Jump to content

Dashboard report permissions in 6.5


Recommended Posts

There are accounts on our ERA server that have permissions only to devices in specific static groups.  After the 6.5 upgrade the dashboard reports are no longer available to them.  I cannot find the permissions required to enable these reports to be seen again.  How do I make these reports available again?

era dashboard.PNG

Link to comment
Share on other sites

  • ESET Staff

It seems user has no access to report templates that are shown on dashboard. In ERAv6, two security-related configuration must be set to have access to report templates:

  1. user must have functionality access to "Reports and Dashboard" with USE rights (Admin -> Access Rights)
  2. user must have access to static group that objects are assigned to. By default, report templates are assigned to group All (see Access Group information in report templates view). In order to share them with other users, you will have to move report templates to different access group - accessible by all users. To move report templates, open context menu of "report template category" and use Access group -> Move. It seems moving only specific report template is not possible (most probably bug). You may find more details in documentation.
       

 

Link to comment
Share on other sites

  • 2 weeks later...
On 20. 3. 2017 at 8:31 PM, MartinK said:

It seems user has no access to report templates that are shown on dashboard. In ERAv6, two security-related configuration must be set to have access to report templates:

  1. user must have functionality access to "Reports and Dashboard" with USE rights (Admin -> Access Rights)
  2. user must have access to static group that objects are assigned to. By default, report templates are assigned to group All (see Access Group information in report templates view). In order to share them with other users, you will have to move report templates to different access group - accessible by all users. To move report templates, open context menu of "report template category" and use Access group -> Move. It seems moving only specific report template is not possible (most probably bug). You may find more details in documentation.
       

 

 In ERA V6.4 I was able to create one "genereal" report with Access Group "All". Users with restricted access to subgroups below "All" could use this report. When using this report, only data relevant to current user were visible. For example only computers from a subgroup where user had access.

With ERA V6.5 if I need set access to different groups for different users I have to create a separate report for each of all these groups? This looks like step back from ver. 6.4.

Update: I have done following test

1, Created report group: All\Reports , without any computers inside it.

2, Moved report to Access group: All\Reports

3, Added access rights for user to group  All\Reports . User additionaly had access to his group All\Domain\Location_1

User was able to display this report with data only from Location_1 group.

This way its working, but I am wondering what is the reason for this "functionality".

Edited by Miami
Link to comment
Share on other sites

  • ESET Staff
7 hours ago, Miami said:

 In ERA V6.4 I was able to create one "genereal" report with Access Group "All". Users with restricted access to subgroups below "All" could use this report. When using this report, only data relevant to current user were visible. For example only computers from a subgroup where user had access.

This has not changed. User will be able to see only computer from groups that user has access.

7 hours ago, Miami said:

With ERA V6.5 if I need set access to different groups for different users I have to create a separate report for each of all these groups? This looks like step back from ver. 6.4.

No. What has changed in ERA 6.5 is that access to all "management" objects is restricted to static groups. This means that access to report templates, dashboards, dynamic groups, task, configuration policies, etc. may be also restricted. Each of this objects is tied to some static group (after upgrade, they are all tied to group All), which is used to filter its visibility for users. Sharing objects requires them to be "moved" or re-assigned to static group that is accessible by users that should be able to see this object.

Link to comment
Share on other sites

14 hours ago, MartinK said:

This has not changed. User will be able to see only computer from groups that user has access.

No. What has changed in ERA 6.5 is that access to all "management" objects is restricted to static groups. This means that access to report templates, dashboards, dynamic groups, task, configuration policies, etc. may be also restricted. Each of this objects is tied to some static group (after upgrade, they are all tied to group All), which is used to filter its visibility for users. Sharing objects requires them to be "moved" or re-assigned to static group that is accessible by users that should be able to see this object.

OK. I just wanted to point out that there is difference between 6.4 and 6.5.

 

 

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...