Reassign the External Content Connectors Service Account user to the global domain
Summarize
Summary of Reassign the External Content Connectors Service Account user to the global domain
To resolve issues with user permissions in instances with domain separation, it is crucial to reassign the External Content Connectors Service Account user to the global domain. This ensures that user permission crawls can correctly map permissions across all domains.
Show less
Key Features
- User Permission Crawls: The External Content Connectors Service Account is responsible for mapping source system user and group permissions to instance users.
- Domain Configuration: Assigning the Service Account user to the global domain allows it to correctly map permissions for users across various domains.
Key Outcomes
By reassigning the External Content Connectors Service Account user to the global domain, you will:
- Enable all instance users, regardless of their assigned domain, to search private content indexed by external content connectors.
- Ensure proper mapping of source system user and group permissions for all users across the instance.
Procedure
- Navigate to All > User Administration > Users.
- Open the user record with ID xcc-connector-service-account and the name External Content Connectors Service Account.
- Configure the user form layout to display the Managed domain, Domain, and Domain Path fields.
- Select the Managed domain option.
- Set the Domain field value to global (default value).
- Set the Domain Path field value to / (default value).
- Select Update.
- Rerun user permission crawls for the affected external content connectors to update user permission mappings.
Fix issues with missing user permissions for users on your instance by reassigning the External Content Connectors Service Account user to the global domain.
Symptom
On an instance with domain separation configured, if you assign the External Content Connectors Service Account user to a domain other than the global domain, external content connector user permission crawls can only map source system user and group permissions correctly for instance users assigned to the same domain. Instance users assigned to other domains are unable to search private content indexed by your external content connectors.
Cause
The External Content Connectors application includes an External Content Connectors Service Account user. When you run user permission crawls for your external content connectors, this user account assigns the retrieved source system user and group permissions to users on your instance.
When the External Content Connectors Service Account user is assigned to a domain other than the global domain, it can only map source system user and group permissions to instance users in its own domain. Instance users assigned to any other domain don't get correctly mapped source system user and group permissions and can't search private content retrieved by your external content connectors.
As an example, suppose you have an instance with domain separation configured where you assign the External Content Connectors Service Account user to the PKD/BR 1.0/VK domain. With this configuration, external content connector user permission crawls can only map source system user and group permissions to your instance users who are assigned to the same PKD/BR 1.0/VK domain. Instance users assigned to any other domain don't get source system user and group permissions mapped correctly and can't search private content retrieved by your external content connectors.