Control to LDAP group
    959658 Pro
    Currently Being Moderated

    Are your LDAP groups are configured in your User directory configuration in Shared services?

     

    and You can export all access controls/provisioning for any/all applications using LCM in EPM 11.1.2.2 from Shared services.

     

    Thanks,

    Santy.

  • 2. Re: Assign Access Control to LDAP group
    user5449503 Newbie
    Currently Being Moderated

    Hi,

     

    Yes, the LDAP groups are imported in Shared Services. We can see them and provision them, but not assign Access Control. With native groups there is not problems.

     

    We do not need export access control, what we need is some report or list to review access control assigned to every application.

     

    Thanks in advance

  • 3. Re: Assign Access Control to LDAP group
    959658 Pro
    Currently Being Moderated

    I think you can see the access controls in shared services by right clicking on Application name & Select "Assign Access Control"

    See if you can see LDAP groups there if you do a wildcard search for Groups.   If you can see, you can assign access by selecting relative groups & clicking Next.

     

    I think you can use MaxL as well to see privileges of specific users/groups. See this: Oracle Essbase Technical Reference

     

    Thanks,

    Santy.

  • 4. Re: Assign Access Control to LDAP group
    Celvin Kattookaran Oracle ACE
    Currently Being Moderated

    Is that LDAP group provisioned to access the application?

     

    Regards

     

     

    Celvin

    http://www.orahyplabs.com

  • 5. Re: Assign Access Control to LDAP group
    Sh!va Pro
    Currently Being Moderated

    LDAP group must be provisioned as filter access before going to assign to Access Control.....

     

    Cheers!

     

    Sh!va

  • 6. Re: Assign Access Control to LDAP group
    Daniel Willis Journeyer
    Currently Being Moderated

    Not exactly answering your question (although it could be considered an alternative).. I actually create a Native Group for each of my AD groups and just have a 1 to 1 mapping between them both. I like this because I can then just concern myself with the Native directory and if I do ever need to temporarily remove access for an AD group I can just break that Native->AD group assignment. I can also create native test users and assign them to the Native Group and they would act essentially identical to an AD user would.

  • 7. Re: Assign Access Control to LDAP group
    user5449503 Newbie
    Currently Being Moderated

    Hi,

     

    by right clicking on Application name & Select "Assign Access Control" we can see rights only for groups we can previously selected, and only for selected application each time. Is it possible to obtaing a general view for all applications?

     

    By other hand the problem assigning Access Control was fixed. It was that groups are defined with Essbase Administrator role, changing to Essbase Server Access (lower role) it works, is it a bug of the product?

     

    Thanks

  • 8. Re: Assign Access Control to LDAP group
    Sh!va Pro
    Currently Being Moderated

    by right clicking on Application name & Select "Assign Access Control" we can see rights only for groups we can previously selected, and only for selected application each time. Is it possible to obtaing a general view for all applications?

    ------No you can't obtain the general view for all applications.But you can get the provision details/security details through Shared Services and LCM for all applications.

     

    By other hand the problem assigning Access Control was fixed. It was that groups are defined with Essbase Administrator role, changing to Essbase Server Access (lower role) it works, is it a bug of the product?

     

    ---Do we need to give any other access control for admin, (Admin is like administrator account for OS ). So its working as it has to be... You need to assign extra controls to the users roles...I will say "filter role".

     

    Cheers!

     

    Sh!va

  • 9. Re: Assign Access Control to LDAP group
    user5449503 Newbie
    Currently Being Moderated

    Hi,

     

    how can i obtain Access Control detail for all applications by means of Shared Services and LCM? i don´t find it.

     

    Thanks in advance

  • 10. Re: Assign Access Control to LDAP group
    Sh!va Pro
    Currently Being Moderated

    Check shared services configuration reports ??

     

    for LCM you have to select the applications for the result....

     

    Hope that hint work..

     

    Cheers!

     

    Sh!va

Legend

  • Correct Answers - 10 points
  • Helpful Answers - 5 points