ACS - Security groups and Organizational Units | Adobe Higher Education
Skip to main content
eveline8
Level 4
March 26, 2019
Répondu

ACS - Security groups and Organizational Units

Hi all,

I would like to know if anyone has ever implement a similar procedure to see profiles of each countries.

In the instance I use now there are only Organizational Units.

I explain the case:

Our customer has different database for different countries and he would like to create users that can see only the profiles associated to a specific country.

user A can see only profiles with country US

user B can see only profiles with country IT

and so on.

I have activated in Custom Resources the option "Add access authorization management fields", I have set the organizational unit, I create the security group in Admin and in Adobe Campaign with the same ID.

I have insert user A in US security group and so on.

I have assigned the profiles to the different organizational units but the user in security group US see all the profiles for all countries, not only US profiles.

How is it possibible? Are there other setting to implement?

Thanks,

E.

Ce sujet a été fermé aux réponses.
Meilleure réponse par bisswang

Hi Eveline,

yes, that is exactly the issue.

If the user is in any security group with all assigned, he will have access to anything in the whole system.

That can't be limited by another security group.

Following documentation states which organizational unit will be taken if multiple are assigned:

Adobe Campaign Help | Managing groups and users

16 commentaires

Level 3
April 1, 2019

i have assigned the product profile to the user in the console but i dont see a way to add a user to the security group inside campaign. I thought all of this was handled in the console?

Here is the Security group and linked to relevant org unit

My test user has the Product Profile assigned to them.

Adobe Employee
April 1, 2019

Hi,

There are 2 issues with your config:

- user is member of "standard users" group which will give access to "all" organizational unit. Remove the user from there

- for your other profile, the name is wrong thus it won't map to ACS security group and justbignore it. You need same prefix as "standard users", i.e. the GEOMETRIXXCAMPAIGN is wrong.

Afterwards log in with the user and check with an admin that the user only belongs to Clothes group.

Level 3
April 1, 2019

Thanks so much for all your help. I was confused on why the instructions said to have both items on the user myself. 

I am confused on the naming of the profile part. Should it be something like "Campaign Standard - cdc-mkt-stage1 - Geometrixx Clothes"? or does it need standard users in the name? "Campaign Standard - cdc-mkt-stage1 - Standard Users - Geometrixx Clothes" which gets really long and truncates on security groups ID.

Level 3
April 1, 2019

And then the Security group ID would just be "Geometrixx Clothes"?

Adobe Employee
April 1, 2019

Product profile:   Campaign Standard - cdc-mkt-stage1 - Geometrixx Clothes

Security Group ID:   Geometrixx Clothes

Level 3
April 2, 2019

thanks so much for all your help! i was able to figure it out yesterday and get everything working with all of your advice.