-->
Showing posts with label GPSecurity. Show all posts
Showing posts with label GPSecurity. Show all posts

Friday, November 19, 2010

Security DrillDown Page From Roles to Tasks to Operations

Rubal has just made an awesome Security drilldown page which lets you drill-down from a Security Role to show you all Tasks in the role. After that you can review all the Operations(Windows/Reports) in a Task.

Check it out at - http://www.gpwindow.com/securityreport.php 

This should be helpful when you are planning for security or making security changes.

Check out Chetna’s post about this at http://www.gpwindow.com/dynamicsgp/2010/11/19/security-drilldown-page-for-dynamics-gp-roles-tasks-and-operations/

Tasks in a Role

clip_image005

Operations(Windows/Reports) in a Task

clip_image006

Friday, October 1, 2010

Security Task/Role associated with a Dynamics GP Window

One of the most common GP queries is “How to give access to a GP Window” ? David Musgrave from Microsoft has covered this in detail in the Microsoft Dynamics GP Application Level Security Series -

I have used both the options a few times, and love them. However, sometimes when you are on the phone guiding somebody who does not have Support Debugging Tool or experience with SQL, this get tough.

So with some excellent coding from Rubal – GPWindow.com now has a Security Task/Role lookup page – You can search for Roles or Tasks for a GP Window or Report. This page -

Search for “Sales Transaction Entry”, shows you the Roles and Tasks that contain this Window.

TIP - Try typing in the full window name for better performance. Single words will mean slower results.

 

image

 

Search for “Transaction Upload” and it lets you know that no Inbuilt security Role has this Window. It points you to this article- Setting up a Security Task/Role for a GP Window or Report

 

image

 

Note -

  1. This page only shows data from the inbuilt roles and tasks. If you have custom tasks, I would recommend following instructions from David’s article.
  2. Try and type in the full Window name for better results.

Related Useful Security Article

Wednesday, August 18, 2010

GP Security Does not work

Recently there was a question in the newsgroups where a user had the problem that their roles were not working correctly. Users with a particular security role could see the windows they were not supposed to see. The problem seemed complicated, but the solution was simple.

It turned out, with the help of MVP Leslie Vail, that the problem was just that the security checkbox was not checked on in the company setup window!

Mark covered this in his weekly review - “You MUST check the Security checkbox in Tools-Setup-Company-Company if you want security to be active.” http://msdynamicsgp.blogspot.com/2009/08/weekly-review-that-little-security.html

Tuesday, July 27, 2010

GPWindow.com – Thousands of GP Tips and Tricks from All MVPs and Experts

For a while now, we have had the custom GP Custom Search engine which searched handpicked Dynamics GP Blogs. Now you have an easy to remember Address for this Search Engine-  www.GPWindow.com.

In addition to the Search Engine, the GP Articles by various MVPs and Experts have been organized by categories, for people who like browsing rather than searching. There are over 6000 articles in various categories. The topics are ranked based on their importance based on how often they are recommended by other GP Experts.

As of today, there are 6169 articles organized into various GP categories like  - 

1. TIPS AND TRICKS BY MODULES (782 Sub-Items) 

In this category, right on the top you will see Mark Polino’s extremely famous “50 MORE Tips in 50 Minutes” presentation. Under the main Tips and Tricks category, you can find hundreds of great tips for each module like -

image 

2. REPORTING (531 Sub-Item) which includes MANAGEMENT REPORTER, SmartList Builder, Report Writer and so on.

3.  A category for the red hot SUPPORT DEBUGGING TOOL under TOOLS FOR GP (102 Sub-Items)

4.  OFFICE INTEGRATION (143 Sub-Items)

Some sample posts -

5. DEVELOPMENT (470 Sub-Items)

6. GP USER INFO (190 Sub-Items)

7. GP TECH INFO (249 Sub-Items)

This category would be useful for people who support or implement Dynamics GP. It has information about

8. DOWNLOADS (30 Sub-Items)

Hopefully this section will save everybody a lot of time. Here you will find the latest links for Dynamics GP Release Downloads, FRx DownloadsGP Service Pack Downloads, IM Downloads and Management Reporter Download

My favorite link here is the Dynamics GP Product Downloads and Service Pack Links maintained and kept current by David Musgrave

9. MANAGEMENT/CONSULTING

Here you will find Consultants Sell article by Martin from eOne Solutions, and lots of excellent articles by Dwight Specht like “I did my job” – “Yeah, but we suck” , Managing in a Downturn, Bad Client! Bad, Bad Client!Evaluation of Consulting Staff and many others.

10. GP 3RD PARTY SOLUTIONS / ISVs (188 Sub-Items)

Here you will find some product information including information about Free Dynamics GP Addon’s by Matt Landis and company.

