Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Active Directory Security Groups and Roles

268 views
Skip to first unread message

Aidan

unread,
Jul 11, 2007, 10:02:03 AM7/11/07
to
I have setup a security group in AD called NavisionSales and made the sales
person a member of this group. I have then gone into NAV and windows logins
and added both sales person and the security group. I then added all the
relevant roles to the security group within NAV. When I log on as the sales
person I get the following message "You do not have permission to run the
'MBS' MenuSuite " has anyone got any ideas what might be causing this ?

Jacques

unread,
Jul 11, 2007, 5:24:02 PM7/11/07
to
My guess would be SQL Permissions on the AD user/group.
Others, Any toughts ?

--
Jacques

Aidan

unread,
Jul 12, 2007, 4:18:00 AM7/12/07
to
So do you know what SQL rights the group should have ?

Diptish Naskar

unread,
Jul 12, 2007, 5:26:04 AM7/12/07
to
Hi,

Firstly it has not nothing to do with SQL, what you need to do is this.

MBS menu suite is the top level menu suite, so until you grant access to
this, the user will not be able to view any menu suite that are
available/customized.

So Go to the user, select roles and then use a relevant role and then drill
down to permission. In permission specify the menu suite and then synchronize
if you are using SQL db.

Diptish Naskar
---------------- http://msnavarena.blogspot.com/

Aidan

unread,
Jul 12, 2007, 7:04:01 AM7/12/07
to
As far as I was aware there is no need to set any roles on the user as long
as the group the user is a member of has the correct roles. If I give the
user the all role I can login no problem but if the all role is on the group
and not the user I can't login. It seems the system is not seeing the roles
assigned to the group but only looks at the roles on the user.

Kine

unread,
Jul 19, 2007, 7:20:01 AM7/19/07
to
I have no such a problem. I have all roles defined on AD Group and users have
no specific role. I am using NAV 4.00SP3 in Normal security mode.

There is just one limitation - user must be directly member of the AD Group,
else it will be not recognized as member in NAV (e.g. when user is member of
group1 and group1 is member of group2 and group2 is defined in NAV with
roles...)

Kamil S.

Aidan

unread,
Jul 19, 2007, 7:26:03 AM7/19/07
to
Thnaks for the reply. This is the setup I have Sales group has the roles and
the user is a direct member of sales group. The only difference isthat I am
using Nav 5. Has anyone done this in Nav 5 without any issues.

Kine

unread,
Jul 19, 2007, 7:46:02 AM7/19/07
to
I tested it now on NAV 5.0 in single user mode (not SQL), and it is working.
What I did:

1) Added windows user into NAV
2) Added AD group, which the user is member of
3) Added role "ALL" and another role (some base role for G/L module) for the
AD group

I was able to open the DB without problems.

Aidan

unread,
Jul 19, 2007, 7:50:02 AM7/19/07
to
OK Thanks. We are using SQL so maybe theres an issue there.

Kine

unread,
Jul 19, 2007, 8:28:06 AM7/19/07
to
I tested it on NAV 5.0 W1 SQL too (MS SQL 2005) without problem. And because
it is connected to MenuSuite, it is nothing with MS SQL... problem must be
somewhere else.

Kamil

Aidan

unread,
Jul 19, 2007, 8:30:03 AM7/19/07
to
Thanks again fro your time. I dont suppose you have any idea where the
problem might be ?

Kine

unread,
Jul 19, 2007, 8:36:02 AM7/19/07
to
I have no clue...

but it can be some dummy mistake. Try it again and check each step 2 times.
And check, that you are not using beta version of the client. I am using
build 5.0.24199.

0 new messages