EcoStruxure IT forum
A support forum for Data Center Operation, Data Center Expert, and EcoStruxure IT product users to share knowledge on installation, configuration, and general product use.
Posted: 2020-07-04 02:48 PM
This question was originally posted on DCIM Support by Shaik Mahboob Ali on 2018-03-06
Hi Team,
I am facing issue for users assigned restricted access to specific folder but still users can see & access all DCE devices in client.So what kind of privilege do it work ?
specifically selected folder from the device group access to users but still all the folders are visible to all the users.
Is this a bug or please guide me its very very serious to resolve this issue at earliest.
Version : DCE 7.4.3
(CID:129403320)
Posted: 2020-07-04 02:48 PM
This answer was originally posted on DCIM Support by Steven Marchetti on 2018-03-06
Hi Shaik,
The only time I have seen issues like this are when users are part of a group and the individual and the group have different permissions. The group may have rights to only one device group but the user is configured as an administrator of the server. I've also seen where someone ads an LDAP group and gives it rights but they also have local individual users that conflict with those in the groups. The user could also be part of multiple groups which could have the same effect.
As spezialist mentioned, screenshots showing information such as you see here for both the individual users and group(s) would be helpful in understanding what it is you're seeing as I too am unable to replicate your issue.
Steve
(CID:129403434)
Posted: 2020-07-04 02:48 PM
This comment was originally posted on DCIM Support by spezialist on 2018-03-06
Dear Shaik Mahboob Ali,
I can not reproduce the above bug in DCE software.
Please, show a screenshot with an example of what you reported above (Users and Device Group Access window and Device Groups tab for a particular DCE user).
With respect.
(CID:129403385)
Posted: 2020-07-04 02:48 PM
This answer was originally posted on DCIM Support by Steven Marchetti on 2018-03-06
Hi Shaik,
The only time I have seen issues like this are when users are part of a group and the individual and the group have different permissions. The group may have rights to only one device group but the user is configured as an administrator of the server. I've also seen where someone ads an LDAP group and gives it rights but they also have local individual users that conflict with those in the groups. The user could also be part of multiple groups which could have the same effect.
As spezialist mentioned, screenshots showing information such as you see here for both the individual users and group(s) would be helpful in understanding what it is you're seeing as I too am unable to replicate your issue.
Steve
(CID:129403434)
Posted: 2020-07-04 02:48 PM
This comment was originally posted on DCIM Support by Shaik Mahboob Ali on 2018-03-06
Hi Thanks for the update . I have created a new user local and he does not belongs to any group or any administrator. Only he is authorized for a specific folder but still he can see all the devices with out any other privileges on menu bar.
(CID:129403494)
Posted: 2020-07-04 02:48 PM
This comment was originally posted on DCIM Support by Steven Marchetti on 2018-03-06
Screenshots? Can you provide specific info as to what rights he has, what devices he can see, etc? If you want someone to try and replicate what you're seeing, you need to provide more information. Here's what my admin can see:
When I create a user and give him access to only one folder with view and control access:
His access is limited to what I gave him:
You can clearly see the difference between the first and last images.
Steve
(CID:129403542)
Posted: 2020-07-04 02:48 PM
This comment was originally posted on DCIM Support by Shaik Mahboob Ali on 2018-03-06
HI Steve,
I have created a user name shaheen. Please see the attach pictures.you can understand the issue i am facing. user shaheen is having access only to one folder called "Shaheen-Cabinet Power" but this user can see all other devices also. why ?
(CID:129403639)
Posted: 2020-07-04 02:49 PM
This comment was originally posted on DCIM Support by Steven Marchetti on 2018-03-06
Hi Shaik,
Don't put him in the device viewer's group. By putting him in that group you are automatically giving him view rights to all devices. As you can clearly see in my screenshots, the user I created was not a member of any groups and had access to only those groups specifically designated. You have conflicting rights where the user has rights to only one device group but the user group you've added him to has view access to everything.
You can also create your own group and add the user to that group.
As you can see here, the user Shaik is part of Shaik's group and Shaik's group has access to the transfer switch device group:
If you log in as Shaik in this server, you can see the access he has:
You can see that he has access to 2 groups. This is because when I created the user initially, I gave him access to the UPS device group.For this response, I added him to the Shaik group and the group has access to the transfer switch device group. He has access to both as the rights of the user and the rights of the group are combined.
Make sure you don't add the user to the wrong group.
Steve
(CID:129403704)
Posted: 2020-07-04 02:49 PM
This comment was originally posted on DCIM Support by Shaik Mahboob Ali on 2018-03-06
Thanks Steve for your understanding to my issue and really appreciate your support to guide me with right process with perfect example.
Best Regards
Shaik Mahboob Ali
(CID:129403744)
Posted: 2020-07-04 02:49 PM
This question is closed for comments. You're welcome to start a new topic if you have further comments on this issue.
Create your free account or log in to subscribe to the forum - and gain access to more than 10,000+ support articles along with insights from experts and peers.