Hi,
Could I get any opinions on the following which is something we are thinking about - specifically what are Pros and Cons - Thanks!
Currently this is our basic security setup using WinAD Authentication - its a simplified version of the actual but gets my point across
In Windows AD
Group: BOWinADProd – in CMC this is Authentication Group
In Business Objects
Group: Report Analyst (associated with Access Level of “Analyst”)
SubGroups: Report Analyst Accounting, Report Analyst Claims
Group: Report Viewer (associated with Access “Viewer”)
SubGroups Report Viewer Accounting, Report Viewer Claims
Process: JohnDoe and JaneDoe are new users
- JohnDoe and JaneDoe are assigned in WinAD to the WinAD Group BOWinADProd
- JohnDoe is assigned in BO CMC to BO Group Report Analyst Accounting, JaneDoe is assigned to BO Group Report Viewer Claims
-------------------------------------------------------------
Proposal – considering the following because the user setup is only needed in WinAD as opposed to the above WinAD and BO CMC
Windows AD
(In CMC these are Authentication Groups)
- BOWinADProdReportAnalystAccting
- BOWinADProdReportAnalystClaims
- BOWinADProdReportViewerAccting
- BOWinADProdReportViewerClaims
In Business Objects
Group: Report Analyst (associated with Access Level of “Analyst”)
SubGroups: BOWinADProdReportAnalystAccting, BOWinADProdReportAnalystClaims
Group: Report Viewer (associated with Access Level of “Viewer”)
SubGroups: BOWinADProdReportViewerAccting, BOWinADProdReportViewerClaims
Process: JohnDoe and JaneDoe are new users
- JohnDoe is assigned in WinAD to the WinAD Group BOWinADProdReportAnalystAccting and JaneDoe is assigned in WinAD to the
WinAD Group BOWinADProdReportViewerClaims - No additional work in BO CMC