11.1.1 Creating OBIEE Roles

To create the OBIEE Roles, follow these steps:

  1. Open the Admin Console of OBIEE.
  2. Click on Security Realms under Domain Structure.
  3. Click on myrealm under Realms.

    Figure 11-1 WebLogic Server Administration Console – Security Realms


    The WebLogic Administration Console allows you to create the OBIEE roles.

  4. Click on Groups tab of User and Groups.

    Figure 11-2 Groups Tab


    This screen of WebLogic Administrator Console allows you to create a new user goup.

  5. Click on New and create new user group as ‘Restricted Access’.

    Figure 11-3 New User Group Creation


    This screen allows you to create a new user group.

  6. Create a new user under Users tab of Users and Groups.

    Figure 11-4 New User Creation


    This screen allows you to create new users.

  7. Map the newly created users to ‘Restricted Access’ group, which need Data Visibility.

    Figure 11-5 Mapping New Users to Restricted Access Group


    This screen allows you to map the newly created users to the restricted access group.

  8. Close the Admin Console of OBIEE.
  9. Open Enterprise Manager of OBIEE.
  10. Click on biinstance under Business Intelligence.

    Figure 11-6 BI Instance


    This screen allows you to select the BI instance.

  11. Click on Security under biinstance.

    Figure 11-7 Security Tab


    The security tab in the biibstance screen allows you to configure and manage the application roles.

  12. Click on Configure and Manage Application Roles to create Application Roles.
  13. Map the newly created user group Restricted Access to the BI Consumer Role.
  14. Click on Create and name as OFSAA CI Data Visibility - MGR role . Ensure to use the same name as it is referenced in RPD failed to do this should have access to all reports data.

    Figure 11-8 Create Application Role


    This WebLogic Administration Console screen allows you to create application roles.

  15. Map the user group, which need data visibility to the OFSAA CI Data Visibility – MGR.

    Figure 11-9 OFSAA CI Data Visibility- MGR


    The biinstance screen allows you to map the user group that needs the data visibility to the OFSAA application.