Setting an account for Lawson Security Admin access

 5 Replies
 0 Subscribed to this topic
 15 Subscribed to this forum
Sort:
Author
Messages
Ronnie
Veteran Member Send Private Message
Posts: 152
Veteran Member

OK,

 

So we have 1 account we usually use for just all open access for all lawson. So we usually use this account to create accounts in lawson security.

 

Things are changing. We now have a few employees who may need to create user accounts in Lawson Security Admin. With this said....I am not sure what all I need to set role wise etc for a user to just be able to use Lawson Security Admin application.

Ronnie
Veteran Member Send Private Message
Posts: 152
Veteran Member
Anyone with any thoughts at all???
Deleted User
New Member Send Private Message
Posts: 0
New Member
We are using a SuperAdminRole, and that role has "all" access in Profiles RM and ADM. We don't have the situation that you are describing, but I would think you need security classes in both RM and ADM that provide only what is needed rather than "all". What exactly you'd need in RM and ADM could be trial-and-error. Then you'd assign those classes to an SecurityAdminLimitedRole.
Ronnie
Veteran Member Send Private Message
Posts: 152
Veteran Member
Gotya. I am not really familiar with the RM and ADM profiles, I have never touched security or any setup outside of our PROD profile.
Deleted User
New Member Send Private Message
Posts: 0
New Member
Testing the new role will be tricky - I hope you have a second userid to test it with. You can't remove the "all access" from your existing security account to test the new role, because then you might not be able to get back in to security ;-)
Brian Allen
Veteran Member Send Private Message
Posts: 104
Veteran Member
I have setup limited user access before at another organization using the ADM and RM roles. You can setup limited access to the LS client and RM section within the ADM and RM profiles. We also setup sub-administrator groups, for instance Finance (class FNADMAccess) only had access to assigning roles starting with FN (however requires some maintance for the sub-admin classes when adding new roles). It was reasonably straight forward. I started by adding what seemed to be required for limited access within the ADM role (e.g. Helpdesk) and then started testing.