Can't access My Devices Portal - Don't have permissions

Just upgraded from ML/Server app with Profile Manager to Mavericks and upgraded Server App to 3.0.1. Profile manager portal is wirking fine and all data are migrated. When trying to access Profile Manager My Devices Portal, we have the following error message after trying to log under Safari:


You do not have permission to access the page you were looking for.

Contact your system administrator.


We are trying to log with an Admin local user on the Mac. It was working fine under Server version 2.


Any hints on what's need to be done?

Posted on Nov 25, 2013 8:57 AM

Reply
6 replies

Nov 26, 2013 4:30 AM in response to Opportun

Just tested Profile Manager 3 on my own server and I have the same error with a brand new user.


In the Profile Manager Log, I have:


[93192] [2013/11/25 20:37:27.572] I: Processing AuthenticationController#device_callback (for XX.XX.XX.XX at 2013-11-25 20:37:27) [GET]

[93192] [2013/11/25 20:37:27.827] I: Redirected to https://mydomain.com/mydevices/

[93192] [2013/11/25 20:37:27.830] I: Completed in 257ms (DB: 55) | 302 Found [https://mydomain.com/authentication/device_callback?auth_token=[FILTERED]c927f-4355-401f-b45d-1d5113719401]

[93193] [2013/11/25 20:37:27.931] I: Processing DeviceController#start_ota (for XX.XX.XX.XX at 2013-11-25 20:37:27) [GET]

[93193] [2013/11/25 20:37:28.258] E: The logged in user is not in the devicemgr access group ({"succeeded"=>"true", "longName"=>"Test2", "uid"=> »XXXXXXXXXXXXX », "generated_uid"=> »XXXXXXXXXXXXXXXXX », "shortName"=>"test2", :authed_at=>1385429847, :auth_token=[FILTERED]> »XXXXXXXXXXXXX »})

[93193] [2013/11/25 20:37:28.258] I: Rendering 403

[93193] [2013/11/25 20:37:28.259] I: Filter chain halted as [:verify_user_access] rendered_or_redirected.

[93193] [2013/11/25 20:37:28.260] I: Completed in 329ms (View: 1, DB: 6) | 200 OK [https://mydomain.com/device/start_ota]



So it seems that all my users (old ones and new ones) are not allowed to access the My Devices pages.

Nov 26, 2013 11:24 AM in response to Opportun

In fact, this is the solution that worked for me:


consiglieri_swe


This solved my questionRe: Profilemanager - Do not have permission to access page


2013-11-14 02:38 (in response to consiglieri_swe)


Seems the issue is solved.

I first ran

"/Applications/Server.app/Contents/ServerRoot/usr/share/devicemgr/backend/wipeDB .sh" to reset ProfileManager which didnt sole the problem.

I then uninstalled the Server app and reinstalled it. Lo and behold it now seems to work.

Nov 27, 2013 10:32 AM in response to Opportun

It worked! Thank you so much!


However, initially it did not work for me and in fact I had a few errors after I had reinstalled Server that made me think this solution made things worse. I had to perform the procedure a few times making sure that I got everything working properly. It seemed that shutting down the services first then quitting server seemed to be a very important step for me. If anybody else experience is the same thing I would suggest that you follow the procedure listed by Opportun exactly.

Feb 24, 2014 7:03 AM in response to Opportun

Actually the fix is quite simple, you have to activate the Device Management in the Profilemanager which installs some stuff and also adds the Group (com.apple.access_devicemanagement) which is required to manage the devices.


If you start Workgroup Manager and look at the groups before you enable Device Management the group is missing (you have to enable System Records under View --> Show System Records). After the setup process the groups is available and you can add users to it.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Can't access My Devices Portal - Don't have permissions

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.