Before you begin: these statements modify Maximo security data directly and give the
MAXADMINgroup extensive access. Take a database backup, follow your organisation's change process and test the statements in a non-production environment first.
The standard Maximo installation creates the MAXADMIN account for configuring and administering the system. The account can use Security Groups to assign permissions, but it does not initially have access to every application.
The statements below read the application options from SIGOPTION and add any permissions missing from APPLICATIONAUTH. Choose the statement for your database platform.
DB2
DB2 assigns each new APPLICATIONAUTHID from the APPLICATIONAUTHSEQ sequence.
--Grant access to all applications
INSERT INTO
APPLICATIONAUTH (
GROUPNAME,
APP,
OPTIONNAME,
APPLICATIONAUTHID
)
SELECT
'MAXADMIN',
APP,
OPTIONNAME,
NEXT VALUE FOR APPLICATIONAUTHSEQ
FROM
SIGOPTION
WHERE NOT EXISTS (
SELECT
NULL
FROM
APPLICATIONAUTH
WHERE
APPLICATIONAUTH.APP = SIGOPTION.APP
AND APPLICATIONAUTH.OPTIONNAME = SIGOPTION.OPTIONNAME
AND APPLICATIONAUTH.GROUPNAME = 'MAXADMIN'
);Oracle
Oracle assigns each new APPLICATIONAUTHID with APPLICATIONAUTHSEQ.NEXTVAL.
--Grant access to all applications
INSERT INTO
APPLICATIONAUTH (
GROUPNAME,
APP,
OPTIONNAME,
APPLICATIONAUTHID
)
SELECT
'MAXADMIN',
APP,
OPTIONNAME,
APPLICATIONAUTHSEQ.NEXTVAL
FROM
SIGOPTION
WHERE NOT EXISTS (
SELECT
NULL
FROM
APPLICATIONAUTH
WHERE
APPLICATIONAUTH.APP = SIGOPTION.APP
AND APPLICATIONAUTH.OPTIONNAME = SIGOPTION.OPTIONNAME
AND APPLICATIONAUTH.GROUPNAME = 'MAXADMIN'
);SQL Server
Unlike DB2 and Oracle, this SQL Server procedure does not use a database sequence. It generates each new APPLICATIONAUTHID by adding ROW_NUMBER() to the highest existing value.
--Grant access to all applications
INSERT INTO
APPLICATIONAUTH (
GROUPNAME,
APP,
OPTIONNAME,
APPLICATIONAUTHID
)
SELECT
'MAXADMIN',
APP,
OPTIONNAME,
(
SELECT
MAX(APPLICATIONAUTHID)
FROM
APPLICATIONAUTH
) + ROW_NUMBER() OVER (
ORDER BY
SIGOPTIONID DESC
)
FROM
SIGOPTION
WHERE NOT EXISTS (
SELECT
NULL
FROM
APPLICATIONAUTH
WHERE
APPLICATIONAUTH.APP = SIGOPTION.APP
AND APPLICATIONAUTH.OPTIONNAME = SIGOPTION.OPTIONNAME
AND APPLICATIONAUTH.GROUPNAME = 'MAXADMIN'
);After the insert, update MAXSEQUENCE so Maximo knows that the allocated range has changed:
--Update APPLICATIONAUTH Sequence
UPDATE
MAXSEQUENCE
SET
MAXRESERVED = (
SELECT
MAX(APPLICATIONAUTHID) + 10
FROM
APPLICATIONAUTH
)
WHERE
TBNAME = 'APPLICATIONAUTH';Restart the Maximo application server after updating MAXSEQUENCE.
Start Center portlets
Start Center portlets work differently from standard application options. A NOPORTLET entry denies access, so inserting the missing permissions does not make every portlet available.
The following statement removes those restrictions for the MAXADMIN group. The same statement applies to DB2, Oracle and SQL Server:
--Grant access to start centre portlets
DELETE FROM
APPLICATIONAUTH
WHERE
GROUPNAME = 'MAXADMIN'
AND APP LIKE '%CONFIG'
AND OPTIONNAME = 'NOPORTLET';Commit the transaction if your database client does not do so automatically. Then sign in with an account in the MAXADMIN group and confirm that the applications and Start Center portlets are available.
The insert grants only the options present in SIGOPTION when it runs. Review the permissions again after installing a product or update that adds application options.