COGNOiSe.com - The IBM Cognos Community

IBM Cognos 10 Platform => Cognos 10 BI => Security => Topic started by: guileinsighter on 19 Dec 2014 08:06:33 AM

Title: Multiple Namespaces with Members Access Restriction
Post by: guileinsighter on 19 Dec 2014 08:06:33 AM
Hi folks,

Wondering if any of you guys have any guidance on following scenario in Cognos 10.2.1 (1 GTW; 1 CM; 2 dispatchers):
We have SSO setup for a namespace that maps to AD hosted at DC01.net and restricting access to members of the built-in namespace, that is, the groups within DC01.net that are associated to consumers, authors, etc. within Cognos namespace.
It happens that users from DC02.net need to access Cognos from now on so we've created a new namespace that maps to it and AD administrators added them to the required groups in DC01.net. Still, although they're able to authenticate from DC02.net, the access is denied as if they were not part of the groups in DC01.net.
It allows access if we unset the restriction to members of the built-in namespace but that bypasses defined security policies.
In addition, upon browsing groups in DC01.net namespace from Cognos Connection, we're not able to see the assigned users from DC02.net
Any clues?

Thanks