Re-assign a different role to many users

Hello

I need to change the role assigned to a large number of users > 5000. I know that I can do this by using actions in bulk for example

Command, User, Waveset.Roles
Update, user1 | Remove | oldRole
Update, user1 | Merge | newRole
Update, user2 | Remove | oldRole
Update, user2 | Merge | newRole

However, this translates into two actions per user and therefore double the time required to process each user.

Someone has a method, workflow etc. that will allow me to change a user's role, but only one task.

Concerning
Steve

To get action by user, you can put the two changes on one line, i.e.:

Command, User, Waveset.Roles, Waveset.Roles
Update, user1 | List; Remove | oldRole | List; Merge | newRole
Update, user2 | List; Remove | oldRole | List; Merge | newRole

Tags: Oracle

Similar Questions

  • Code examples need to assign the admin role to a user

    I'm looking for a sample code snippet assign administrative roles to a user.

    Help, please.

    Try this.

    Private Sub (String userLogin, String roleName) {} assignAdminRole
    Ars AdminRoleService = oimClient.getService (AdminRoleService.class);
    Client caches = ars.getAdminRole (roleName);
    Arm AdminRoleMembership = new AdminRoleMembership();
    arm.setAdminRole (pine);
    arm.setUserId (getUserKey (userLogin));
    arm.setScopeId("3");
    arm.setHierarchicalScope (false);
    ars.addAdminRoleMembership (arm);
    }

    private String getUserKey (String userLogin) {}
    Take string = null;

    Try
    {
    UserManager usrService = oimClient.getService (UserManager.class);
    User user = usrService.getDetails ("User Login", userLogin, null);
    = Take user .getAttribute ("usr_key") m:System.NET.SocketAddress.ToString ();
    }
    catch (Exception e) {}
    e.printStackTrace ();
    }
    System.out.println ("user key =" + take);
    Return take;
    }

  • How many user take RDP at the same time with different user login ID in Server R2 2012

    How many user take RDP at the same time with different user login ID in Server R2 2012?

    How many user take RDP at the same time with different user login ID in Server 2008 R2?

    How many user take RDP at the same time with different user login ID in Server 2012 starndard?

    How many user take RDP at the same time with different user login ID in Server 2008 standard?

    This issue is beyond the scope of this site (for consumers) and to make sure you get the best answer, we need to ask either on Technet (for IT Pro) or MSDN (for developers)

    If you give us a link to the new thread we can point to some resources it
  • Assign an IOM custom role to a user in OIM 11 g R2

    Hello world

    I created a role whose type is "IOM roles."

    Given that this role should not be assigned per catalog.

    This is not seen on the catalog.

    When I opened the details of this role, I can't assign this role to a user directly.

    How can I assign this role to a user?

    Thank you.

    Best regards.

    Rather than defining the category as the roles of the IOM, you can set the IS_REQUESTABLE flag to 0 in the table of the CATALOGUE on the IOM scheme that will not display the item in the catalog, but it can still be assigned to the users.

    -xelsysadm

  • Assignment of roles to the user when creating the user

    Hi all

    I gave a roll deposited (< dsp:input bean = "ProfileFormHandler.value.roles.role" maxsize = "30" size = "30" type = "text" / > on the registration page.) After registration, each field in db except role (table dps_role).
    Pls let me know what I am doing wrong.

    Thank you

    You should not assign roles to the user as 'ProfileFormHandler.value.roles.role' of 's profile. You can link formhandler property to which you can pass the name or id of the role that you want to assign role assignment must always route through safety ATG API in order to properly update the mappings of Homeland Security. Because of these dependencies, you should not try the role of simply call profile.setPropertyValue ('roles',...) The code cannot fail this way, but if you assign the role in this way then it may not work as expected when checking for role based privileges. Here's one possible way to do it:

    1. in your file properties formhandler declare a dependency on the directory of the default user, which by default points to the profile database:

    userDirectory = / atg/userprofiling/ProfileUserDirectory

    So, in the form Manager, you declare corresponding setUserDirectory() and getUserDirectory().

