Showing posts with label Delegation. Show all posts
Showing posts with label Delegation. Show all posts

Tuesday, March 19, 2019

Delegation in Project Online: what's wrong??

4 years ago, I wrote an article about the delegation limitations and it has reached a great number of views. I guess this is because the delegation feature is (I should say was) intensively used by administrator for daily support and security model use case testing.

However back to May 2016, we noticed a strange behavior while running delegation sessions. Starting a delegation session for a user with limited access (team member for example), we were seeing more projects than we were supposed to. As usual, Brian Smith reacted promptly and published an article to explain this unexpected behavior. I didn't update my initial article at this time, and I now feel like I should write a short post about it since I still see this question on the TechNet forums and from some on my customers, so I think that this change in the delegation feature is still not completely known and well understood.

Basically you'll see this unexpected behavior if the delegate user is a global administrator (O365 admin or Site Collection admin). Here the reason of the change, with Brian's words: "The reason for the change is that in Project Online customers were accidentally locking themselves out of PWA by removing all their PWA administrators – and then the only way to make a user an admin again was to open a support call". To avoid this frustrating situation where the admin is locked into a delegation session, this restriction was created.

The workaround is unfortunately not magic: you simply have to use a session (not delegated) of a user to test the security model. 

Share this article :

Friday, April 24, 2015

Delegation: what are the limitations?

Hi Project Server addicts!

Today I was willing to talk about the delegation. This feature was introduced with the 2010 version, replacing (more or less) the surrogate feature in 2007 version. Project Server 2013 reproduces exactly the same functionnality than in Project Server 2010. The delegation is a quite nice improvment, thus it has been blogged a few times here, here and here. So I won't reinvent the wheek since my fellow Project experts did a really good job with their blogs.

Too bad, what am I going to blog about??

After working on few Project Server deployments where the delegation was heavily used, I found out that there were a few limitations which could sometimes be painful. Here is a good subject to blog about! To understand the big picture, one must understand that the delegation applies to the PWA site. Thus all limitations below are a direct consequence, meaning that all that is outside the PWA site scope will not be included in the delegation influence.

1- BI Center
As you might know, the BI Center is a specific site beside from PWA, so the BI Center is not included in the delegation scope, preventing users from accessing by delegation reports they should not see.

2- Project sites
Similarly, the project sites are on the SharePoint side of the Force thus the delegation will not permit a user to access project sites of a delegate fellow colleague.

3- MS Project Pro
The Project client is a side application which is related to Project Server when opening, saving, publishing, creating the project team. So you cannot connect to PWA using a delegation session.

4- Resources with no valid account
Finally one of the heaviest limitation I encountered concerns the delegation for external resources, for example for consultants or customers timesheets. Those resources usually do not have a PWA access with the appropriate CAL, thus they are just created as resources with no valid account. You will see that the delegation feature does not work for resources which are not also users. Prasanna wrote a blog about it.
Figure 1: delegation for a resource with no valid account impossible to create

Finally I would like to end this blog by a nice app I just found. This app easies the PWA navigation through additional buttons in the ribbons. One of them allows navigating from the delegate creation page to the acting as a delegate page.
Figure 2: "act as delegate" new button in the "manage delegates" page


Will Project 16 provide some improvments about those limiations? We'll know it soon hopefully!

EDIT 2015-04-27: as Karen suggested in her comment, the PDP security is also out of the delegation scope.

Share this article :

Thursday, July 24, 2014

Delegation in 2013 - Don't Misundurstand the Project Pro Message

One interesting feature Project Server has introduced in 2010 is the capability to substitute yourself to someone else using the delegation.
By the way, you cannot use it while in SharePoint Permission mode

One of the drawback is that this is only working in PWA interface (except for the Business Intelligence part).
Consequently, Project Professional will not allow you to connect to a server while you have an ongoing delegation session.
So now, let's imagine you're in a delegation session in the name of this famous John.

Then, you try to open your MS Project Pro connected to your server and, Surprise, a misleading message appears.

It's not that wrong message as you do have inadequate permissions but not really explicit!

So, next time a user call you with this kind of message, make sure they are not using the delegation in the meantime before trying to check network or permissions to the server!

Regards!
Share this article :