Views, Filters & Print

Security Profiles

Security Profiles is Admin > Security Profiles global and project privilege sets; not Users; no table on project XER

P6 EPS / Projects tree. Enterprise nodes hold projects such as EC00515.
This is the project tree. Security profiles are Admin privileges, not a project.

What a planner means

Security Profiles is the privilege-set dialog. Oracle Admin Menu: "Opens the Security Profiles dialog box. Use the Security Profiles dialog box to create, edit, and delete security profiles, or user access types." Enabled when "All." Corresponding toolbar: Administrator Toolbar. How-to pages: Admin, Security Profiles.

Oracle Security profiles: "Security profiles determine a user's level of access to project information. The security profiles include both global profiles and project profiles. A global profile determines the user's access to application-wide information. A project profile determines the user's level of access to each project within the Enterprise Project Structure (EPS)."

This dialog is enterprise privilege sets. It is not Admin > Users (login accounts; assignment of a profile to a user). It is not Admin Preferences (enterprise defaults). See Admin Preferences. It is not Admin Categories (standard category dictionaries). See Admin Categories. It is not Edit > User Preferences (per-user display and session). See User Preferences. It is not OBS (Responsible Manager tree). See OBS. It is not EPPM User Administration pages (a different admin surface; see below).

Assignment of a profile to a person is Admin > Users. Oracle Assign global profiles: Admin, Users → Global Access tab → "select a global security profile." Oracle Assign project profiles: Admin, Users → Project Access tab → Assign an OBS element/responsible manager → Security Profile field. Do not treat this note as the Users dialog.

Professional dialog fields Oracle names

Oracle did not print a dedicated Security Profiles dialog-box tab-list page in the collection fetched. Create / change how-tos name two choices (quote Oracle; do not invent "tabs"):

  • Global Profiles
  • Project Profiles

How-to Create global profiles: "Choose Admin, Security Profiles." "Choose Global Profiles, then click Add." "Type the new profile's name." "To make the new profile the default global profile, mark the Default checkbox." "Mark the appropriate checkboxes to grant specific privileges to the profile."

How-to Create project profiles: "Choose Admin, Security Profiles." "Choose Project Profiles, then click Add." "Type the new profile's name." "To make the new profile the default project profile, mark the Default checkbox." "Mark the appropriate checkboxes to grant specific privileges to the profile."

How-to Change global profiles / Change project profiles: double-click the profile to rename; mark Default; "mark or clear the checkboxes to grant or deny each privilege." Delete: select the profile, click Delete, click Yes.

Oracle Global Privilege Definitions / Project Privilege Definitions: "The privileges are listed in the same order as displayed in the Security Profiles dialog box. To view the privileges in alphabetical order in the Security Profiles dialog box, click the Privileges bar."

Oracle printed full privilege-definition pages. This note does not reprint that catalog. Quote the pages, not an invented short list. Privileges Oracle named that distinguish this dialog from neighboring Admin objects (not a catalog):

  • Add/Edit/Delete Security Profiles — "create, modify, and remove global and project security profiles, which grant access to application-wide and project-specific information."
  • Edit Admin Preferences — "modify administrative preferences as defined in the Admin Preferences dialog box."
  • Add/Edit/Delete Categories — "create, modify and remove categories data as defined in the Admin Categories dialog box." (Oracle also printed a second Categories sentence: "modify administrative categories as defined in the Admin Categories dialog box.")
  • Add/Edit/Delete Users — "create, modify, and remove P6 Professional user data."

Global profiles — Oracle Global profiles: "P6 Professional requires that all users have a global profile. A global profile defines a set of privileges for access to global, or application-wide, information such as cost accounts, resources, and roles." Oracle Global Privilege Definitions: "A global profile definition specifies the individual access privileges associated with the profile. For a global profile, access privileges apply to application-wide information and settings. The module requires you to assign a global profile to each user."

When P6 Professional is connected to a P6 Professional database: "you create global profiles, and then assign specific profiles to individual users." When connected to a P6 EPPM database: "you create global profiles using P6, and then assign specific profiles to individual users."

Oracle Add new users: "When you create new users, they are automatically assigned the default global profile."

Project profiles — Oracle Project profiles: "A project profile defines a set of privileges for access to project-specific information. Project profiles are assigned to users based on the OBS hierarchy. To control access to project-specific information, you create project profiles, and then assign specific OBS elements and associated project profiles to individual users." "The assigned OBS element determines the EPS and WBS elements for which the user can access project information. The assigned project profile determines the type of access privileges the user has to that project information."