11. SQL SCRIPTS (217 Sub-Items)

Here you will find the Useful SQL Scripts Series by David Musgrave and other scripts by Mariano, Mark, Victoria, M Daoud and Ron Wilson at Real Life Dynamics User Blog. You can find more than 200 scripts under various modules.

12. SECURITY IN GP (121 Sub-Item) 

More

This site is all Dynamics GP, so you would see a category for Dex.ini Settings (with excellent posts from Leslie Vail, Mariano and Mark ) and one for Reports.dic under SUPPORT (TECHNICAL) (438 Sub-Items) .

N0tes -

  1. There are over 200 categories so I highly recommend using “CTRL + F” to look for a category.
  2. There are over 6000 articles, the articles above are just a small selection from each category. I was also trying to keep a healthy mix of articles from all GP Experts. Please dig into a category to find out more articles. Over the next few months I will try and detail out the most popular articles in each category.

Thank you notes !

Thanks to David Musgrave for noticing and promoting the Custom GP Blog Search, which lead to GPWindow.com, and for his excellent review. Thanks to Vaidy for taking out time to review the website in detail, and staying up late to give his feedback in a busy week. Thanks to Mariano Gomez, the GP expert with the big heart, for passing on good words about GPWindow. Thanks to Mark Polino and M Daoud for their feedback.

Thanks to my good friend Evgeny for his techie magic. Thanks to Rubal, the idea-machine, for suggesting a URL and the directory, she already has ideas about the next version. Thanks to Kuldeep for telling me every Monday morning- “You know, I’ll tell you the truth - the website looked pretty average last week, but now it ROCKS! It looks very useful now!”, and after reading this post telling me “You know I like the site, and I like your post about it, but the Thank you notes are a little cheesy!” He said it was perfect, when I told him, the only name I could take out was his name.

Thanks to Chetna for volunteering to spend time in reviewing the website and checking meticulously if there was any missing data, to Tina for her keen eye pointing out all the things that didn’t work, to Richard and Belinda for their encouragement and humor!

Feedback and Next Steps -

  1. Use the website, Search or Directory, whatever you prefer. If you have trouble finding a download link, try looking it up in the Downloads category, if you are searching for a SQL Script, try using the search. If GPWindow helps, let me know or spread the word.
  2. If you go into a category and notice an old article missing, please shoot me a line. Because of the sheer volume of the articles there could be some articles missing from their appropriate categories. 
  3. Do see any categories missing ? or any categories that are difficult to find ?
  4. Any other feedback your might have – add it as a comment to this blog or shoot an email.

Hopefully GPWindow will help you find the extremely valuable articles created by people in the GP community ! Good Luck!

Tuesday, May 25, 2010

Field Level Security in Dynamics GP 2010

In Dynamics GP 2010 all Business Essentials(BE) users receive Field Level Security(along with Account Level Security and Electronic Banking Suite) at no additional cost.

This makes the recent post by Frank Hamelly on Field Level Security worth highlighting -  http://gp2themax.blogspot.com/2010/05/gptip42day-fiield-level-security.html – He has a nice example “let's say you want to hide the Current Cost field in the Item Card from everyone but your cost accounting department.  Here's how you do it with FLS:”

Using Field Level Security you can hide any field on a window from specific users. Without Field Level Security if you want to hide the Post or Approve Button on the Batch Entry window from specific users, you would have to use a customization or VBA Code. Field Level Security offers this out of the box. Field Level Security also allows you to assign passwords to make a field or window available to the users.

image

 

Some more resources -

Post by Janakiram at http://janakirammp.blogspot.com/2009/07/optimize-security-using-field-level.html

FAQ about Advanced Security and about Field Level Security in Microsoft Dynamics GP and in Microsoft Great Plains - https://mbs.microsoft.com/knowledgebase/KBDisplay.aspx?WTNTZSMNWUKNTMMYKKQRRUZVRPSSXNSNWTQZRSXSPOKVWULOKVZQXRMWLXVVUMZK

Monday, May 17, 2010

Dynamics GP Professional Tools Security

GP Professional Tools Library requires the user to be logged in as ‘sa’.

The tools that specifically require this are -

• Toolkit
• Database Disabler
• Customer Modifier
• Customer Combiner
• Customer Name Modifier
• Item Number Modifier
• Item Number Combiner
• Vendor Modifier
• Vendor Combiner
• Vendor Name Modifier
• Login/User Generator
• Account Modifier/Combiner
• Salesperson Modifier
• Territory Modifier
• Territory Combiner

This is often a problem with customers as administrators don’t like giving out the sa password to end users, who could be running a tool like say Customer Combiner.  Right now, Administrators have the option to go up to the users and log them in every time they want to use these tools, or give them the sa password.

