Managing groups and user rights on Windows Active Directory

Hi all,

I’m setting up a Bi environment for my client using “Business Objects Xi R2” and “Windows Active Directory”.

The security team wants to centralize the groups and users rights on all the ressources (Business objects Folders and reports) on Active Directory.

Is it possible to define all the rights on “Active Directory” and then use them automatically to manage the access to folders and reports in Infoview?

How can I configure the CMC in order to use the rights defined on Active Directory?

Note: We don’t want to use BO SDK.

Thanks for your answers.


bngbob :cote_divoire: (BOB member since 2006-03-09)

You can define the groups in the Active Directory but you have to assign the AD groups to the proper folders and also to the applications(Infoview, Designer etc) in the CMC.


Sheshachala5 :india: (BOB member since 2004-01-09)

Do you mean,
I can define the groups and users in “Windows AD” but I can’t specify in “Windows AD” that a user or a group have or doesn’t have the rights to access to a business Objects ressources (folder or report)?

I’m oblige to proceed as follow?

  1. Define groups and users on “Windows AD”?

  2. Manage the rights on "folders and “reports” on Business Objects using the CMC?

Thanks


bngbob :cote_divoire: (BOB member since 2006-03-09)

Yes, thats true. Define your BO groups who have access in the AD and once you configure the AD authentication in BO you can map these groups to the folders and Applications in CMC.
That way, when a user in the company needs access to BO, then he will be added to that particular AD group. As those particular groups have access to BO reports and applications they can use their AD account to login and view their assigned stuff.


Sheshachala5 :india: (BOB member since 2004-01-09)

Ok,

So it is not possible to define the groups, the users and their rights on Bo folders and reports on Windows AD.

Solution

  • Groups and users on Windows AD
  • Rights on Folders and Reports on Bo

Our first target is to manage everything (groups, the users and their rights on Bo folders and reports) on Windows AD.

But I think, we can work that way.

Thanks a lot


bngbob :cote_divoire: (BOB member since 2006-03-09)

Yes this is correct. You can create a group in AD who will have access to Universe Designer tool and then map this group in CMC to have access to designer.


Sheshachala5 :india: (BOB member since 2004-01-09)

I recently had to do this.
Steps used were

  1. Ask your it admin people to create groups for your business object report purpose and ask them to add all the users of ur bo reports in that group who would be given ad authentication by u in cmc.
  2. Then add this created group to your business object ad authentication group list ( inthe authen section of your cmc)
  3. Then create users or add existing existing user to this group and specifing the ad authentication method. If you dont have agroup created and u try to give ad verification then error comes saying that the user doesnot belong to a mapped group.

In future, I suppose if a new user has to be added to this group, the IT admin will have to add this user to the group they created usign their rights.


armadain (BOB member since 2006-04-07)

Ok,

I totally agree with the steps you described.

We’ve planed to do as you said.

But what we want to do is to set up specifics attributs in windows AD such as:

  • default_language
  • default_region

And we want to know if we can read these attributes when a user log on Infoview.

Thank you.


bngbob :cote_divoire: (BOB member since 2006-03-09)