BusinessObjects Board

Security Setup

I’ve been thrown into getting our Web Server set up for business objects set up. Currently we have had handful of users with full client Business Objects installed on their machines. Needless to say, I have no training (hey, but that’s a whole different story :crazy_face: ). I’ve gotten to the point were I am setting up the security in Supervisor. I read the document “Let me speak to your supervisor” and have begun as follows:

Corporate
–Privileges
----Viewer
----Designer
----Report Writer
–Data Access
----Department 1
------User A
----Department 2

So, in the Data Access group, I have disabled access to Designer, BusinessObjects, Supervisor, Business Query, WebIntelligence. However, when I add User A to the Department 1 group using the User Profile, suddenly BusinessObjects is active for that user Inherited from Profile. How do I get BusinessObjects to be disabled for the user profile or to Inherit from my Data Access Group. Or, am I still missing something in how Inheritance works. Any help you can provide before I get too far along would be great.

Thanks a million in Advance :smiley:


krebsy (BOB member since 2004-03-05)

I think you’re running into the “sometimes most restrictive / sometimes least restrictive” problem.

For configuring resources (roles / access / modules / features), users in multiple groups are granted rights on a Most Restrictive basis. That is, if a feature is revoked from the user in one place, it’s gone everywhere.

For configuring Information Resources (e.g., universes), granting is done on a [b]Least Restrictive /b basis. That is, if you are granted a universe in one group, you have it everywhere – even if you are in another group where that universe is not available.


Anita Craig :us: (BOB member since 2002-06-17)

I think that a User profile automatically enables Reporter.

I use the Versatile profile for these types of people.


KSG :us: (BOB member since 2002-07-17)

Ok, so I figured out that I need to have Business Objects enabled b/c all of our reports were created in the full client. So, I have created a configuration group called Report Viewer and disabled ‘Create Documents and Create Templates’ in BusinessObjects and disabled ‘Create Documents’ in Web Intelligence. However, when a user in this group logs into WebIntelligence, I still see the Create Documents link and BusinessObjects opens. Once B.O. opens, the user doesn’t have access to create documents, but I would prefer that the Create documents link in WebIntelligence was hidden. Is this possible?


krebsy (BOB member since 2004-03-05)

How long did you wait from the time you made the change until you tried it. It takes up to 10 minutes to take effect and you have to log out first.


Steve Krandel :us: (BOB member since 2002-06-25)

I initially tried it immediately after I made the change (no patience). But, I’ve been in a meeting since then and I tried again with the same results.

Maybe I’ll just try again in the morning.


krebsy (BOB member since 2004-03-05)

I just wanted to post a followup and let everyone know I finally was able to obtain my desired results. :lol:

When Configuring the groups for the WebIntelligence Module under Options, I marked ‘Download Zero Admin Business Objects’ as hidden and this removed the ‘Create Documents’ link when a ‘User’ profile logs into WebI.

Thanks everyone for your suggestions!!!


krebsy (BOB member since 2004-03-05)

Security Setup

Okay, been working at BO for the past year and its very cool. But we are currently on version 3.x and moving to 4.0 September 2012

I was wondering if you or how you did your profile setups. I am unfamiliar with the best way to set this up and I think the way its set up here can be better. I know some things about View on Demand and Admin but if you have a template you used on setting your users up I would greatly appreciate the start.

We have SAP authentication n using SQL Server as the database. If you use LDAP or some other method I would like to see what and how you implemented the single-sign on. Seems a bit hard from what I have been trying to understand from the documentation. Actually most of the docs I read have been …Not at all clear for me :?


Joealyche (BOB member since 2012-02-29)