In Microsoft’s SQL Server Security Best Practices, Microsoft recommends -

· Do not manage SQL Server by using the sa login account; assign sysadmin privilege to a knows user or group.

· Rename the sa account to a different account name to prevent attacks on the sa account by name.

As of now, if you are using the Professional Tools Library, you have to use the sa login. You cannot use DYNSA, or any other user with sysadmin rights.

You would simply get the message - “You must be logged in as ‘sa’ to utilize this Utility”

Or maybe, I am missing something here …

Vote for this feature to be implemented,  fliehigh had put this as a product suggestion in May 2008 - https://connect.microsoft.com/dynamics/feedback/details/347992/gp-professional-service-tools-security

Monday, March 30, 2009

Why User Classes are still relevant in GP 10

Mark Polino writes about how User Classes are STILL relevant in GP 10. They are used in Organizational Structures and thereby Account Level Security.

http://msdynamicsgp.blogspot.com/2009/03/weekly-dynamic-dynamics-gp-10-roles-vs.html

Monday, April 7, 2008

GP 10 Security : Power User is more Powerful than all other roles combined!

Recently we got a request to remove access to one window in GP for a user, who was otherwise a "Power User".

We had to remove access to the 'Challenging' Posting Setup Window, which I would write about in detail sometimes soon. Depending upon your experience with the Posting Setup Window you can substitute 'challenging' with words of your choice.

So we created a new role, selected all tasks in it, just removed access to posting setup window. We then changed the role of the user from Power User to this new role.

A week later, the user started reporting problems. It turned out even with all tasks assigned to the user, they didn't have access to certain areas. This was because - there were no tasks for those areas. I had written about how there are no inbuilt tasks Safe Pay Earlier.

So we ended up creating new tasks for all these areas. This was an iterative process, where we created tasks for various products. I will try and document all these areas in the future for your reference. It is a lengthy process to create tasks for all these missing modules in an organized way.

Meanwhile, Mr Power Users can keep their legacy for a while longer.

Wednesday, March 19, 2008

GP 10 does not have an inbuilt role/task for Safe Pay

Today while giving a user access to Safe Pay (Tools > Routines > Financial > Safe Pay), I realized that there wasn't an inbuilt task/role for Safe Pay. I was a little surprised, as this was the first major missing task in the otherwise excellent default Security Role /Task Setup.

However, it wasn't too difficult to set it up, here's what you have to do -

1. Create a new task called SAFE_PAY (or whatever, you want to name it according to your security setup)

2. Select Safe Pay as Third Party Product and give access to the Safe Pay Windows and Reports (Let me know if you need details on this)

3. Assign this tasks to a Role

4. Give the user who needs safe pay access, access to this role.

You should be able to see Safe Pay Menu option after this.

Wednesday, January 16, 2008

Security Upgrade to GP 10 - Upgrade Security or Set Up Security from Scratch?

A recent discussion in the forums about upgrading security went like this -

http://www.microsoft.com/Businesssolutions/Community/NewsGroups/dgbrowser/en-us/default.mspx?dg=microsoft.public.greatplains&mid=b41718b4-bb8b-471a-af2c-2f95fd2c7c15

Brad (Customer): Does anyone know if there is a tool or utility to convert Advanced Security in GP 8 to the new security model in GP 10. Lots of time and effort went into setting up security in 8 and would hate to redo it.

David (from Microsoft) : There is a security conversion tool which can be used during the upgrade of the DYNAMICS database.

Before you use the tool, you should be aware of how it works and what the consequences of using the tool are.

In the new model, each user can be assigned multiple security roles. Each role is made up of tasks and each task is made up of operations. Operations are the actual access permissions as shown in v8 Security (Standard or Advanced).

When you use the conversion tool, it will create a new security task and matching security role for each user/company combination.

While this will provide the same access you had in v8, it will not leverage the role based model at all. Also, maintenance would need to be handled on a individual user/company combination as there are no classes or multi-selection in v10.0.

My personal opinion is to promote this as a perfect opportunity to redo security using the new more powerful and flexible role based pessimistic model.

Brad (Customer) : Thank you very much for your answer, I understand the added granularity that the new security model allows, unfortunately our Sarbanes auditors aren't as flexible.

Now I totally understand what Brad is saying - It takes a lot of time and effort to set up Security. Making sure each user has access to what they are required to do, not more, not less - is work. And if you have something working - you generally don't want to break it.

