cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Showing results for 
Search instead for 
Did you mean: 

We are happy to announce the new Windchill Customization board! Learn more.

View and Print Only Group

MikeLockwood
22-Sapphire I

View and Print Only Group

New for 10.x is the site-level View and Print Only Group. This Group has one ACL against it at Site level- it denies all actions except Read and Download. At Site, License Reporting, there is a tab for this group.


We recently attempted to convert fromusing our "Viewers" Group at Org level to this OTB Site level group. We just backed out of doing this, pending more understanding.


At this point, from the info page of EVERY user, that usershows thatthey are part of the View and Print Only Group, even though only about 1/4 of users were added to it. You can edit any user and remove the View and Print Only Group. On refresh it comes back. We tried every cache deletion, recompute, etc. It's very sticky. If you go to the info page of the View and Print Only Group and list the users, it correctly only displays the users that we added there.


We cannot figure out how to get all the users to not list that they are part of this group on their info pages.


Wondering if anyone has seen this and figure it out.


Tech support case C11856126 is pending. Seems like a major bug to us.

8 REPLIES 8

Are they using deny rights? If so, this is might be the issue. Deny overrides all other grants and since its at the site level, it can affect everything. Users in this group cannot be added to any other group. This is different than ACLS that add increasing levels of access to achieve the desired level.



In Reply to Mike Lockwood:



New for 10.x is the site-level View and Print Only Group. This Group has one ACL against it at Site level- it denies all actions except Read and Download. At Site, License Reporting, there is a tab for this group.


We recently attempted to convert fromusing our "Viewers" Group at Org level to this OTB Site level group. We just backed out of doing this, pending more understanding.


At this point, from the info page of EVERY user, that usershows thatthey are part of the View and Print Only Group, even though only about 1/4 of users were added to it. You can edit any user and remove the View and Print Only Group. On refresh it comes back. We tried every cache deletion, recompute, etc. It's very sticky. If you go to the info page of the View and Print Only Group and list the users, it correctly only displays the users that we added there.


We cannot figure out how to get all the users to not list that they are part of this group on their info pages.


Wondering if anyone has seen this and figure it out.


Tech support case C11856126 is pending. Seems like a major bug to us.



Mike,



I am pretty sure this is a special group that is specifically intended for the not commonly advertised “View Print Only” licenses of Windchill, these are the cheaper licenses that are available if you beg your sales guy. As I understand things being in the group comes with limitations in the User Interface with an imposed profile and embedded access control.



Sounds like this is somehow impacting your entire organisation though, do you have a group at the org for all users? Has this somehow been added to the special View Print, or has your entire Org been put in there?


-----

Lewis




We do in fact have the "View and Print Only" licenses, and this is our main motivation for attempting to convert to use of this group.
There is a Profile tied to it OTB; we edited the profile a bit to match what we have had in place for our created "Viewers" group. Same behavior seen when we temporarily edited the Profile to remove it from this Group.

We nest groups extensively - which allows far more efficient application of ACL's. Only a few are provided to the View and Print (Viewers) group; each subgroup level has additional. We removed the OTB Deny ACL from the View and Print Only group to allow for this approach.

We're now removing all configurations that we added and trying to get all users correctly displaying their correct groups. Will be very cautious to fully test this outside production before attempting to add back.

Mike,

Where you able to get this to work?

MikeLockwood
22-Sapphire I
(To:STEVEG)

Nope - never went back to try to use this OTB group.

On our test server I added one user to the group but it doesn't show up in that tab under Usage and License Reporting for some reason.  I don't know why it's not showing that user.

TomU
23-Emerald IV
(To:STEVEG)

Steve Galayda‌,

I am using this group on Windchill 10.2 M030 and it's working fine.  At the moment I have one test user and one Active Directory group added to it.

The Active Directory group contains both user and other groups and goes several levels deep.  All of these users are being correctly resolved by the Usage and License Reporting tool.

This report only gets recalculated every so often (once per day???), so you won't see changes immediately.

There were a couple of times where I removed someone from a group and the change didn't show up immediately.  Typically a "Recompute group" command, or (worse case) a server restart takes care of the issue.

STEVEG
21-Topaz I
(To:TomU)

Tom Uminn

Thank you for the info.  I just tried the recompute but it didn't update it.  Not a big deal.  I might have to try and restart WC.

Top Tags