    2 then in the formhandler, get the DirectoryPrincipal objects associated with the user profile and the role you want to assign and then assign the role to the user:

    import atg.userdirectory.UserDirectory;
    import atg.userdirectory.DirectoryPrincipal;
    import atg.userdirectory.User;
    import atg.userdirectory.Role;
    import atg.userdirectory.DirectoryModificationException;
    
    import java.util.Collection;
    import java.util.Iterator;
    
    ..
    ..
    
    private boolean assignRoleToUser(String roleName, String userId) {
    
      UserDirectory userDirectory = getUserDirectory();
      DirectoryPrincipal userPrincipal = userDirectory.findUserByPrimaryKey(userId);
      DirectoryPrincipal rolePrincipal = userDirectory.getRoleByPath(roleName);
    
      User user = (User)userPrincipal;
    
      Collection collection = userDirectory.getRoles();
    
      boolean status = false;
    
      Iterator iter = collection.iterator();
      while(iter.hasNext())
      {
        Object obj = iter.next();
        if(obj instanceof Role) {
          Role role = (Role)obj;
          if(roleName.equals( role.getName() ) && user!=null) {
            try {
              status = user.assignRole(role);    //will return true if the role was added otherwise false
            }
            catch (DirectoryModificationException e) {
           //handle exception
            }
            break;
          }
        }
      }
      return status;
    }
    

    In the code above 'roleName' parameter is the name of the role to be assigned to the profile with the id as "userId". If you want to do the role assignment when creating the user, then you can do the things above in postCreateUser() so that you can get the Principal associated with the profile. For more information about the interfaces and classes used here, you can refer to the documentation of the API of the ATG.

    http://docs.Oracle.com/CD/E26180_01/platform.94/APIDoc/ATG/userDirectory/package-summary.html

  • Assign a role to a user already created

    Hi experts,

    I created a rule, a role, a strategy of access and every time I have to create a new user of the access policy is properly triggered and appropriate resources are properly assigned.
    If I manually assign a role to a user, IOM provisions automatically objects associated with the role.
    The problem is that all users created before the creation of the role, do not belong to the role: what should I do to give the role to all users?

    Thank you

    1 create an access policy and audit indicator change see details below

    #If renovation flag is set for the policy

    These assessments do not immediately occur after the action. Instead, they occur during the next run to evaluate the schedule task user policies. Evaluations can occur in the following scenarios:

    * Definition of strategy is updated so that the indicator adaptation is defined on IT. Policies are evaluated for all users there.
    * A role is added or removed from the definition of the policy. Policies are evaluated only for roles that is added or removed.
    * A resource is added, deleted, or the flag value revoke if no. Longer applies is changed for the resource. Policies are evaluated for all users there.
    * When the policy data are updated or deleted. This includes data form of the mother and the child. Policies are evaluated for all users there.

    2. a way to do this is to write a scheduled task and using the API assign the role of the user
    Check below link
    http://docs.Oracle.com/CD/E14571_01/doc.1111/e14309/spmlapi.htm
    Article 29.3

  • How to divide the request to assign a role to multiple users in several.

    Hello

    While we are assigning a role to multiple users OIM11g at the same time, demand has cut several queries to get approved by the Manager of beneficiaries. Please let us know ways to apply the composite to divide the application.

    Why two separate approval process? Instead of two only have a license deal with assignment of dynamic loop based Manager of beneficiary to the owner of the role, and attach it to the level of the operation and you should be good (with auto level template and request approval).
    The child requests are generated only at the level of the operation and NOT to any two previous levels. It is the engine of the application for you.

    -BB

  • Assignment of the task to its users and groups

    Hi Experts,

    We have a requirement for the assignment of the task to its users and groups. What are the different options we have to achieve this goal.

    (1) considers that I have 6 groups, 6 groups, I need to take a group and itinerary of the task to a dynamic group.

    Each group contains also 15 users when a task is routed to the Group A then all users in Group A should get the job. How can I achieve this. Can u send me please step by step procedure.

    We use Jdev 11.1.1.6

    (2) I have confusion about the roles of Parametic what exactly it is? And what is the difference between parametric and Management Chain.

    Thanks in advance.

    Pavan

    Dan, thank you so much for the post and the explanation...

    But today, I just mention its only 6 groups... but if the groups continues to increase as groups of 100 or more so how can we achieve...

    Kind regards

    Pavan

  • Assigning a default schema for a user.

    In Oracle can I assign a default schema for a user without using the later session command?

    Is there a USER EDIT setting where I can assign a default schema to a user?

    user9229690 wrote:
    Why don't you create a role and assign this role to this user
    -specify what you want in the role.

    hope this has helped

    That would give the user permission to access the tables in the schema of the app, but it would not eliminate the need to qualify these tables with schema name, and it was the stated purpose of the OP.

