After our IT department completed an LDAP group synchronization update last Friday, several users lost access to the CAD viewer in Windchill 12.0 CPS05. These users can still log into Windchill and see their assigned parts and assemblies, but when they try to open any CAD file in the viewer, they get an “Access Denied” error.
The affected users are primarily in our design review team who need viewer access to approve engineering changes. Before the LDAP sync, everything worked perfectly. I checked their user profiles and their LDAP group memberships appear correct in Active Directory. The LDAP sync logs show successful synchronization with no errors.
I’m concerned this might be related to how LDAP groups are mapped to Windchill roles, or possibly access control rules that govern CAD viewer permissions. Has anyone experienced similar issues where LDAP group changes break viewer access specifically? Design reviews are currently blocked, and we need to restore access quickly.
Let me provide a comprehensive solution covering LDAP group mapping, role assignment validation, and access control rules.
LDAP Group Mapping Fix:
The root cause is that your LDAP group distinguished names changed during the organizational unit restructuring, breaking Windchill’s group-to-role mappings. Here’s the complete fix process:
Identify Changed Group DNs: First, document the old vs new DN paths for all affected groups. For example:
Update LDAP Directory Service Configuration: Log into Windchill as an administrator and navigate to Site > Utilities > Directory Service Management. For each affected LDAP directory:
Edit the directory service entry
Update the Group Search Base to reflect the new OU structure
If you had specific group filters, update them to match new DN patterns
Save the configuration changes
Update External Group Mappings: Go to Site > Group Management and for each external LDAP group:
Search for the group by its old DN (it will show as not found or orphaned)
Delete the old group reference
Add the group again using its new DN path
This re-establishes the link between LDAP and Windchill
Re-sync LDAP Groups: After updating mappings, trigger a full LDAP synchronization:
Navigate to Site > Utilities > Scheduled Jobs
Find the LDAP User Synchronization job
Run it manually with “Force Full Sync” option enabled
Monitor the sync logs to confirm groups are discovered with new DNs
Role Assignment Validation:
Once LDAP groups are remapped, validate that Windchill roles are correctly assigned:
Check Role Definitions: Navigate to Site > Organization Templates > Roles. For each role that should grant CAD viewer access (typically “Design Reviewer” or “Viewer” roles):
Click on the role to view its members
Verify that LDAP groups with new DNs are listed as members
If groups are missing, manually add them using the new DN
Verify Team Role Assignments: For product and library contexts where design reviews occur:
Go to the specific product or project
Navigate to Structure > Team Management
Check that design review team roles include users from the remapped LDAP groups
If team roles are empty or missing members, re-add the LDAP groups
Validate User Role Inheritance: For affected users, verify their effective roles:
Go to Site > User Management
Select an affected user and view their profile
Check the “Roles” tab to see all assigned roles (direct and inherited)
Confirm they have roles that include viewer permissions
If roles are missing, the group mapping hasn’t propagated correctly
Force Role Re-evaluation: Sometimes Windchill caches role assignments. Force re-evaluation by:
Logging out affected users (or having them log out)
Clearing Windchill’s security cache (restart method server if necessary)
Having users log back in to refresh their role assignments
Access Control Rules Update:
LDAP group DN changes can break access control policies that explicitly reference groups:
Audit Access Control Templates: Navigate to Site > Access Control Templates. For templates used on CAD documents:
Review each template’s access control entries
Look for entries that reference LDAP groups by DN
Update any entries using old DNs to reference new DNs
Review policies for Part, CAD Document, and EPM Document types
Look for read/view permissions tied to specific LDAP groups
Update group references to use new DNs
Apply policy changes
Fix Context-Specific Rules: For product and project contexts:
Navigate to each product/project where design reviews occur
Check context-specific access control rules
Update any rules referencing old LDAP group DNs
Verify rules grant “Read” permission for CAD documents
CAD Viewer Specific Permissions: The CAD viewer requires specific ACL entries:
Users need “Read” permission on CAD documents
Users need “Read” permission on associated visualization representations
Check that access control rules grant both permissions
Verify no “Deny” rules are blocking viewer access
Propagate Access Control Changes: After updating templates and policies:
Navigate to the root product/library container
Use “Apply Access Control” utility to propagate changes
Select “Recursive” to update all child objects
This ensures existing CAD documents inherit updated rules
Verification Steps:
After implementing these fixes:
Test with an affected user account:
Log in as the user
Navigate to a CAD document in a design review workflow
Attempt to open the CAD viewer
Verify viewer loads without “Access Denied” error
Check viewer license allocation:
Go to Site > License Management
Verify affected users have viewer licenses assigned
If licenses are missing, check if license assignment rules reference old LDAP groups
Test design review workflow:
Create a test change request with CAD documents
Assign design review task to affected users
Verify they can open and markup CAD files in the viewer
Monitor for recurring issues:
Check method server logs for access control errors
Review LDAP sync logs to ensure groups sync correctly on schedule
Document the new DN structure for future reference
Prevention for Future LDAP Changes:
Use LDAP group names instead of DNs where possible in Windchill configurations
Coordinate with IT before AD restructuring to update Windchill mappings proactively
Maintain a test environment where LDAP changes can be validated before production
Document all LDAP group to Windchill role mappings for quick reference
Create a runbook for LDAP DN change procedures
This comprehensive approach addresses the group mapping, role assignment, and access control aspects of your issue and should restore CAD viewer access for your design review team.
This draft is based on general Windchill knowledge. It has not been verified against your specific version and environment. Practitioners: verify the steps and share your experience below.
This is likely a role assignment issue. When LDAP groups sync, Windchill re-evaluates role memberships based on group mappings. If the mapping between LDAP groups and Windchill roles changed or wasn’t preserved during sync, users would lose their viewer permissions even though their LDAP groups are correct.
Check if the LDAP group distinguished names changed during the sync. Sometimes organizational unit restructuring in AD changes the DN path, and Windchill’s group mapping uses exact DN matching. Even if users are in the same group name, a different DN breaks the mapping to Windchill roles.
Confirmed this resolves the access denied errors — updating the LDAP group DNs in Windchill’s directory service configuration after our OU restructure immediately restored CAD viewer permissions for design reviewers.
I compared the LDAP group DNs before and after sync using our AD backup. You’re right - the OU structure was reorganized and several groups now have different DN paths. The group names are identical, but the full distinguished names changed. How do I update the Windchill group mappings to reflect the new DNs?
You’ll need to update the LDAP group mappings in Windchill’s directory services configuration. Go to Site > Utilities > LDAP Configuration and update the group search base and group mappings to use the new DN paths. After updating, run a manual group sync to refresh the role assignments.
Also verify the access control rules on your CAD documents and parts. Sometimes LDAP sync triggers a re-evaluation of access policies, and if the policies reference specific groups by DN, they’ll fail when the DN changes. You might need to update access control templates to use the new group references.
Don’t forget to check the CAD viewer license assignments too. Some viewer configurations tie license allocation to specific LDAP groups. If those group mappings broke, users might lose their viewer license assignment even if they have the right permissions. Check License Management to see if affected users still have viewer licenses assigned.