CAD viewer access denied for users after LDAP group sync in design review workflows

After our IT department completed an LDAP group synchronization update last Friday, several users lost access to the CAD viewer in Windchill 12.0 CPS05. These users can still log into Windchill and see their assigned parts and assemblies, but when they try to open any CAD file in the viewer, they get an “Access Denied” error.

The affected users are primarily in our design review team who need viewer access to approve engineering changes. Before the LDAP sync, everything worked perfectly. I checked their user profiles and their LDAP group memberships appear correct in Active Directory. The LDAP sync logs show successful synchronization with no errors.

I’m concerned this might be related to how LDAP groups are mapped to Windchill roles, or possibly access control rules that govern CAD viewer permissions. Has anyone experienced similar issues where LDAP group changes break viewer access specifically? Design reviews are currently blocked, and we need to restore access quickly.

Let me provide a comprehensive solution covering LDAP group mapping, role assignment validation, and access control rules.

LDAP Group Mapping Fix:

The root cause is that your LDAP group distinguished names changed during the organizational unit restructuring, breaking Windchill’s group-to-role mappings. Here’s the complete fix process:

  1. Identify Changed Group DNs: First, document the old vs new DN paths for all affected groups. For example:

    • Old: `CN=DesignReviewers,OU=Engineering,DC=company,DC=com
    • New: `CN=DesignReviewers,OU=Design,OU=Engineering,DC=company,DC=com
  2. Update LDAP Directory Service Configuration: Log into Windchill as an administrator and navigate to Site > Utilities > Directory Service Management. For each affected LDAP directory:

    • Edit the directory service entry
    • Update the Group Search Base to reflect the new OU structure
    • If you had specific group filters, update them to match new DN patterns
    • Save the configuration changes
  3. Update External Group Mappings: Go to Site > Group Management and for each external LDAP group:

    • Search for the group by its old DN (it will show as not found or orphaned)
    • Delete the old group reference
    • Add the group again using its new DN path
    • This re-establishes the link between LDAP and Windchill
  4. Re-sync LDAP Groups: After updating mappings, trigger a full LDAP synchronization:

    • Navigate to Site > Utilities > Scheduled Jobs
    • Find the LDAP User Synchronization job
    • Run it manually with “Force Full Sync” option enabled
    • Monitor the sync logs to confirm groups are discovered with new DNs

Role Assignment Validation:

Once LDAP groups are remapped, validate that Windchill roles are correctly assigned:

  1. Check Role Definitions: Navigate to Site > Organization Templates > Roles. For each role that should grant CAD viewer access (typically “Design Reviewer” or “Viewer” roles):

    • Click on the role to view its members
    • Verify that LDAP groups with new DNs are listed as members
    • If groups are missing, manually add them using the new DN
  2. Verify Team Role Assignments: For product and library contexts where design reviews occur:

    • Go to the specific product or project
    • Navigate to Structure > Team Management
    • Check that design review team roles include users from the remapped LDAP groups
    • If team roles are empty or missing members, re-add the LDAP groups
  3. Validate User Role Inheritance: For affected users, verify their effective roles:

    • Go to Site > User Management
    • Select an affected user and view their profile
    • Check the “Roles” tab to see all assigned roles (direct and inherited)
    • Confirm they have roles that include viewer permissions
    • If roles are missing, the group mapping hasn’t propagated correctly
  4. Force Role Re-evaluation: Sometimes Windchill caches role assignments. Force re-evaluation by:

    • Logging out affected users (or having them log out)
    • Clearing Windchill’s security cache (restart method server if necessary)
    • Having users log back in to refresh their role assignments

Access Control Rules Update:

LDAP group DN changes can break access control policies that explicitly reference groups:

  1. Audit Access Control Templates: Navigate to Site > Access Control Templates. For templates used on CAD documents:

    • Review each template’s access control entries
    • Look for entries that reference LDAP groups by DN
    • Update any entries using old DNs to reference new DNs
    • Save template changes
  2. Update Domain-Level Policies: Check domain-level access policies:

    • Go to Site > Policies
    • Review policies for Part, CAD Document, and EPM Document types
    • Look for read/view permissions tied to specific LDAP groups
    • Update group references to use new DNs
    • Apply policy changes
  3. Fix Context-Specific Rules: For product and project contexts:

    • Navigate to each product/project where design reviews occur
    • Check context-specific access control rules
    • Update any rules referencing old LDAP group DNs
    • Verify rules grant “Read” permission for CAD documents
  4. CAD Viewer Specific Permissions: The CAD viewer requires specific ACL entries:

    • Users need “Read” permission on CAD documents
    • Users need “Read” permission on associated visualization representations
    • Check that access control rules grant both permissions
    • Verify no “Deny” rules are blocking viewer access
  5. Propagate Access Control Changes: After updating templates and policies:

    • Navigate to the root product/library container
    • Use “Apply Access Control” utility to propagate changes
    • Select “Recursive” to update all child objects
    • This ensures existing CAD documents inherit updated rules

Verification Steps:

After implementing these fixes:

  1. Test with an affected user account:

    • Log in as the user
    • Navigate to a CAD document in a design review workflow
    • Attempt to open the CAD viewer
    • Verify viewer loads without “Access Denied” error
  2. Check viewer license allocation:

    • Go to Site > License Management
    • Verify affected users have viewer licenses assigned
    • If licenses are missing, check if license assignment rules reference old LDAP groups
  3. Test design review workflow:

    • Create a test change request with CAD documents
    • Assign design review task to affected users
    • Verify they can open and markup CAD files in the viewer
  4. Monitor for recurring issues:

    • Check method server logs for access control errors
    • Review LDAP sync logs to ensure groups sync correctly on schedule
    • Document the new DN structure for future reference

Prevention for Future LDAP Changes:

  1. Use LDAP group names instead of DNs where possible in Windchill configurations
  2. Coordinate with IT before AD restructuring to update Windchill mappings proactively
  3. Maintain a test environment where LDAP changes can be validated before production
  4. Document all LDAP group to Windchill role mappings for quick reference
  5. Create a runbook for LDAP DN change procedures

This comprehensive approach addresses the group mapping, role assignment, and access control aspects of your issue and should restore CAD viewer access for your design review team.


This draft is based on general Windchill knowledge. It has not been verified against your specific version and environment. Practitioners: verify the steps and share your experience below.

This is likely a role assignment issue. When LDAP groups sync, Windchill re-evaluates role memberships based on group mappings. If the mapping between LDAP groups and Windchill roles changed or wasn’t preserved during sync, users would lose their viewer permissions even though their LDAP groups are correct.

Check if the LDAP group distinguished names changed during the sync. Sometimes organizational unit restructuring in AD changes the DN path, and Windchill’s group mapping uses exact DN matching. Even if users are in the same group name, a different DN breaks the mapping to Windchill roles.

Confirmed this resolves the access denied errors — updating the LDAP group DNs in Windchill’s directory service configuration after our OU restructure immediately restored CAD viewer permissions for design reviewers.

I compared the LDAP group DNs before and after sync using our AD backup. You’re right - the OU structure was reorganized and several groups now have different DN paths. The group names are identical, but the full distinguished names changed. How do I update the Windchill group mappings to reflect the new DNs?

You’ll need to update the LDAP group mappings in Windchill’s directory services configuration. Go to Site > Utilities > LDAP Configuration and update the group search base and group mappings to use the new DN paths. After updating, run a manual group sync to refresh the role assignments.

Also verify the access control rules on your CAD documents and parts. Sometimes LDAP sync triggers a re-evaluation of access policies, and if the policies reference specific groups by DN, they’ll fail when the DN changes. You might need to update access control templates to use the new group references.

Don’t forget to check the CAD viewer license assignments too. Some viewer configurations tie license allocation to specific LDAP groups. If those group mappings broke, users might lose their viewer license assignment even if they have the right permissions. Check License Management to see if affected users still have viewer licenses assigned.