    The solution to the OP's question is synonymous, as Centinul suggested. If it is for a single user, private synonym would be appropriate if, as it seems, many users, may need a public synonym would be more appropriate. If who is considered to be a security problem, then either the logon (ALTER SESSION SET SCHEMA CURRENT...) trigger or procedure run when a new user is created, a set of private synonyms.

  • Is it possible to assign a different sound to my second e-mail account?

    I have two email accounts set up and works fine in Thunderbird. My main account, which I use for almost everything and a second account that I use for video surveillance and I was wondering if it was possible to assign a different sound to the second account.

    You can try this addon, it seems to be mixed results.
    Hard to know if it had fallen to not properly configure the user.
    I have not used it myself, but it must be worth a try.

    How to install the Extension module:
    After you download addon extension *.xpi file to the downloads or desktop folder.

    In Thunderbird
    'Tools > "Add-ons"
    or
    'The menu icon ' > 'Add-ons'

    • Click the gear icon and select 'install module file.
    • Find the downloaded *.xpi file and click 'open '.
    • You have as much need to restart Thunderbird when you are prompted.
  • How many user accounts is permitted in windows 7 Home Premium

    Hi, I finally bought Windows 7 Home Premium and had a number of questions below:

    (1) how many users can use Windows 7 Home Premium?
    (2) can I use my (created during the installation of windows) default Administrator account and the guest account?
    (3) can I use my default Administrator account and leave someone else to use the guest account?
    (4) can I create another administrator account and delete my old account administrator?
    (5) can I as administrator (single user) to use more than one user account on my computer?

    Yours,
    MMK.

    (1) don't know (or believe) that there is a numerical limit on the number of accounts no matter who would be worried about using "Home Premium".
    FOR THIS I NEED SOME EXPLANATIONS!

    (2) Yes.  Or advised by some, while first by most.
    For comments, I understand that this account represents a risk factor. But why the account (by default) is not advisable?

    Yours,
    MMK

    (1) do you intend to have thousands of users on the computer Windows 7 Home Premium?  Then you have no worries.  Well, more accurately - it depends on the resources you have.  If you have the hard drive space, you can continue to create users in general.

    It is Home Premium and not professional, enterprise or ultimate edition - it is unlikely, it is used in a domain environment where user accounts are supposed to be more than an environment domestic.  Although you can use it in a business environment - is obviously not a big company.

    (2) - for the most part - you need multiple administrative level accounts; reasons for backup.  The built-in function is one that stays around.  Use it every day and for everything which is not only as imprudent as the use of any other administrative level account-, but it adds to the danger, because it is one you are not easy to get rid of.

    My advice is for you to create at least one additional administrative level account and make sure that the passwords for all the administrative accounts (different passwords for each account) is 15 + characters with at least one of the three following types of characters: uppercase letters, lowercase letters, number, and symbol.  Then create standard accounts for each normal computer user and don't give the administrative password to those entrust you the powers he gives them.  No need to start as an administrative level account for most (if not all) - just creative use of RUN AS ADMINISTRATOR.

  • Revoke ROLE on the user table

    Hi team,

    I'm trying to revoke grant on the user table

    The Sub statement gives error saying

    [code]

    REVOKE < role_nm > on < a.table_nm > to < b.user_nm >

    Error: ORA 00990: missing or invalid privilege

    [/ code]

    But the following works fine

    [code]

    REVOKE ALL ON < a.table_nm > to < b.user_nm >

    [/ code]

    Please suggest me to revoke the grant on the user table

    Smile says:

    [code]

    REVOKE on of

    Error: ORA-00990: missing or invalid privilege

    [/ code]

    A GRANT on table is assigned to a ROLE and that ROLE is assigned to the USER. So when you want to REVOKE a specific GRANT what is assigned to a user by ROLE. You must REVOKE any ROLE to the user or REVOKE the GRANTING OF THE ROLE.

  • URM notification based on roles rather than users.

    When you configure URM there is possibility to assign a writer to the category and a critic of Notification for a provision. Unfortunately, two of them allow for individual users as far as we can tell. In addition, there is the role of RMAReviewers that seems to "notify" users that something has occurred, but there seems to be a break. Does anyone know how to assign the role of RMAReviewers (or any role) to the author or a reviewer Notification so anyone having this role will see the provisions assigned to this role in My Content Server pending / My documents assignments? As it is, that one user will actually see these provisions, unless they all click list.

