AEM and Admin Console Synchronisation | Community
Skip to main content
July 13, 2020
Solved

AEM and Admin Console Synchronisation

  • July 13, 2020
  • 2 replies
  • 2141 views

If I add an user in the admin console and then provide permission to that user to access the AEM instance, that gets auto synced to AEM. But, if I update permissions for the same user in the AEM instance, will that reflect automatically in the Admin Console?

This post is no longer active and is closed to new replies. Need help? Start a new post to ask your question.
Best answer by joerghoh

What do you mean when you write "permission"? The Adobe AdminConsole does not now about any permissions, but just knows users and groups and their relations (next to some other things, which are not significant for this question).

The only direction in which there is a sync is from AdminConsole to AEM. That means that any user-to-group relationship visible in the AdminConsole is synced into AEM, but not the other way around.

 

When referring to "permission" in the context of AEM, we normally mean the permission to access nodes/resources in the AEM content repository. This is entirely handled within AEM itself, because the AdminConsole does not understand this concept at all. Typically these permissions are mapped to AEM groups, and these groups can be handled within the AdminConsole as opaque entities.

 

Jörg

2 replies

vanegi
Adobe Employee
Adobe Employee
July 13, 2020

In admin console https://adminconsole.adobe.com, permissions are given specific to the products (AEM, Adobe Analytics etc ) assigned to the user. It could be system administrator, product administrator, profile administrator etc which are different from permissions that we have in AEM. So, depending upon the role of user (system administrator, product administrator, profile administrator), he can access AEM but permissions that are applied in http://<host:port/useradmin in AEM are different.

joerghoh
Adobe Employee
joerghohAdobe EmployeeAccepted solution
Adobe Employee
July 13, 2020

What do you mean when you write "permission"? The Adobe AdminConsole does not now about any permissions, but just knows users and groups and their relations (next to some other things, which are not significant for this question).

The only direction in which there is a sync is from AdminConsole to AEM. That means that any user-to-group relationship visible in the AdminConsole is synced into AEM, but not the other way around.

 

When referring to "permission" in the context of AEM, we normally mean the permission to access nodes/resources in the AEM content repository. This is entirely handled within AEM itself, because the AdminConsole does not understand this concept at all. Typically these permissions are mapped to AEM groups, and these groups can be handled within the AdminConsole as opaque entities.

 

Jörg

joerghoh
Adobe Employee
Adobe Employee
July 20, 2020
It doesn't matter. Because under the hoods there is a group-id, which is different from the name. And you cannot change that ID of a group without removing and recreating it. That means if you can that name to TestAB, it will still sync, because its groupid is still "TestA" after all.