Page 1 of 1

Configuring AD/CAM/Cognos group with ADMIN privileges

Posted: Tue Sep 19, 2017 2:55 pm
by Kingsley
Hi fellow Gurus,

I have an AD\TM1 Admin group I want to maintain outside of TM1. How should I go abouts to automatically granting these users TM1 Admin access?
I've tried setting a security cube rule to grant ADMIN to AD\TM1 Admin users but noticed it doesn't take effect when they login for the first time or until SecurityRefresh is triggered. Which lead me to believe that shouldn't be the best approach.

Your input is much appreciated.

Re: Configuring AD/CAM/Cognos group with ADMIN privileges

Posted: Wed Sep 20, 2017 8:48 am
by Steve Vincent
Correct; TM1 doesn't seem to behave when you try to use rules to govern security. We got around it by using TIs instead. Yes, it isn't instant but you can provide access to the external group to run the TI, then the user just has to run the TI on their first log on.

Word of caution tho; we've found this will crash the TM1 client. The task completes fine and logging in again will have admin access, but it seems to dislike the refresh of the explorer afterwards and crashes as a result. Not sure what version you are using, but we've seen that on 10.2.2 FP1 and FP7