The sub-groups and access policies

It seems that when I add a user to a subgroup, the access policies of the parent that user Group does not occur. However, the user is added to the parent company of the Group of users
Can someone please verify this?

Thank you

Subgroups does not inherit the access policy of SuperGroup in IOM [ID 815373.1]

Bug 5985475 :

Define an event handler after insertion and attach it to Manager data access policies as an object so that when a group is assigned to an access policy, it checks and add its subgroups to the access policy (just the first level as it will recursively the same it keeps adding subgroups). Verify that you have the same event handler attached to the event after removal of the access policy, so that to delete the access of a group policy, all subgroups are also dismissed by the access policy

Good luck!

Tags: Fusion Middleware

Similar Questions

  • Portal Page, the Page groups and access - AUDIT

    Hi all

    I have a client who has an Intranet Portal that contains hundreds of pages with different conditions of access.

    They would like their portal, checking that they are planning to give it an overhaul and erase all old pages.

    A list of information they would like to include:
    (1) a list of all current pages (possibly showing the hierarchy),
    (2) a list of the user who has access to each page
    (3) the last time a page has been visited and possibly some stats on how many times she visited


    Is there a way to get this type of audit information? This functionality is provided in the portal?

    I leaned on these forums - people have asked the same questions, but it doesn't seem to be an answer.

    I have no idea where to start, so any information would be appreciated!

    Amanda.

    Hi Amanda,.

    For such a solution, you need to use several sources and write a custom solution. and to be honest with you, generally, it is not inclined to simply publish or State all these scripts custom in public forums. However, for works custom / advanced for a smart developer, a set of indicators should be enough.

    you will need to write scripts to run on your pages to collect the data you are looking for.
    You can get the list of pages in a number of ways. including using wwsbr_api. or just go and extract from the table wwpob_page$.

    to search for access privileges, you can discover the use of this table: portal.wwsec_sys_priv$
    for example;
    Select the separate name of portal.wwsec_sys_priv$ where object_type_name = 'PAGE '.
    Please see this note. [311982.1 ID]

    for usage statistics, Portal 10.1.4 offers a performance monitoring tool. you order it and then can get statistics on how many times those that have been visited. You can search in the Portal performance analysis oracle documentation.

    hope that helps!
    AMN

  • How to create the home group and how to connect two computers that are running windows 7. and also Remote Desktop connection!

    Someone help me how to create the home group and how to connect two computers that are running windows 7. and also Remote Desktop connection!
    step by step information!

    Hello

    I suggest you to refer to the links and check if it helps:

    Create a homegroup

    http://Windows.Microsoft.com/en-us/Windows7/create-a-HomeGroup

    Join a homegroup

    http://Windows.Microsoft.com/en-us/Windows7/join-a-HomeGroup

    Setting up a network home

    http://Windows.Microsoft.com/en-us/Windows7/setting-up-a-home-network

    Remote Desktop connection

    http://Windows.Microsoft.com/en-us/Windows7/products/features/Remote-Desktop-connection

    What types of connections remote desktop should I allow?

    http://Windows.Microsoft.com/en-us/Windows7/what-types-of-Remote-Desktop-connections-should-I-allow

    Remote Desktop connection: frequently asked questions

    http://Windows.Microsoft.com/en-us/Windows7/Remote-Desktop-connection-frequently-asked-questions

    Let us know if it helps.

  • VMRC permissions Voodoo - limitation of the ad group and folder VM-based Console access

    We are allowing access to their virtual machine using VMRC console administrators. Our Unix administrators get access to their virtual machines and the same Windows administrators, but they should not be able to access each of the other consoles.

    We have implemented a 'VMRC Console' role and allowed only 'Interaction of virtual Interaction/Console machine' for this role. When we apply this role to the user group AD for Unix (for example) administrators on the ESXi host objects, they are not able to connect unless we put the option spread. When we do this, they now have access to all THE consoles, not just them.  As soon as uncheck us spread it, they can see their VM once again, but cannot access the console.

    What is the secret sauce here to limit them to their own consoles? I can see why this is happening, but I was hoping that the VM folder permissions would have limited their access. Apparently the host permissions override the VM folder permissions (and this is not surprising, really).

    There is currently no provision for limiting access to a single console you want. Work is ongoing at this address in a future version with changes in vSphere, ESXi/etc. and VMRC.

