AAI Machine page does not honor EEM Scheduler policies for instance-level access
search cancel

AAI Machine page does not honor EEM Scheduler policies for instance-level access

book

Article ID: 447867

calendar_today

Updated On:

Products

Automation Analytics & Intelligence

Issue/Introduction

When using Embedded Entitlements Manager (EEM) to segregate user access in Automation Analytics & Intelligence (AAI) by AutoSys instance, the following symptoms are observed:

  • A user is restricted via the Scheduler resource class policy in EEM to only see specific schedulers (e.g., Access to AC1, No Access to AC2).
  • EEM policy evaluation tests show the correct "Allow" or "Deny" results for the user.
  • However, within the AAI Machine page, the user can see all machines from all schedulers (e.g., seeing machines from both AC1 and AC2).
  • The machines are only restricted if the user manually selects a filter on the page.

Environment

  • Product: Automation Analytics & Intelligence (AAI)
  • Authentication: EEM (Embedded Entitlements Manager)
  • Feature: Machine Page / Scheduler Resource Class

Cause

This is a confirmed product defect where the AAI Machine page authorization engine fails to automatically apply EEM Scheduler resource class policies upon page load. The view is not restricted by instance-level permissions unless a manual filter is applied.

Resolution

This issue is tracked via internal defect DE183933.

A permanent fix is targeted for the following release:

  • AAI 24.4.2 (and all subsequent releases)

Workaround

To restrict the view to authorized machines in versions prior to the fix:

  1. Navigate to the Machine page.
  2. Use the Scheduler filter dropdown.
  3. Selecting a specific authorized scheduler (or selecting 'All' while the policy is active) will correctly refresh the view to show only the machines the user is permitted to see