WJ,
I have not personally tested the Capabilities settings in PAx, but a few considerations:
- Are the users you are trying to Deny permissions for Admin users?
- Do your users belong to more than one security group? If so, is the Capability set to Deny for all Groups they are in?
I believe Capabilities work based on the least restrictive access between the union of all the user's security groups. The easiest way to configure this for every user (other than Admins) is to set permissions for ALL groups to DENY.
Since the Capabilities exist on the Planning Analytics (TM1) server, we would expect them to apply in all user interfaces including PAx, TM1Web and PAW.
------------------------------
James Hanifin
Implementation Manager & Cross Solutions Architect
QueBIT Consulting
------------------------------