<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User Level Authorization in Position Based Security in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/user-level-authorization-in-position-based-security/m-p/5686446#M1292311</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Venkat,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try restricting on P_PERNR, i don't have an HR system to check in, though i recall, P_PERNR should be able to restrict users on their own personnel numbers for the expense infotypes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers !!&lt;/P&gt;&lt;P&gt;Zaheer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 04 Jun 2009 05:55:24 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2009-06-04T05:55:24Z</dc:date>
    <item>
      <title>User Level Authorization in Position Based Security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/user-level-authorization-in-position-based-security/m-p/5686443#M1292308</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Geeks,&lt;/P&gt;&lt;P&gt;I'm facing a problem in restricting a user accessing from another users data.&lt;/P&gt;&lt;P&gt;Let me give you a picture of my issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have assigned a position based role to a Position XXXXX, while XXXX is accessing his data, he is also able to see the data of User YYYYY, but as per my client requirement, User XXXXX can only see the data of his own, not other users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please let me know how to restrict this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;removed_by_moderator&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Venkat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: Julius Bussche on Jun 4, 2009 8:44 AM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jun 2009 04:27:59 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/user-level-authorization-in-position-based-security/m-p/5686443#M1292308</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-06-04T04:27:59Z</dc:date>
    </item>
    <item>
      <title>Re: User Level Authorization in Position Based Security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/user-level-authorization-in-position-based-security/m-p/5686444#M1292309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Venkat, can you be more specific ?&lt;/P&gt;&lt;P&gt;Roles may be assigned to position but that itself wouldn't restrict the access, it is the authorization within the role that gives access to data.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers !!&lt;/P&gt;&lt;P&gt;Zaheer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jun 2009 04:38:02 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/user-level-authorization-in-position-based-security/m-p/5686444#M1292309</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-06-04T04:38:02Z</dc:date>
    </item>
    <item>
      <title>Re: User Level Authorization in Position Based Security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/user-level-authorization-in-position-based-security/m-p/5686445#M1292310</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Zaheer, thanks for the quick reply, &lt;/P&gt;&lt;P&gt;here it goes. my client implemented SAP TV, &amp;amp; user X logs his expenses, while other users do. &lt;/P&gt;&lt;P&gt;but when User X is accessing his data (Expenses) he is also able to see the expenses of User Y.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have used the Auth Obj, F_TRAVL_RW, TV_CREAT, TV_EVSIM, also assigned a T.Code KSB1/KOB1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if u need more details.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Venkat&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jun 2009 04:58:26 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/user-level-authorization-in-position-based-security/m-p/5686445#M1292310</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-06-04T04:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: User Level Authorization in Position Based Security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/user-level-authorization-in-position-based-security/m-p/5686446#M1292311</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Venkat,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try restricting on P_PERNR, i don't have an HR system to check in, though i recall, P_PERNR should be able to restrict users on their own personnel numbers for the expense infotypes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers !!&lt;/P&gt;&lt;P&gt;Zaheer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jun 2009 05:55:24 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/user-level-authorization-in-position-based-security/m-p/5686446#M1292311</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-06-04T05:55:24Z</dc:date>
    </item>
    <item>
      <title>Re: User Level Authorization in Position Based Security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/user-level-authorization-in-position-based-security/m-p/5686447#M1292312</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Venkata, are you using Structural Authorization?  You may want to look in to assigning structural authorization using PD Profiles. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maintain Evaluation Path&lt;/P&gt;&lt;P&gt;Maintain Structural profiles&lt;/P&gt;&lt;P&gt; - rh_get_manager_assginment&lt;/P&gt;&lt;P&gt; - rh_get_org_assignment&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"while XXXX is accessing his data, he is also able to see the data of User YYYYY, but as per my client requirement, User XXXXX can only see the data of his own, not other users."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sapsec-HB&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jun 2009 14:33:44 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/user-level-authorization-in-position-based-security/m-p/5686447#M1292312</guid>