When P6 Professional is connected to a P6 EPPM database: "you do those tasks using P6."

Oracle Project Privilege Definitions: "A project profile definition identifies the specific access privileges that are granted by the profile. Each project profile is associated with an organizational breakdown structure (OBS) element to determine which EPS structure elements an individual user can access."

Oracle Security profiles (both database types): "When you assign a project profile to a user" (EPPM-database sentence: "as defined in P6") "you also associate the project profile with an OBS element/responsible manager." "The user's access privileges, as defined in the project profile, will then apply only to those elements of the EPS that are assigned to the OBS element/responsible manager you selected."

Oracle Create project profiles note: "Unless a user's global profile is Admin Superuser, a user cannot access any projects without a project profile." Oracle Assign project profiles note: "A user is not required to have a profile for every OBS element. However, unless a user's global profile is Admin Superuser, a user cannot access project information without a project profile." OBS access is not inherited down child OBS elements. See OBS.

Admin Superuser / Project Superuser — Oracle names these predefined profiles. Quote Oracle's printed spellings (Admin superuser / Admin Superuser; Project superuser / Project Superuser). Do not collapse them.

  • Oracle Admin superuser (popup): "A global profile that gives a user read/write privileges for application-wide information and features. This information includes all projects, resources, cost accounts, and users. An Admin superuser always has access to all resources. If resource security is enabled, resource access settings will be ignored."
  • Oracle Global Privilege Definitions: "P6 Professional includes a global profile called Admin Superuser. This profile automatically gives a user all of the preceding privileges for all projects and P6 Professional features (assuming all applicable checkboxes are marked on the Users dialog box, Module Access tab)."
  • Oracle Global profiles (Professional database): "you can assign a global profile called Admin superuser." (EPPM-database sentence: "You cannot edit the Admin Superuser security profile.")
  • Oracle Project superuser (popup): "A project profile that gives a user read/write privileges for all project/ OBS specific information and features."
  • Oracle Project Privilege Definitions: "A project profile, Project Superuser, automatically gives a user all of the above privileges for each project, according to the specified OBS element." "To allow read-write privileges for all aspects of a project, you can assign a user to a project's root OBS element and then apply the Project Superuser profile to the project/OBS assignment."

Who may apply Superuser — Oracle's pages disagree; quote both. Do not pick a winner.

  • Setting up user security: "Only an Admin Superuser can apply the Admin Superuser profile to a user. Any user with the Add/Edit/Delete Users privilege can apply the Project Superuser profile to a user."
  • Assign project profiles: "Only an Admin Superuser can apply the Project Superuser profile to a user."
  • Project profiles (Professional database): "Only an Admin Superuser can apply the Admin Superuser profile to a user."
  • Project profiles (EPPM database): "Only an Admin Superuser can apply the Admin Superuser or Project Superuser profile to a user." (Oracle's "When Each user" as printed on that page.)

Professional pages fetched do not print No Global Privileges. That name is EPPM (below). Do not copy it onto this dialog.

Not Users. Resource security (All Resource Access; "select up to five resource nodes") and Module Access live on Admin > Users. They are not this dialog. Activity owner is TASKUSER, not a security profile. See Primary Resource.

Offline note Oracle printed on Security profiles / Setting up user security: avoid changing "User details, Global or project security profiles, OBS assignments (both for users and for projects), and Resource security" while a user is working offline. Check Out: security profile does not apply; all project data is exported. See Check Out.

EPPM — User Administration / Security Profiles, not Admin > Security Profiles

Oracle About Security: "Security Profiles: Defined collections of global and project level security privileges are stored and then assigned to users as needed. Users can only edit and save items if they have the appropriate security privileges."

Oracle About User Access lists these items (quote Oracle; do not copy the Professional dialog onto them): Users; OBS; Global Security Profiles ("assign or omit global privileges to profiles"); Project Security Profiles ("assign or omit project privileges to profiles").

Oracle Creating Global Security Profiles Getting Here: Administration → User Administration → Global Security Profiles. Fields Oracle named on that page: Profile Name; Description; Privileges detail window; Set As Default; Duplicate. Professional create/change pages fetched do not print Description / Duplicate. Do not invent them on Admin > Security Profiles.

