4.0 Permission problem (multiple companies)

fvet
fvet Member Posts: 2
A customer wants the following setup of permissions:

User X may have full access to company A,
but only restricted access to some modules in company B.

So I've set up follow permissions:

User X has been assigned the SUPER role for company A.
For company B, the user has only been assigned e.g. the ALL role.

Problem is that when the user logs in into company B, he gets full access to everything, allthough only the ALL role had been assigned for company B. It seems like the SUPER role assigned for company A, also gives permissions in company B. Seems like assigning a SUPER role in combination with multiple companies gives a problem.

Any ideas?

Comments

  • ritz
    ritz Member Posts: 25
    fvet,

    i had the same problem when we were supporting the offshore client the client for some reason assigned me super role for only one of his 2 companies and i was not even able to open the database.

    I think you can not assign a super user to only one company rather super user has all the permission for the data base.

    the logic behind this is, if you are super user to one company u have rights to change in the architecture for that company but since you are not the super user of the other company u cannot change it.

    Its kind of two persons are holdin 50% of stake each and you trying to give one of them all the rights.

    Its conflict.

    if you come to know more about it please post.
    Thanks,

    Ritesh
  • Asallai
    Asallai Member Posts: 142
    fvet wrote:
    A customer wants the following setup of permissions:

    User X may have full access to company A,
    but only restricted access to some modules in company B.

    So I've set up follow permissions:

    User X has been assigned the SUPER role for company A.
    For company B, the user has only been assigned e.g. the ALL role.

    ...

    Any ideas?

    Have you tried copy the SUPER group to another SUPER group(B) with your criteria? (SUPER copy to SUPER2 and tilt any modification in to Permission table, or something like this)
    :-k
  • Captain_DX4
    Captain_DX4 Member Posts: 230
    To be assigned SUPER permission, the user will have unrestricted access to Object Designer, all the menus, ability to change companies to any company, etc. You cannot restrict some of these functions by one Company only. Simply have SUPER will allow it application-wide.

    Using the ALL permission does give a fairly wide range of permissions throughout a Company. So the combination of ALL in one and SUPER in another may appear as the user isn't being restricted at all.

    Could we get more detail on what functions you would specifically like restricted for the user? From there we can verify how to accomplish what you are looking to do.
    Kristopher Webb
    Microsoft Dynamics NAV Developer
  • kine
    kine Member Posts: 12,562
    There is one issue with that. If some user has SUPER role with company field filled in (and he can have the SUPER role for all companies in the database in this way), he will be not able to delete any company in the DB. For deleting company and may be other actions you need to have SUPER role without company filled in...
    Kamil Sacek
    MVP - Dynamics NAV
    My BLOG
    NAVERTICA a.s.