on 07-29-2015 12:46 AM
Hi Experts,
We are facing a wierd issue with BPC 10.0 Data Access Profiles. We have transported 3 DAP thru Dev -> QA -> Prd. It is working fine till Quality but in production we can see the new data access profiles but we cannot assign them to the users.
This is not a security authorization issue as we can assign other data access profiles to the users successfully. I checked UJE_PROFILE_AGR table and entries are present but table AGR_1251 doesn't have any entries for the PFCG role generated by the Data access profile like other data access profiles.
I ran report UJE_VERIFY_SECURITY_DATA in production and it shows new data access profiles doesn't exist which is not true because I see them in table UJE_PROFILE_AGR. I have not tried by checking Fix Security data option in this report as I am not 100% sure of the impact.
Could anyone please advise or guide me why we cannot assign either from front end or backend ?
I tried to find some KBA/OSS notes on marketplace but could not find anything related this issue
Regards,
Salman
issue resolved. PFCG role was not generated.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Salman,
Can you please clarify what does it mean that you can't assign DAPs? Do they show up when you click "Add/ Remove" in DAps tab? Screen shot would help.
Regards,
Gersh
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Gresh,
There is a outage right now so cannot take screenshots.
Yes, the DAP's show up and we can add it to the users but when we save it does not reflect and we also tried to assign PFCG role in backend and it dispalys as Role doesn't exist.
But, we can assign other DAP's without any issues.
We have been transporting our task and Data access profiles to production without issues since two years. Followed same process for these new DAP's as well.
Regards,
Salman
Hi Salman,
Still not clear. What does it mean "it doesn't reflect": does it mean that you don't see new Roles added to the user master or you can see those Roles, but the y don't take effect? Can you see those roles in PFCG?
Also, when you try to assign those Roles in back-end, how do you know which generated roles to use?
Have you assigned those roles before in back-end? Have you created them in production in that namespace?
Regards,
Gersh
Hi Gresh,
1. Once DAP's are transported to production. We use table UJE_PROFILE_AGR to get the correct generated PFCG roles
2. We use these generated PFCG roles to assign to the users using SU01
3. In this case, We can see PFCG role generated for the DAP in table UJE_PROFILE_AGR but when we use SU01 to assign them to the users. SU01 --> User id --> roles --> paste PFCG role --> "Role Doesn't exist" error message appears. Also, role doesn't exist in PFCG
.
4. Then we thought of adding these DAP's from BPC front to the users. We can see the new DAP's but when we add them to the users and save it then see the user whether the DAP is added or not added --> Not added
5. BPC is not creating PFCG roles for the DAP's automatically.
Hope I answered your questions.
Regards,
Salman
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Andy,
We have been transporting BPC security object through landscape since two years without issues. The problem is with these particular data access profiles. The DAP's exist in production but when we add them to the users it says doesn't exist.
Not able to understand why DAP is not getting added to the users like other DAP's.
Regards,
Salman
User | Count |
---|---|
15 | |
3 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.