      <dc:creator>Hank</dc:creator>
      <dc:date>2009-06-04T14:33:44Z</dc:date>
    </item>
    <item>
      <title>Re: User Level Authorization in Position Based Security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/user-level-authorization-in-position-based-security/m-p/5686448#M1292313</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Venkat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If user X is able to view data for another user it is probably the P_PERNR object. Try Interpretation of assigned personnel number (I) which allows users to view data for his own records. Structural auth will control the Org assignment however accessing Infotypes or data will be controlled by P_ORGIN /P_PERNR. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;santosh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jun 2009 15:23:43 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/user-level-authorization-in-position-based-security/m-p/5686448#M1292313</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-06-04T15:23:43Z</dc:date>
    </item>
    <item>
      <title>Re: User Level Authorization in Position Based Security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/user-level-authorization-in-position-based-security/m-p/5686449#M1292314</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; If user X is able to view data for another user it is probably the P_PERNR object. &lt;/P&gt;&lt;P&gt;That is the exact opposite of what P_PERNR does... &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Probably P_ORGIN is proving the access via some other role assignment, or indirectly via a reference user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jun 2009 16:09:14 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/user-level-authorization-in-position-based-security/m-p/5686449#M1292314</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-06-04T16:09:14Z</dc:date>
    </item>
    <item>
      <title>Re: User Level Authorization in Position Based Security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/user-level-authorization-in-position-based-security/m-p/5686450#M1292315</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks Julius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I meant to convey P_PERNR controls to update persons own data. like user cannot update his own basic pay. you are correct it is P_ORGIN ...my bad on the P_PERNR &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;santosh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jun 2009 16:19:03 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/user-level-authorization-in-position-based-security/m-p/5686450#M1292315</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-06-04T16:19:03Z</dc:date>
    </item>
    <item>
      <title>Re: User Level Authorization in Position Based Security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/user-level-authorization-in-position-based-security/m-p/5686451#M1292316</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is my understanding... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;p_orgin&lt;/STRONG&gt; providing access to infotyes with this object automatically gives access to both own user's reocord and the other employee records.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;p_pernr&lt;/STRONG&gt; when this object is present, including infotypes in this object allows you to control access to own record &lt;U&gt;only&lt;/U&gt;(I), or other employee records &lt;U&gt;only&lt;/U&gt;(E) excuding own. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sapsec-HB&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jun 2009 16:37:06 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/user-level-authorization-in-position-based-security/m-p/5686451#M1292316</guid>
      <dc:creator>Hank</dc:creator>
      <dc:date>2009-06-04T16:37:06Z</dc:date>
    </item>
    <item>
      <title>Re: User Level Authorization in Position Based Security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/user-level-authorization-in-position-based-security/m-p/5686452#M1292317</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; p_pernr when this object is present, including infotypes in this object allows you to control access to own record &lt;U&gt;only&lt;/U&gt;(I), or other employee records &lt;U&gt;only&lt;/U&gt;(E) excuding own. &lt;/P&gt;&lt;P&gt;Stated like that it could still be misleading. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;E does not grant access to other employees records. It only means that if the user already has access to other employees records (via P_ORGIN...), then this authorization will &lt;STRONG&gt;exclude&lt;/STRONG&gt; their own personel number from that authorization, even although they have the access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This can be usefull, for example to prevent the HR department from changing their own basic pay without stopping them from giving you a raise or a bonus... &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jun 2009 16:49:32 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/user-level-authorization-in-position-based-security/m-p/5686452#M1292317</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-06-04T16:49:32Z</dc:date>
    </item>
    <item>
      <title>Re: User Level Authorization in Position Based Security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/user-level-authorization-in-position-based-security/m-p/5686453#M1292318</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks a bunch, Guyz, will mark it solved, once I try with the solution given.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Venkat&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jun 2009 16:51:55 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/user-level-authorization-in-position-based-security/m-p/5686453#M1292318</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-06-04T16:51:55Z</dc:date>
    </item>
  </channel>
</rss>

