This discussion has been locked. The information referenced herein may be inaccurate due to age, software updates, or external references.
You can no longer post new replies to this discussion. If you have a similar question you can start a new discussion in this forum.

Account limitation errors for admins without limitations

This has been discussed many times, but the posted solutions either don't apply, or are posted on a link that is now getting 404 errors.

None of our accounts have any limitations.

The AD group I'm logging in umder is dedicated to admins.  It has no limitations, and has every possible privilege.  

When I go to the "Manage groups" page from the all settings> Node & Group Management> Manage Groups path, I can see and create groups, but if I click on *any* of them I get the account limitations error.

When I push a group status out in an alert, the URL to link to the details also displays that error to all users that try to follow it.  The URL is the one I get with the "${N=SwisEntity;M=DetailsUrl}" in my alert messages.

Basically the link is good, the object exists, but no one has permissions to see it, even users operating as full unlimited admin.

So as an admin, I can create a group, I can edit the group details, but I cannot click on the group name and open the linked page from unlimited accounts.

  • Does this occur when logged as an Orion Admin? is there a node in the groups that's in all the groups? 

  • I've seen this behavior if there are orphaned limitations present in the DB. If you run an active diagnostics or go to the My Orion Deployment -> Deployment Health there should be a warning if they exist. It will also tell you how to remediate it. Another remediation item you can do is to try and clear the Information Service Subscriptions, this has regularly resolved weird issues like this for me.

  • I will have to see if I can get clearance access to the admin account, I'm in cybersecurity and anonymous admin accounts are big risks, and will trigger an event that my manager's manager has to answer to...  So is this important info worth the notifications and supervision this will require?  if this is required for troubleshooting I will do it...  

    To your second question, I created 50 geographical groups, so I know for a fact that there are no nodes in all groups.  Naming conventions include the geographical group id in the node name, so picking nodes for a group is extremely easy and accurate.

  • Take a look at this thwack post 

    Cannot drill into any groups - Account Limitation Error - Forum - Network Performance Monitor (NPM) - THWACK (solarwinds.com)

    -- see if there are any limitations to the permissions on the group view as stated below.

    I forgot to follow up.  Someone was working on creating views and changing the permissions on the main "Group" view.  

  • Yes, I have an orphaned limitation id=4.  I put in a change request, and talked to the dba, looks like I will have to wait at least a week for the approval of the cr, so I'll update this thread and verify the answer then.

  • Recommended to test with the Admin account, and this options will apply for the actual versions 2020.2.X

    Next create a group , with one or 2 nodes that you know that you can see

    Once is created, Go to Settings > All Settings > Manage Groups > Select the square and click the expand, and you should see the 2 new elements for your group.

    Next stand over the group name > Right Click> Copy Link address (example http://localhost/Orion/NetPerfMon/ContainerDetails.aspx?NetObject=C:24),and open another tab , and you should have access.

    Other option to access the group is to open the Dashboard> home summary, or Dashboard Home groups 

    And if issue persists, and an error is presented, usually the error will be under the Logs C:\ProgramData\Solarwinds\Logs\Orion\OrionWeb.log (at the bottom of the file as an ERROR, and check the timestamp. 

    And consult with SW support.

    Let us know if it helps.