Hi Guys,
I have a problem.
I have a TM1 server that is IntegratedSecurityLogin=5. I have two admin accounts for the moment. These two user accounts (A and B) are Active Directory accounts.
My problem is when I assign the account B to any (one or all) of non-admin groups, when I try to login using this account B, an error prompts saying 'Client Does Not exist on the server'.
So I logged in using the admin account A. And there I see that the assignment I made for the account B is already gone. Like no marks at all, no traces.
Why does this happen guys?
Prior to this, I wasn't able to see the manually-added groups I created in the Select Group in Performance Modeler when I tried to manage the Rights for my application. (See image)
I noticed that the principal element name convention in TM1 }Groups dimension is CAMID(":<Group Name>"), and a attibute value format for }TM1_DefaultDisplayValue of Cognos\<Group Name>.
I followed the existing formats and was able to see the groups in the selection pane. I did the formatting in TI.
Are these two issues connected?
Please help.
I really appreciate it.
BUnch
User group assignment gets lost in log in attempt
-
- Regular Participant
- Posts: 197
- Joined: Thu Dec 03, 2009 8:47 am
- OLAP Product: IBM Cognos TM1
- Version: 10.2.2.x
- Excel Version: 2010
- Location: Singapore
User group assignment gets lost in log in attempt
- Attachments
-
- Performance Modeler
- Capture.JPG (51.43 KiB) Viewed 4635 times
-
- Posts: 8
- Joined: Thu Oct 18, 2012 12:24 am
- OLAP Product: TM1
- Version: 9.5.2
- Excel Version: 2003
Re: User group assignment gets lost in log in attempt
Hi mate,
Just wondering if you have fixed this issue already, I am going through the same issue now with CX10.2, I have made sure I add users and tag them to respective groups in Cognos BI before adding and assigning a user to a group in TM1, still no luck.
Cheers,
Venu.
Just wondering if you have fixed this issue already, I am going through the same issue now with CX10.2, I have made sure I add users and tag them to respective groups in Cognos BI before adding and assigning a user to a group in TM1, still no luck.
Cheers,
Venu.
-
- Community Contributor
- Posts: 156
- Joined: Tue Apr 02, 2013 1:41 pm
- OLAP Product: tm1, cognos bi
- Version: from TM1 9.4 to PA 2.0.9.6
- Excel Version: 2010
- Location: Toronto, ON
Re: User group assignment gets lost in log in attempt
You can't assign users to groups in TM1 if you're using IntegratedSecurityLogin = 5.
The User to Group mapping should be done in Cognos BI or whatever namespace you use (i.e. third party LDAP )
After user connects to TM1, the TM1 }ClientGroups cube will be updated automatically for that specific user.
The User to Group mapping should be done in Cognos BI or whatever namespace you use (i.e. third party LDAP )
After user connects to TM1, the TM1 }ClientGroups cube will be updated automatically for that specific user.
Ardian Alikaj
- qml
- MVP
- Posts: 1095
- Joined: Mon Feb 01, 2010 1:01 pm
- OLAP Product: TM1 / Planning Analytics
- Version: 2.0.9 and all previous
- Excel Version: 2007 - 2016
- Location: London, UK, Europe
Re: User group assignment gets lost in log in attempt
That is not a correct statement. In security mode 5 it is possible to mix CAM and native TM1 groups. You might not be able to make assignments via the Server Explorer security grid GUI (which is rather useless anyway), but all the other options like TI security functions or writing directly to }ClientGroups are still available and work fine.ardi wrote:You can't assign users to groups in TM1 if you're using IntegratedSecurityLogin = 5.
Kamil Arendt
-
- Site Admin
- Posts: 1457
- Joined: Wed May 28, 2008 9:09 am
Re: User group assignment gets lost in log in attempt
I agree with QML (of course).
I do recall, and would welcome input, that with CX 9.5 at least, if you entered membership of Cognos groups via Architect (either via the proper dialogue, or into the cube) that it would be overwritten from the half a$$ed version of CAM which came with that product. I haven't revisited this with 10.2.2 but will try to find the time to do that.
With PA (=10.3), since the shared partner instance at least does not allow access to CAM, I did establish that I could add a 'normal' group via TI and put users into that group, and the membership persisted - PA would have been royally stuffed if that hadn't been possible.
I do recall, and would welcome input, that with CX 9.5 at least, if you entered membership of Cognos groups via Architect (either via the proper dialogue, or into the cube) that it would be overwritten from the half a$$ed version of CAM which came with that product. I haven't revisited this with 10.2.2 but will try to find the time to do that.
With PA (=10.3), since the shared partner instance at least does not allow access to CAM, I did establish that I could add a 'normal' group via TI and put users into that group, and the membership persisted - PA would have been royally stuffed if that hadn't been possible.
-
- Community Contributor
- Posts: 156
- Joined: Tue Apr 02, 2013 1:41 pm
- OLAP Product: tm1, cognos bi
- Version: from TM1 9.4 to PA 2.0.9.6
- Excel Version: 2010
- Location: Toronto, ON
Re: User group assignment gets lost in log in attempt
Well, what I meant is, you cannot Assign LDAP Users to LDAP Groups in TM1. Actually TM1 will not stop you from doing that, and you assign a non-TM1 user to a LDAP group, the }ClientGroups cube gets populated properly, and that gives you the perception that everything is fine. But next time the user logs in, that kind of membership will be goneqml wrote:That is not a correct statement. In security mode 5 it is possible to mix CAM and native TM1 groups. You might not be able to make assignments via the Server Explorer security grid GUI (which is rather useless anyway), but all the other options like TI security functions or writing directly to }ClientGroups are still available and work fine.ardi wrote:You can't assign users to groups in TM1 if you're using IntegratedSecurityLogin = 5.
Ardian Alikaj