Oracle Analytics Cloud and Server

Welcome to the Oracle Analytics Community: Please complete your User Profile and upload your Profile Picture

OBIEE 12c: Delivering Content to SQLAuthenticator Groups

Received Response
1
Views
2
Comments
Rank 5 - Community Champion

Hi,

I'm using the authenticator provider BISQLAuthenticator to bring users and group infomation from oracle database tables into OBIEE (12.2.1.2.0).  The BISQLAuthenticator is working well as I can map the groups from the database to OBI application roles and permission correctly what the users can see on the UI.    However when i set up Agents and add any of these OBI application roles as the Recipients the content is not being delivered but does deliver if i add the user directly (i.e. not via the role)  anyone know is this an issue that Delivers can't determine the user to group membership for the BISQLAuthenticator?  or anyone run into something similiar and got round it?

Thanks

Answers

  • Rank 5 - Community Champion

    In the 12c documentation the Prerequisites here https://docs.oracle.com/middleware/12212/biee/BIESC/GUID-30F09EE4-A2DE-443D-BF24-CC401B6E13FD.htm#GUID-C9E78F90-B14F-408…    states

    • If you need Oracle Business Intelligence to deliver content to members of an application role the following restrictions apply:
      • You can only pair a single LDAP authenticator with a single BISQLGroupProvider.When you configure multiple LDAP authenticators and want to retrieve
        group membership from the BISQLGroupProvider, content cannot be
        delivered to all members of an application role. In this configuration Oracle BI Delivers cannot resolve application role membership based on users and group membership.
      • You cannot define the same group in more than one identity store.You cannot have a group with the same name in both LDAP and database groups table. If you do, the security code invoked by Oracle BI Delivers cannot resolve application role membership.

    Reading this tells me delivering content to application roles is possible with the BISQLGroupProvider as long as your configuation doesn't meet the two points.

    My setup involves configuring the BISQLGroup Provider with the Default Authenticator therefore one LDAP to a single BISQLGroupProvider.

    Anyone configured the BISQLGroupProvider and able to deliver content to app roles ?

  • Rank 5 - Community Champion

    I believe, to adding individual user to agents, you need to configure SA System subject area.

    you can try this - https://docs.oracle.com/cd/E17904_01/bi.1111/e10541/sa_system.htm#BIESG3141

Welcome!

It looks like you're new here. Sign in or register to get started.