  • Enter the user groups and privileges in labVIEW

    Hey Gang,

    We are developing an application in LV 2010 where we need to control user access to the parts of the application.  This application will be installed on about 50 machines.  It dept can assign users to one or more of the three special groups to manage permissions through Windows.  I need to be able to read what the current user belongs to groups by programming LabVIEW.  I know that this can be done in Teststand, but we do not use that.

    I know how to get the user name of the application object, but we have to manage our own list of privileges on the network somewhere and we do not want to do that.

    I saw here in the DevZone that someone posted a DLL that return a Boolean value if the user is an administrator, and who has come close, but do not do.

    I hope that we don't need to dig into the programming to do this Windows System.  It seems that someone would have done this before.

    Any help is appreciated!

    Roger

    Ready to deal with a .NET solution? The joint assumes that you are in an environment Active Directory. NOTE: This requires .NET 3.5.

  • service groups of access policies

    I have an access policy1, which provides a user with a group in AD function attribute1.
    The I have an another policy2, which supplies several groups for this user based on attribut2.

    When attribut2 changes, another policy (strategie3) comes in to add more groups. I need to know if the previous groups are going to be cancelled in policy2 supply? will just groups be cancelled only supply? I want the user to be always be there and just existing supply cancelled and no new groups put into service.

    THX

    Hello

    For forms of process changes, the policy with the lowest priority gets run the show.

    For child form entries, I suppose that the values are culminitative and will be revoked if you selected "revoke if not apply ' so you should get the behavior you want assuming you have implemented the belonging to the RO group without the parent form.

    Best regards
    / Martin

  • Question about the account administrator and access

    I am logged in as administrator, but when I try to access certain programs or files that I am refused access as a limited user.

    Can anyone help?

    Jon

    Hello

    You can access files or programs by making a 'right-click' on the file/shortcut and 'left click' on 'run as administrator '. ».

    Then, the application will run wirh maximum rights and full access.

    Welcome them

  • Cisco Unity Connection (CUC) - import LDAP user based on the security group and then assign a model

    Need to CUC automatically import users and assign a certain user or role model if they are added to a specific security group. (These are the help desk users).  Username admin accounts they will use to sign in CUC differs from that there windows account that is linked to their profile of voicemail.

    Current - now we must import new recruits and assign the correct model

    Want - when a user is added to a security group in AD, so when CUC doing his nightly sync, it automatically import user and assign a preconfigured for the account and all user model is automatic and I have never import it back these users.

    At the present time the course help desk users are already imported via LDAP and have the role that was.

    Suggestions?

    Not something that the UCA can do out of the box.

    The UCC does not offer, is to do the LDAP synchronization and once they are in CUC, to import, choose the model.

  • To connect to the internal interface and access the LAN

    Hello

    I have the following problem, I have a Cisco 2811 router with a serial number and an ethernet interface. On the serial port, I have an address got from the ISP, but not a real IP address. It's a 30 ip only for communication ECCAS my site and the ISP and the ethernet I one of the addresses of my range. I have have need allow VPN connections on this address (ethernet one) and access hosts on the internal LAN.

    I am able to connect to the VPN, but I can't reach any host inside the LAN

    Is it possible to display relevant configuration

    crypto-address ethernet card must be present in the router.

    What also makes sh crypto isakmp her and sh crypto ipsec his give?

  • How to recover my apps which are lacking in the start screen and access?

    Original title: Apps

    IN the start screen several pre-installed applications are missing, for example maps, news, weather, etc. When I want to re install through the store, I get the message that they are already installed. How do retrieve my apps and access?

    Thanks for your help

    Buri Ram, Hi

    Thanks for posting your question in the Microsoft Community.

    I understand you want to know how to get Windows apps like Maps, Weather, News etc on Start menu are missing. Correct me if I'm wrong.

    I imagine the inconvenience that you are experiencing. I will try to help you in the matter of fixing.

    To help you suggest several steps to solve the problem, I would appreciate if you could answer the following questions:

    1. did you uninstall applications?

    2. don't remove you applications on the start menu?

    Follow the steps below to get the missing apps in the start screen and check the issue:

    a. press the Symbol of Windows and type one of the missing apps Ex name: cards.

    b. you might see maps in the top left corner, right-click on it and click PIN to start from the bottom task bar.

    c. check the missing applications in the home screen to see the Maps application; Get all missing apps in the same way.

    Your response is very important for us to ensure a proper resolution. Please get back to us with the information above to help you accordingly.

    In the future if you fall on any question relating to Windows, please do not hesitate to post your request here on Microsoft Community, we will be more than happy to help you.

