User rights in Navision

jcl
Member Posts: 2
I'm trying to understand the user rights definition in Navision. I've read the French "Installation and Administration" manuel but I find the explanation short and everything but clear.
Is there anyone who as a document on the user rights administration (either navision official manual, navision internal manual, or a self-made document) he could give me the reference of or a copy of?
I'm especially interested in understanding how permissions work
- what is exactly an 'indirect permission'?? Any definition a little bit clearer than the one I found in my Navision Manual('a permission you have only if nother permission is directly given to you') will help.
- what are the rules that apply when a user belong to different groups giving him different permissions on the same object. What is the permission hierarchy. Is it possible to forbid the access to an object to a user who belong to a group that has this permissions (something similar to the 'No access' in NT)??
- etc.
Thanks for your answers
Jean-Christophe
Is there anyone who as a document on the user rights administration (either navision official manual, navision internal manual, or a self-made document) he could give me the reference of or a copy of?
I'm especially interested in understanding how permissions work
- what is exactly an 'indirect permission'?? Any definition a little bit clearer than the one I found in my Navision Manual('a permission you have only if nother permission is directly given to you') will help.
- what are the rules that apply when a user belong to different groups giving him different permissions on the same object. What is the permission hierarchy. Is it possible to forbid the access to an object to a user who belong to a group that has this permissions (something similar to the 'No access' in NT)??
- etc.
Thanks for your answers
Jean-Christophe
0
Comments
-
Indirect permission means that the user cannot directly access the data, but they can use code to access the table.
The best example of this is the posting codeunits. A user is allowed to READ the data, but is given only indirect INSERT and MODIFY. The posting codeunit has permission properties that allow the INSERT and MODIFY.
Permissions are GRANT only. If any group grants WRITE, the user can write. There is no way to deny a particular access to the user with Navision permissions.
-jp-jp0 -
The highest permission for an object that one has is the one that applies. If one has read permission for an object from one group and modify permission on another, the modify permission applies. There is no way to say deny a permission to anybody once it is given as in NT.
However, one can copy a group of permissions into a new one, take away a particular permission and assign it to the user in question.0
Categories
- All Categories
- 73 General
- 73 Announcements
- 66.6K Microsoft Dynamics NAV
- 18.7K NAV Three Tier
- 38.4K NAV/Navision Classic Client
- 3.6K Navision Attain
- 2.4K Navision Financials
- 116 Navision DOS
- 851 Navision e-Commerce
- 1K NAV Tips & Tricks
- 772 NAV Dutch speaking only
- 617 NAV Courses, Exams & Certification
- 2K Microsoft Dynamics-Other
- 1.5K Dynamics AX
- 320 Dynamics CRM
- 111 Dynamics GP
- 10 Dynamics SL
- 1.5K Other
- 990 SQL General
- 383 SQL Performance
- 34 SQL Tips & Tricks
- 35 Design Patterns (General & Best Practices)
- 1 Architectural Patterns
- 10 Design Patterns
- 5 Implementation Patterns
- 53 3rd Party Products, Services & Events
- 1.6K General
- 1.1K General Chat
- 1.6K Website
- 83 Testing
- 1.2K Download section
- 23 How Tos section
- 252 Feedback
- 12 NAV TechDays 2013 Sessions
- 13 NAV TechDays 2012 Sessions