<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Menu vs. Authorization roles in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/menu-vs-authorization-roles/m-p/5697723#M1294408</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you want to create two roles one with just the menu and other with just the authorizations?&lt;/P&gt;&lt;P&gt;Just out of curiosity, why do you want to do that? Itu2019s going to be quite a mess during upgrades and also role Changes are going to be painful.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 10 Jun 2009 17:16:29 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2009-06-10T17:16:29Z</dc:date>
    <item>
      <title>Menu vs. Authorization roles</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/menu-vs-authorization-roles/m-p/5697722#M1294407</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear all, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am checking the possibility to separate roles in order I have in one role a menu structure and another associated role for the authorizations. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I found out 2 standard SAP roles having something similar &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SAP_AUDITOR_BA_FI_APMD &lt;/P&gt;&lt;P&gt;SAP_AUDITOR_BA_FI_APMD_A &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Checking SAP_AUDITOR_BA_FI_APMD I realize here is a menu structure with "transactions" inside but on the authorization tab there is nothing. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How could do that if I would like to create my own roles? I mean when I add a transaction on the menu the authorization part will be updated automatically. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will appreciate any suggestion to do that. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;P&gt;FedeX&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Jun 2009 17:03:29 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/menu-vs-authorization-roles/m-p/5697722#M1294407</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-06-10T17:03:29Z</dc:date>
    </item>
    <item>
      <title>Re: Menu vs. Authorization roles</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/menu-vs-authorization-roles/m-p/5697723#M1294408</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you want to create two roles one with just the menu and other with just the authorizations?&lt;/P&gt;&lt;P&gt;Just out of curiosity, why do you want to do that? Itu2019s going to be quite a mess during upgrades and also role Changes are going to be painful.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Jun 2009 17:16:29 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/menu-vs-authorization-roles/m-p/5697723#M1294408</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-06-10T17:16:29Z</dc:date>
    </item>
    <item>
      <title>Re: Menu vs. Authorization roles</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/menu-vs-authorization-roles/m-p/5697724#M1294409</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is the concept of the AIS (Audit Information System).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The old report tree (transaction SECR) was not enough (people click on things they can see...).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The bugger is that auditors generally have audit check-sheets with "start report xxx from SA38" and "Check table xxxx from SE16" all over the place...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The AIS gives you SAP default menus to that information and you can add your own by copying them into your namespace. The real access is the authorization role though, as the user might be able to break out of the menu in some transactions - or generally via the ability to execute objects from the menu where they can control the object name.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It works for such things as the AIS, but is not scalable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your other options are SA38, SE16, etc...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Jun 2009 20:09:38 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/menu-vs-authorization-roles/m-p/5697724#M1294409</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-06-10T20:09:38Z</dc:date>
    </item>
    <item>
      <title>Re: Menu vs. Authorization roles</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/menu-vs-authorization-roles/m-p/5697725#M1294410</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My personal opinion is, this is a stupid idea to use this design. If we return back to this concept then we are going to ignore the facility provided to us by SAP introducing Profile Generator.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Dipanjan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Jun 2009 20:53:45 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/menu-vs-authorization-roles/m-p/5697725#M1294410</guid>
      <dc:creator>sdipanjan</dc:creator>
      <dc:date>2009-06-10T20:53:45Z</dc:date>
    </item>
    <item>
      <title>Re: Menu vs. Authorization roles</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/menu-vs-authorization-roles/m-p/5697726#M1294411</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Note that the PFCG also now also offers "Authorization Defaults", which is basically the same thing, but within the same single role. This is a very good thing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This gives you the option of pulling proposals from SU24 without them being visible (or executable...) via the menu navigation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I agree with you that it is ideal to derive the authority from the menu tab (whether visible or not) and build roles at a higher level, and less of them too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But try explain that to an auditor who wants to run a report in his check-list?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually, I heard auditors recently recommending composite roles for this reason to reduce the access of the end users to less profiles... &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately they turn up on a Monday morning without invitation and want access... It is more secure to hash up a menu for them and know what access they have behind it (test and transport that one!) than dish out SA33 etc and SE16 etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If they are IT auditors (as is often the case) then they will want to display some development objects. Forget about S_TCODE from that point onwards.... use the authorizations role values.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Jun 2009 21:09:58 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/menu-vs-authorization-roles/m-p/5697726#M1294411</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-06-10T21:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: Menu vs. Authorization roles</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/menu-vs-authorization-roles/m-p/5697727#M1294412</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks guys for your remarks and comments. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to understand only technically speaking how can I reproduce something that SAP  already did in the case of these 2 standard roles &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SAP_AUDITOR_BA_FI_APMD &lt;/P&gt;&lt;P&gt;SAP_AUDITOR_BA_FI_APMD_A &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The reason or if this a good or a bad thing is something that I have to decide for my specific scenario that it is complicated to clarify here. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was able to do something similar for composite role level, but to a single role level I am not allow to add standard transactions via PFCG and remove them later from the authorizations. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the end I try to create a role that only have the menu part but nothing in the authorization part similar to SAP_AUDITOR_BA_FI_APMD &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have some idea how can I do that , I will appreciate it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;/P&gt;&lt;P&gt;FedeX&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jun 2009 08:37:03 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/menu-vs-authorization-roles/m-p/5697727#M1294412</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-06-11T08:37:03Z</dc:date>
    </item>
    <item>
      <title>Re: Menu vs. Authorization roles</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/menu-vs-authorization-roles/m-p/5697728#M1294413</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; If you have some idea how can I do that , I will appreciate it. &lt;/P&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;How about:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;build the menu role by filling the menu but do not go to the authorizations tab.&lt;/P&gt;&lt;P&gt;save the role and copy it for the role with authorizations.&lt;/P&gt;&lt;P&gt;go into the copy and edit and generate the authorizations.&lt;/P&gt;&lt;P&gt;delete the menu from the copy and save.&lt;/P&gt;&lt;P&gt;go to the authorizations tab of the copy, expert mode, edit old status.&lt;/P&gt;&lt;P&gt;generate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jurjen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jun 2009 08:43:38 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/menu-vs-authorization-roles/m-p/5697728#M1294413</guid>
      <dc:creator>jurjen_heeck</dc:creator>
      <dc:date>2009-06-11T08:43:38Z</dc:date>
    </item>
    <item>
      <title>Re: Menu vs. Authorization roles</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/menu-vs-authorization-roles/m-p/5697729#M1294414</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; In the end I try to create a role that only have the menu part but nothing in the authorization part similar to SAP_AUDITOR_BA_FI_APMD &lt;/P&gt;&lt;P&gt;I dont understand where you are stuck - it is exactly as you have described. See also Jurjen's suggestion on using the one to build the other in the beginning.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One role with the menu only and more flexible access to add / remove objects to it. Another with the authorizations only and less flexibility to change. No connection between the two, except that they are assigned to the same user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jun 2009 12:16:08 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/menu-vs-authorization-roles/m-p/5697729#M1294414</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-06-11T12:16:08Z</dc:date>
    </item>
  </channel>
</rss>

