Export users and roles into MES
- Last UpdatedNov 04, 2024
- 2 minute read
Although Entity Model Builder is not a comprehensive user/role synchronization tool, you can use it to export System Platform users and roles into corresponding MES users and groups in the MES database.
In System Platform, you must use Galaxy, OS User, or OS Group security to export users and roles into MES. Also, MES must be in the same security mode as the Galaxy. For example, if System Platform is in the Galaxy security mode, MES must be in Native security mode.
Note: If the System Platform security type is None, you will not be able to export users and roles into MES.
You can export System Platform IDE users and roles into corresponding MES users and groups with the following conditions:
-
If using System Platform OS Group security, the OS Users are added to the Galaxy as those users are authenticated. Therefore, you might have to periodically run Entity Model Builder to export new OS users into the MES database.
-
You cannot export the System Platform DefaultUser user or Default role.
When a user and role export to the MES database is performed:
-
All users and roles in the Galaxy database will be candidates for export even if they do not match the current System Platform security mode.
-
If duplicate names are present in the set of names to export, a warning message will appear in the Progress dialog box and the Operations Control Management Console Log Viewer during the export.
-
Entity Model Builder will create users and groups if they do not already exist in the MES database. It will not delete or modify the configuration of any existing MES users or groups.
-
MES users and groups will have the same parent/child relationships as the associated System Platform users and roles.
-
If a user is new but the groups of which the user is a member already exist in the MES database, the user will be added to the existing groups.
-
New users are initially set as Inactive in MES.
-
If using System Platform Galaxy and MES Native security modes, new users are assigned a password that is the same as their username. An administrator must assign the user to a group in MES Client that has MES Client login privileges. Each user can then log on to MES Client and change their password to a more secure password.
-
The permissions for new MES groups are left blank. Permissions will have to be assigned in MES Client.
-
New MES groups are not granted any entity access. Entity access will have to be assigned in MES Client.
-
If a user or role is deleted in System Platform, Entity Model Builder will not delete the corresponding MES user or group.
You can modify or update users and roles at any time in the System Platform IDE. When exporting, Entity Model Builder will check the System Platform users and roles and make any necessary additions or modifications to the MES users and groups.