LBI report users

 10 Replies
 1 Subscribed to this topic
 22 Subscribed to this forum
Sort:
Author
Messages
Jan
Veteran Member
Posts: 55
Veteran Member
    I haven't found this issue in this forum so I'll post it now. I apologize if this was addressed earlier and I missed it.

    As employees terminate or transfer, I need to determine if I need to adjust LBI report distributions. Which LBI tables do I need to access to see which reports (or smartnotes) an employee has been a recipient for? I have quite a few reports built up, so doing this by hand is getting to be unworkable.

    thanks in advance for any help you can throw my way
    JeanneS
    Veteran Member
    Posts: 49
    Veteran Member
      I will be out of the office on Friday, November 11th. Please direct your requests for support from Financial Systems to the FINSYS mailbox at FINSYS@geisinger.edu.



      >>> 11/11/11 10:37 >>>

      Lawson Business Intelligence/Reporting/Crystal Forum Notification
      ----------------------------------------------------------------
      Posted by:Jan
      Date: 11/11/2011 09:37 AM
      Subject: LBI report users
      Message:
      ----------------------------------------------------------------
      I haven't found this issue in this forum so I'll post it now. I apologize if this was addressed earlier and I missed it.

      As employees terminate or transfer, I need to determine if I need to adjust LBI report distributions. Which LBI tables do I need to access to see which reports (or smartnotes) an employee has been a recipient for? I have quite a few reports built up, so doing this by hand is getting to be unworkable.

      thanks in advance for any help you can throw my way
      ----------------------------------------------------------------
      To view the complete thread and reply via your browser, please visit:
      https://www.lawsonguru.co...bi/lbi-report-users/

      Thank you,
      LawsonGuru.com

      You were sent this email because you opted to receive email notifications when someone posted and/or responded to a message on this forum. To unsubscribe to this thread please visit your user profile page and change your subscription options.


      IMPORTANT WARNING: The information in this message (and the documents attached to it, if any) is confidential and may be legally privileged. It is intended solely for the addressee. Access to this message by anyone else is unauthorized. If you are not the intended recipient, any disclosure, copying, distribution or any action taken, or omitted to be taken, in reliance on it is prohibited and may be unlawful. If you have received this message in error, please delete all electronic copies of this message (and the documents attached to it, if any), destroy any hard copies you may have created and notify me immediately by replying to this email. Thank you.

      Geisinger Health System utilizes an encryption process to safeguard Protected Health Information and other confidential data contained in external e-mail messages. If email is encrypted, the recipient will receive an e-mail instructing them to sign on to the Geisinger Health System Secure E-mail Message Center to retrieve the encrypted e-mail.
      Ruma Malhotra
      Veteran Member
      Posts: 412
      Veteran Member
        If you are using Lawson security and single sign on with LBI, as the employee terminates or leaves the organization, whenever the id is removed from the AD account, LBI will synchronize this account and the account automatically gets removed from LBI as well. You may need to set up syncronize in LBI. But you can never have an accunt removed in AD and exist in LBI. LBI will automatically remove that id as soon as it syncronizes.

        You can check this by going to manage roles on the tools directory in LBI, putting in the id and clicking on roles.

        If you are looking to replaces users who had access to reports, the best way is to query the reporting database and look for those user-ids and manually add new user-ids that will be replacing the old ones to those report security groups or report access.

        Greg Dey
        Advanced Member
        Posts: 23
        Advanced Member
          I created a report in Crystal to provide this information for me. The tables I'm using for the reports are ers_reports and ers_reportattributes. The tables I use for report access include ers_reportaccess, ers_customgroups, ers_customgroupmembers. There may be more depending on your setup (security groups). I do not however have anything for Smart Notes, not yet anyway.
          Greg Moeller
          Veteran Member
          Posts: 1498
          Veteran Member
            For ReportingServices, I'd start with ERS_REPORTACCESS -- perhaps joined to ERS_REPORTS ? But then you are going to have to know to which group a user belongs if you are assigning writes to reports by group, so you'll have to access the LDAP to determine that. (I've got a script that produces a web page from the list.. If you'd like, I'll share.)
            For SmartNotes: I don't really have a good idea for you, but I'd look at ENPUSERMAP and maybe QRTZ_TRIGGERS ??

            Greg Moeller
            Veteran Member
            Posts: 1498
            Veteran Member
              Ruma: The id only gets deleted from LBI if you have the "Remove Expired Users and Roles" box checked.
              We haven't had that box checked in a while, and we still have LBI id's in that are no longer in AD.
              Greg Moeller
              Veteran Member
              Posts: 1498
              Veteran Member
                Here's the script that I was talking about. It's not real pretty, but it produces some good output that our Business analysts access daily. The final file doesn't look too bad, but I wrote the script in my earlier days of scripting, and haven't really gone back to make it run more efficiently.

                Use if you'd like.

                -Greg
                Attachments
                Ruma Malhotra
                Veteran Member
                Posts: 412
                Veteran Member
                  You are right Greg. It gets removed only if you have the checkbox checked. However best practices is to have this checked becuase there is a limit on the no: of users and roles in LBI and when you add new users from AD into LBI by synchronizing LBI will check this limit. If new users + roles exceeds this limits these new user ids will not get setup in LBI from AD.
                  Greg Moeller
                  Veteran Member
                  Posts: 1498
                  Veteran Member
                    I wasn't aware of any limits. Could you tell me the number of each? I may have to check our box again.
                    Massimo Emilione
                    Advanced Member
                    Posts: 29
                    Advanced Member
                      I agree with ruma, you should have it running to delete users. But test in dev. On 9032 there was a bug where it would not work correctly. We have not any problems in 9041 or 9042, and it is the best thing to use to maintain your user base. And I always suggest using groups vs indivduals to help with maintenance, until Lawson creates Ruma & my dream of better reporting of security within LBI
                      Greg Moeller
                      Veteran Member
                      Posts: 1498
                      Veteran Member
                        You can add myself and a bunch of workers here at Genesis to your dream of better reporting security.