Cache Builder and User Roles
Hi @Justin_Workman, figured this would be a good place to continue our discussion from this morning about the cached builder and scoped access.
Here is an output of all the roles and their memberships:
USER ROLE: RTS Portal End Users
USER ROLE: Change Managers
USER ROLE: Incident Resolvers
DIRECT USER/GROUP: ASURITE\M.OVPR.Servers.ServiceManagerAnalysts
USER ROLE: Activity Implementers
USER ROLE: Workflows
DIRECT USER/GROUP: ASURITE\vprscsm_app
DIRECT USER/GROUP: ASURITE\vprscsmdev_app
USER ROLE: Administrators
DIRECT USER/GROUP: ASURITE\vprscsm_app
DIRECT USER/GROUP: ASURITE\vprscsmdev_app
DIRECT USER/GROUP: ASURITE\M.OVPR.SCSMAdmins
DIRECT USER/GROUP: ASURITE\jdjohn35
USER ROLE: Problem Analysts
USER ROLE: Advanced Operators
DIRECT USER/GROUP: ASURITE\M.OVPR.Servers.ServiceManagerAdvancedAnalysts
USER ROLE: Authors
USER ROLE: Change Initiators
USER ROLE: Release Managers
USER ROLE: Service Request Analysts
DIRECT USER/GROUP: ASURITE\M.OVPR.Servers.ServiceManagerAnalysts
USER ROLE: Read-Only Operators
DIRECT USER/GROUP: ASURITE\mjenniso
USER ROLE: End Users
Their are 3 groups being used here, ServiceManagerAnalysts has ~250 members, ServiceManagerAdvancedAnalysts has ~50 users and SCSMAdmins has 5 members.
So all together we have 300 users that should be getting scoped access.
I just restarted the cache builder with debug level logging, I still see old groups that have been removed from end users role (DL.ORG.OKED.ALL) and there are 20k lines of building the scoped access for my 300 users in roles.
I'm at a loss what to do next. Thanks, James.
Answers
@James_Johnson - I removed your log for privacy's sake but I have it. The evaluation of the dl.org.oked.all group is probably happening due to its use in the portal somewhere, not because of role membership. You might look for its use in old announcements or Team Requests View Groups in Admin Settings -> Group Settings.
I did have the group used for some announcements. Is there a way to scope an announcement to a user role instead of picking an AD group?
@James_Johnson - There's not. You can only scope announcements on user groups.