At the same time I can understand David's pain - The security architecture in GP 10 is miles ahead of the security in GP8/9. Its in a different generation altogether! And as he points out correctly - in the longer run - it would be difficult to maintain the upgraded security. Maintaining GP 10 Tasks and Roles are much more easy.

I guess there is no simple answer to this. What I decided to do was - to do some tests and show how security upgrades. Perhaps, that would probably make it a little easier for people to make a decision.

If you have any inputs or suggestions, do let me know.

Security in GP 9

I created a test company in GP 9 and added 6 users in it.

1. I created 3 classes.

2. I assigned 3 users - to a class "AP Clerk".

3. One user was given a class - "Accounting Manager".

4. The two remaining users - were not given a class - I set up security for them independently

Users Created in GP 9

How the Security upgraded to GP 10

In GP 10

1. Each Class was translated to a task.

2. Each "User/Company" Security permissions was translated to a Role. This role - had one task - which in turn had the permissions.

3. All Users were assigned their own individual "User/Company" Role. None of the users was assigned to the common class.

A Task was made for each Class

A Task was made for each User/Company Combination The User was given access to the new Role specific to that User A Task Broken down into Operations

A Alternate Modified Reports ID was made for each User and Class.

Maintenance Problems - When you use Upgraded Security

Having a Role for each User, is a maintenance nightmare. You would have to make a change in 50 places for 50 users.

If you have to make a change to the class "AP Clerk" - that is not possible immediately. You would have to

a) Make a role which maps to each task created from a GP 9 class

b) Assign all the three users access to the new role.

Now when you make a change to that role, all users would pick it up.

This looks kind of ugly, because each Role just has one task, which as the permissions. In a way the Role is just a pseudo role. It sits there as a proxy, looking at what's going on feeling useless about its existence.

However, it's the best that can probably be done in migrating to a completely new architecture.

Now if you were to set up the same security in GP 10. Here's how you would probably do it. You would create a role AP Clerk, and all relevant users would be assigned that role. You would have relevant tasks in that role. Then, when you make a change in the role - all users would pick up the change.

Additionally you could use Tasks to further break down your security architecture. Roles, Tasks and Operations in GP 10 offer a far greater potential to plan security in comparison to Classes and Operations in GP 9.

Knowing what's possible with GP 10 security - I would feel uneasy, in just migrating security and using it the way it migrated. Everything would probably work - but it is just not the way it is supposed to work.

Tuesday, December 11, 2007

GP 10 Security : Planning for Security White paper

Excellent Read, especially for the IT guys managing a Great Plains installation. This document ships with GP 10 as well, but I haven't run into anybody who has actually read it !

https://mbs.microsoft.com/customersource/documentation/whitepapers/msdygp10_securityplanwp.htm?printpage=false

Because the size of Microsoft Dynamics GP implementations can vary a great deal, it is important to carefully consider the needs of a smaller business and to weigh the effectiveness of security against the costs that may be involved. Use your best judgment to recommend a policy that helps to meet security needs.

This document discusses the following topics:

    * Basic security recommendations
    * Securing the server operating system
    * Network security
    * Virus protection
    * Microsoft Dynamics GP security
    * The Microsoft Dynamics GP database security model
    * Core application security tasks
    * Frequently asked questions about security in Microsoft Dynamics GP

Thursday, November 15, 2007

GP 10 Security : Excel Sheet which has the roles and tasks in each role

Most people setting up GP 10 security have trouble understanding the in built roles - what tasks are available to each role.

We've generated an excel sheet which has the roles and tasks in each role. It comes in handy as finding out the tasks in each role is difficult right now, as there is no option to view only available tasks. You have to scroll up and down to see which tasks are in a role.

You can download it from here.

I've seen lots of suggestions related to this in the newsgroups, so I guess this should come in a future release.

If any of you would like more details – let me know and I can put out a larger excel sheet.

PS - If you are just about getting started with GP 10 security, or planning an upgrade might be a good idea to listen to Mark Polino's podcast #7 (Listen till the end). Lots of useful information there.

GP 10 Security : Quick Facts ... The 1-2-3.

1. Users can be Assigned Roles which have a list of Tasks Associated with them, which are made of operations. So the Hierarchy is as follows – Roles >> Tasks >> Operations

2. Roles, Tasks and Operations can each be Customized

3. You can even assign multiple roles to a user.

4. Field Level security : We can select specific Windows and Fields in them and apply setting on them( Hide/Disabled/Password Protected etc)

Security role example The ACCOUNTING MANAGER* role contains security tasks that allow a user who is assigned to this role to view General Ledger account information, enter journal entries, enter bank transactions, and perform other tasks that an accounting manager might need to perform.

Security Tasks Examples

Set up Inventory Set up item classes and currencies Set up lot categories