EcoStruxure IT forum
Schneider Electric support forum about installation and configuration for DCIM including EcoStruxure IT Expert, IT Advisor, Data Center Expert, and NetBotz
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-05 04:15 PM . Last Modified: 2024-04-03 05:10 AM
Hi Team,
we have a DCE 7.5 deployment with an authentication server configured and it is working properly. We can create a new user from AD and assign rights to different locations.
But when we create a local user in DCE with the purpose to give only access to a specific location, it does not work properly. It seems that everything is configured but when you log with this new user you can see all the locations:
The user is TSB:
Without administrator's rights:
It has only view access to Brasil:
But when you log with this user you can see and edit all the locations:
(CID:138381629)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-05 04:15 PM . Last Modified: 2024-04-03 05:10 AM
Hi Javier,
I've only seen this happen when the user is either:
A: Also a member of another group that has another set of rights such as server admin or any local group (User Group Membership) with differing rights
or
B: A duplicate user where that name exists as both a local user as well as an AD user.
Steve
(CID:138381646)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-05 04:16 PM . Last Modified: 2024-04-03 05:10 AM
Hi Steven,
thank you for your answer. We have checked and this user is only in group Device Viewers:
And this group does not have special rights:
And in the remote users there is not an user with the same name:
(CID:138381653)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-05 04:16 PM . Last Modified: 2024-04-03 05:10 AM
Javier,
Ok, so he's part of device viewers. That is a group that has a certain set of rights.
You then give the user specific rights to device groups. This is the conflict. If you see here:
I've created a user and added him to the device viewer group. I did not add any specific rights to any specific groups. I simply logged in and saw what you see above.
If I then remove him from that group and give him specific view access to only one device group:
Now he can only see this:
So you must either provide him specific view access to a specific device group as you did here:
OR you must add him to the device viewers group that can view ALL groups at that level. If you do both, he will get the higher level of access.
Steve
(CID:138381682)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-05 04:16 PM . Last Modified: 2024-04-03 05:10 AM
Thank you Steven, I have checked and now it is work fine. But I think is not well considered. Because if at least when you insert a new user into a group you could see the inherited rights, you could disable what you do not need. I think the user should have more restrictived rights than the group, now you can not eliminate any right if the group has it.
Does it work in DCO in the same way?
Regards
(CID:138381704)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-05 04:16 PM . Last Modified: 2024-04-03 05:10 AM
That's true Javier but if you want a group with specific rights, we also offer the option of creating your own user group. You can then give that group access to specific device groups as you see fit. In an case, I'm glad you know how it's working now.
Steve
(CID:138381726)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-05 04:16 PM . Last Modified: 2024-04-03 05:09 AM
Yes, Thank you Steven Marchetti
(CID:138381919)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-05 04:16 PM . Last Modified: 2023-10-22 01:17 AM
This question is closed for comments. You're welcome to start a new topic if you have further comments on this issue.
Link copied. Please paste this link to share this article on your social media post.
Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.