    Thank you.

    So first up front, what you ask is not completely and cleanly as possible OOTB. You can get to the 'part' of the solution, but overall, it sounds a bit like an enhancement request.

    'RMAReviewers' is not a 'role', but simply an 'alias' with special meaning. It is a great distinction - impossible to assign users to an alias based on the membership of a group in AD/LDAP. (I do not think that Fishbowl offers such customization, but this isn't an OOTB scenario.) Adding a user to the alias is manual.

    URM11g, and then uses this alias to do two things - 1) send notifications to members of the alias and 2) control access to users who could potentially see the layout any list, treatment more so than just the items for which the user is directly responsible. As a general rule, such a group of users are admins of documents, so that they in theory should be able to see all the actions to come anyway. (But you might have a group of 25 records admins, with only 1 or 2 actually responsible for approvals other content not directly attributed to them. Put these 1 or 2 people in the alias then limited who can see and act on the global list).

    In AAU/URM, there is no concept of a group of 'own' a given object. It is always an individual user who has actually. (I don't see this change.) Given that the category is "owned" by an individual, you will only get the option to choose a user. The stage of notification is similar, where you can choose a user, rather than a group.

    So the just solution of 'Party' emphasis on the aspect of the notification. (In any case, you can use the option "list all the '.) If this additional button click is simply boring, create one link somewhere else for the complete list.)

    To report a group of people, you will need to create a generic user who will be the "author" / "owner" of the category. This user will also be an email address that is simply a group mailbox. When the Treaty system, it retrieves the generic user's e-mail address and send the mail. The mailbox of the group then just send a copy to all the people who are assigned to the mailbox of the group. In this way, everyone gets warned that action is necessary and can enter the system to act.

    Repeat the same process for the step of the notifier, except with another generic user.

    It certainly isn't the cleanest way, but probably as close as you will get OOTB.

  • How many users we can create?

    Hai all,

    How many users we can create in an any version oracle database
    or
    maximum number of users allowed to create in the oracle database.

    http://download.Oracle.com/docs/CD/E11882_01/server.112/e25513/limits003.htm#i288032 says:

    >
    Users and roles maximum 2,147,483,638

  • assign MORE storage space to a user

    Hello

    I'm using sql * plus, oracle 10 g, windows 7.

    I know that I can assign a default tablespace for a user.
    e.g. SALLY DEFAULT TABLESPACE ALTER ACCOUNT user;

    How to assign a different tablespace for example EMP for the same user?

    Published by: sweetiePie April 30, 2011 22:01

    Hello

    To allow SALLY to use up to 500 MB on the tablespace (IEM), an authorized user (such as SYSTEM) can mean:

    ALTER USER sally QUOTA 500 M ON emp;
    

    Allow SALLY to use regardless of the space available on ts2 tablespace:

    ALTER USER sally QUOTA UNLIMITED ON ts2;
    

    You can make any number of commands like those above; they will not interfere with each other.

    However, a user can have only one default tablespace at any time. If the default tablespace of SALLY's account, and she wants to create a table or index into any other tablespace where she has a quota, then she has to specify this space in tables in the CREATE statement, like this:

    CREATE INDEX     table_x_last_name_idx
    ON          table_x (last_name)
    TABLESPACE     emp
    ;
    

Maybe you are looking for

  • Synchronization between devices

    I have an iMac, iPad + iPhone all with the same apple ID. Set of synchronization via iCloud photo library. Sync / update of photos between devices, do I have to open the Photos App? or synchronization works even without an application to open picture

  • Hard drive crashed and now 'My Documents' reports 'access denied '.

    My drived by 'C' crashed. I replaced the trive and install a new copy of XP pro on a new drive. I plugged the old drive as slave and when I go to the 'Documents and Settings' area I am able to open most of all files except thoes in "Documents and Set

  • MIC fixed, it cannot load...

    I cannot sign says try again later for the last week, what can I do? Almost all of the executable files do not work.  I have to reload all, but don't know how to get Microsoft fixit to connect and when I put the old FIXIT on has started last year it

  • put a lot of files to *.mp3 in sourceUrl

    Hi, who can not I put a lot of files to *.mp3 in sourceUrl MediaPlayer {}ID: playMedia} as: "/ sounds/001000.mp3. "/ sounds/002000.mp3. and play all the theme an author

  • Installation of Acrobat DC to alternate file

    There is an option at all for this?