Expand my Community achievements bar.

We are excited to introduce our latest innovation to enhance the Adobe Campaign user experience — the Adobe Campaign v8 Web User Interface!
SOLVED

ACS - Security groups and Organizational Units

Avatar

Level 4

Hi all,

I would like to know if anyone has ever implement a similar procedure to see profiles of each countries.

In the instance I use now there are only Organizational Units.

I explain the case:

Our customer has different database for different countries and he would like to create users that can see only the profiles associated to a specific country.

user A can see only profiles with country US

user B can see only profiles with country IT

and so on.

I have activated in Custom Resources the option "Add access authorization management fields", I have set the organizational unit, I create the security group in Admin and in Adobe Campaign with the same ID.

I have insert user A in US security group and so on.

I have assigned the profiles to the different organizational units but the user in security group US see all the profiles for all countries, not only US profiles.

How is it possibible? Are there other setting to implement?

Thanks,

E.

1 Accepted Solution

Avatar

Correct answer by
Employee Advisor

Hi Eveline,

yes, that is exactly the issue.

If the user is in any security group with all assigned, he will have access to anything in the whole system.

That can't be limited by another security group.

Following documentation states which organizational unit will be taken if multiple are assigned:

Adobe Campaign Help | Managing groups and users

View solution in original post

16 Replies

Avatar

Employee Advisor

Hi Eveline,

yes, I got this running.

Just quickly listing steps required for you to check:

  1. Create org unit
  2. Extend profile resource
  3. Assign org unit to profile
  4. Create new security group
  5. Assign organizational unit to security group in "User Access" section

From your description, I would guess that 5. is missing as this is commonly forgotten / not too well documented

Only once this is assigned, the organizational unit will be checked.

Avatar

Level 4

Hi Ramon,

sorry I forgot to write the point 5. I've already assigned the org unit to security group.

I have a doubt: the user that have to see only US profiles is insert in various security group as for example Administrators (all units). Can this setting cancel the permissions of the other US security group? Can this be the reason for the failure?

Thanks,

E.

Avatar

Correct answer by
Employee Advisor

Hi Eveline,

yes, that is exactly the issue.

If the user is in any security group with all assigned, he will have access to anything in the whole system.

That can't be limited by another security group.

Following documentation states which organizational unit will be taken if multiple are assigned:

Adobe Campaign Help | Managing groups and users

Avatar

Level 4

Thanks, I tried and it works.

E.

Avatar

Level 3

I am having the same problem but I have followed all the steps. The one step above that is confusing to me is "Extend profile resource". Is this the Product Profile in the admin console? If so, I have that created as well. I followed these steps - Adobe Campaign Help | Organizational units  - but the test user still sees everything. Here are screenshots. What am I missing?

admin-consol.jpgorg-unit.jpgsecurity-group.jpgsecurity-group-2.jpg

Avatar

Employee Advisor

No, this is not product profile.

If you want to limit people of seeing all recipient profiles, you need to create a resource extnsion of ACSprofile data type. I.e. Administration - Development- Custom Resources

Avatar

Level 1

IN the instructions for adding users through the console, it says to create a Product profile if limiting by groups. Why do I need to create a custom resource? it is not mentioned anywhere on the Security group creation page??

Avatar

Employee Advisor

At the end it depends on what objects you want to limit.

Items like Campaigns or workflows can be limited without creating custom resources.

If you want to limit user profiles though then you need to create a custom resource as by default it does not have the fields for access authorization.

Avatar

Level 3

I just want to first limit what the user sees when they go into Programs & Campaigns. I thought the instructions would be enough but something must be missing.

Avatar

Employee Advisor

Ok, if that's the case the indeed no custom resource needed.

Please check:

* User Access is defined on Security Group and links to the relevant org Unit

* use is part of security group and not member of other security groups with different user access* Acces authorization is set on the program and all subelements

If that is met, visibility should be limited accordingly

Avatar

Level 3

i have assigned the product profile to the user in the console but i dont see a way to add a user to the security group inside campaign. I thought all of this was handled in the console?

Here is the Security group and linked to relevant org unit

1723131_pastedImage_2.png

My test user has the Product Profile assigned to them.

1723132_pastedImage_3.png

Avatar

Employee Advisor

Hi,

There are 2 issues with your config:

- user is member of "standard users" group which will give access to "all" organizational unit. Remove the user from there

- for your other profile, the name is wrong thus it won't map to ACS security group and justbignore it. You need same prefix as "standard users", i.e. the GEOMETRIXXCAMPAIGN is wrong.

Afterwards log in with the user and check with an admin that the user only belongs to Clothes group.

Avatar

Level 3

Thanks so much for all your help. I was confused on why the instructions said to have both items on the user myself. 

I am confused on the naming of the profile part. Should it be something like "Campaign Standard - cdc-mkt-stage1 - Geometrixx Clothes"? or does it need standard users in the name? "Campaign Standard - cdc-mkt-stage1 - Standard Users - Geometrixx Clothes" which gets really long and truncates on security groups ID.

Avatar

Level 3

And then the Security group ID would just be "Geometrixx Clothes"?

Avatar

Employee Advisor

Product profile:   Campaign Standard - cdc-mkt-stage1 - Geometrixx Clothes

Security Group ID:   Geometrixx Clothes

Avatar

Level 3

thanks so much for all your help! i was able to figure it out yesterday and get everything working with all of your advice.