Oracle Working with Security Profiles:

  • Global Security Profiles — "A global security profile determines a user's access to application-wide information and settings, such as resources, global codes, and the OBS. P6 requires that you assign a global security profile to each user." "You can define an unlimited number of global security profiles in P6. In addition, P6 provides two predefined global security profiles: Admin Superuser and No Global Privileges."
  • Admin Superuser — "allows complete access to all global information and all projects." "It also shows the full Administer menu, even when the currently assigned user interface view settings do not." "At least one user must be assigned to the Admin Superuser profile."
  • No Global Privileges — "restricts access to global data." Assigning Global Security Profiles: "The No Global Privileges profile provides read-only access to all global data except costs and secure codes."
  • Project Security Profiles — "A project profile is a role-based profile that limits privileges to specific project data, such as baselines, the WBS, and expenses. P6 does not require that each user be assigned a project profile; however, users cannot access projects unless they are assigned a project profile or the global profile, Admin Superuser." "P6 provides a predefined project profile called Project Superuser." "Project profiles are applied to users via OBS assignments." "The default profile is automatically assigned when an OBS is assigned to a user."

Do not copy Professional Admin > Security Profiles, Administrator Toolbar, Global Profiles / Project Profiles choose-list, Privileges bar, or the Professional Superuser-assignment conflict onto EPPM User Administration. Do not copy EPPM No Global Privileges, Description, Duplicate, User Interface Views, or Administration → User Administration onto this Professional dialog. When Professional is connected to an EPPM database, Oracle's Global profiles / Project profiles pages send create/assign to P6, not to Admin > Security Profiles.

XER

Security Profiles is an enterprise / database dialog. It is not an XER table.

Oracle's project XER data map TOC lists no PROFILE, SECURITY, SECURITYPROFILE, USERPROF, PROFPRIV, or USERS table. Do not invent a PROFILE / SECURITY / SECURITYPROFILE / USERS %T or columns for Global Profiles, Project Profiles, Default, privilege checkboxes, Admin Superuser, or Project Superuser.

OBS is the OBS tree (Responsible Manager). It is not this dialog. User-to-OBS / profile assignments are not on the cited project map. See OBS.

TASKUSER is Activity Owners. It is not a user account and not a security profile. See Primary Resource.

A Viewer parse of one project XER cannot reconstruct Security Profiles (global or project privilege sets, Default, Superuser definitions, or user-to-profile assignments).

Microsoft Project

Desktop Project has no Security Profiles dialog and no global/project privilege-set admin surface.

Microsoft Password-protect a project file is File > Save As → Tools → General Options file-sharing passwords: Protection password (open the file); Write-reservation password (read without the password; change only with it). "Project Web App automatically adds security to project files, so you don't have to add a password to files you store there." That is a file password, not a privilege profile.

Microsoft Plan user access in Project Server is Project Web App: SharePoint permission mode vs Project permission mode (customizable security groups; categories; RBS filtering). That is Project Server / PWA, not desktop Project, and not P6 Admin > Security Profiles.

They are not the same object. Do not map Security Profiles to File > Options, to a file password, to SharePoint groups, or to Project Server groups/categories. Do not claim MPXJ can write a real MPP.

Don't

  • Treat Security Profiles as Users, as Admin Preferences, as Admin Categories, as User Preferences, as OBS, as EPPM User Administration, or as project XER data.
  • Invent a PROFILE / SECURITY / SECURITYPROFILE / USERS / USERPROF / PROFPRIV XER table, or treat OBS or TASKUSER as "the Security Profiles dialog."
  • Claim a Viewer reconstructed Security Profiles from a project XER.
  • Write a privilege catalog Oracle did not print on the pages fetched, or invent privilege names.
  • Collapse Oracle's Admin superuser and Admin Superuser, Project superuser and Project Superuser, or pick a winner among the Superuser-assignment sentences.
  • Copy Professional No Global Privileges (EPPM name) onto Admin > Security Profiles, or copy Professional Admin > Security Profiles / Privileges bar / Administrator Toolbar onto EPPM User Administration.
  • Copy Users All Resource Access / Module Access onto this dialog, or treat profile assignment (Admin > Users) as the profile definition.
  • Map P6 Security Profiles to MSP File > Save As passwords or Project Server / PWA permission modes as the same object.
  • Claim MPXJ writes a real MPP.

Sources

Back to top