DRA users unable to see global tasks from the web UI

  • 7023445
  • 16-Oct-2018
  • 16-Oct-2018

Environment

Directory and Resource Administration Server 9.2.0.x

Directory and Resource Administration REST Services 9.2.0.x

Situation

When certain Assistant Admins (AA) logon to the Directory and Resource Administration (DRA) Web UI, they are not presented with a list of global tasks. They are able to see the properties of an AD object. The global tasks include create new <Object type>, Add member to group, remove member from group, and more.

Resolution

The DRA product administrator will need to reconfigure the DRA security. They will need to build a new custom role containing the powers of multiple roles. This will allow you to apply a single DRA security role to an active view assignment.

Cause

This issue is caused by having nested DRA security roles within a single DRA Active View (AV). In this situation the DRA Product admin has created a custom security role and added another (custom or built-in) role to it. The DRA Web UI is unable to correctly check the AA's powers when those powers are granted via nested security roles.

Additional Information

This KB applies only to the DRA version listed above.