  • On the obtaining of a number in the United Kingdom and access it from outsite UK

    Hi Skype,

    I work for a company based in the United Kingdom and my major customer is in a UK/Europe. Now my question is, I would like to know, how do I register a normal number of UK and tie it to my Skype account and use it as my official number. I would also recharge it and make outgoing calls, how is it possible. Finally since I want to make my official UK number and if I'm not around or disconnected, is there a voicemail that I can put in place, which can record messages while I'm away?

    I look forward to your responses as soon as possible. Thank you.

    Hello

    Yes, and here is a link to the FAQ article explains the steps to the implementation of caller ID:

    https://support.Skype.com/en/FAQ/FA1248/what-is-caller-identification-and-how-do-i-set-it-up

    Kind regards

    Elaine

    __________________________________________________________________________________________________
    Your question has been answered? Please click on the link to accept as a Solutionfor everyone can quickly find what works! As a post or want to say, 'Thank You ' -? Click on the button of congratulations!
    Reliable information: Brian Krebs: 3 basic rules for online safety

  • No methodActions in a module of the App application and access of backing bean

    USNG ADF 12 c on Windows 7.

    I've inherited an application that does not have methodActions defined in the pageDefs and uses a custom method to get the instance of the app module (return (appModule) getDCBindingContainer () .getDataControl () .getDataProvider ()) by supporting beans.

    The latest I can remember seeing in a document is a bad practice.

    All the places where the app module instance is acquired should be changed to methodActions? Or am I worried for nothing here?

    Thanks for your opinion!

    Kind regards

    Dave

    ^ Well, for me, this is a no go to use the code you provided. You should not use the application module in the bean because it tends to violate the MVC pattern. You may have to implement a method of the application module, add to the interface and use via the pageDef as an action method customer. This seems to be more work but allows to encapsulate the business logic in the view layer. The advantage of using methods defined in the pagedef, is that they are handling errors the same way. There is no need to handle the error yourself. The framework know dangels done in methods (if you do not use pl/sql to change the db directly and does not synchronize the frame later).

    request module is the interface that everyone should use.

    Timo

  • GR 11, 1 IOM material: nested roles and access policies

    Hello

    We have an access policy that fires to assign users to Active Directory. Access policy has the following composition:

    Rule: The user Type is EMP AND Orgname == Company

    Role: Roles of the employees of the company is granted automatically to all users which are evaluated to TRUE for the rule. It works very well.

    Access policy: resource access policy: Active Directory, membership rule: "employees of the company.

    The strategy above works fine. It fires when an employee is hired, and it fires again when an employee leaves. The grant and revoke the resource as expected. Now, we also give the resource for all roles of children "employees of the company. I have create a role called 'cooperative society student', and I attribute it's parents to be "collaborators."


    User1: Role: employee of company
    User2: Role: student cooperative society

    If I look at role: an employee of the company, click the Members tab, I see two members: User1, direct. User2, indirect.

    However, the access policy is not shooting to add User2 to Active Directory. They are a member of the role indirectly, but do not receive the resources assigned to the role.

    Should it? I can do to ensure that members of the role junior/child benefit resources via the access on the role of parent policy?

    Thank you.

    It is the expected behavior. You can update the access policy and add your child group in the list of roles that are allowed to access this policy.

    Kind regards
    GP

  • Display of the Smartphone blackBerry and access Web site link

    Hi all

    I want to show a Web site highlighted link in my application and want to access it.

    What I would do.
    Right now I have the poster as a normal link.

    Please, help me to solve this problem.

    Thanx
    Thakur

    I m solve this thread I found the solution. Sorry for the delay...

  • How to limit navigation directly via the URL when the user tries to type the page number and access this page in ORACLE APEX 4.2

    Hi all

    I developed an application where I have 6 pages and 5 tabs and based on the user role I posted the tabs for the user to access these pages.

    But when the user, who doesn't have access to the particular page (say, page 2), but still the user can navigate to it directly by typing the page number in the URL.

    I want to avoid such scenarios.

    eg: http://Apex.Oracle.com/f?p=110:2 , when the user type this in the address bar, it navigates the user to this page even if this particular user does not have access to this page.

    How to prevent the user to navigate through the URL, if the user tries to navigate directly through URLS rather than tabs, I have to give the error message.

    Version: ORACLE APEX 4.2

    Thank you

    Good reading this recent post

    Re: Authentication at the Page level

    All links to a page and the page itself must be secure.

    You can also consider the protection of session state to prevent tampering of the URL.

Maybe you are looking for