<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authorization Object Clarification in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970773#M1339200</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the version of ECC6 I have access to at the moment, S_DEVELOP is set to Check with proposal = No, so will not be pulled through in to a role.  There are no change logs for this during the time installed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 06 Aug 2009 15:32:06 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2009-08-06T15:32:06Z</dc:date>
    <item>
      <title>Authorization Object Clarification</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970761#M1339188</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have two questions regarding Authorization objects, my first question is, why we canu2019t execute any transaction if we have access to all the authorization objects that has linked to those t-codes for example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(SA38 or SE38) bringing S_Develop, S_DATASET, and S_PROGRAM if I assign all these authorization objects into the role manually I still don't have access to sa38 or se38. So how come we always say everything is control by authorization object. We always need T-codes in the role either by menu or manually.  Is that true?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My second question:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We always say don't assign S_Develop in Production, but we need to assign one general role which should have SU53 and by SAP standard SU53 bringing S_Develop authorization object which is very dangers for Production. How come SAP standard conflicting rule not to assign S_Develop in Production?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please kindly give your feedback and thoughts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: Faisal on Aug 6, 2009 3:39 PM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: Faisal on Aug 6, 2009 3:39 PM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Aug 2009 13:34:34 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970761#M1339188</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-08-06T13:34:34Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Object Clarification</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970762#M1339189</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; (SA38 or SE38) bringing S_Develop, S_DATASET, and S_PROGRAM if I assign all these authorization objects into the role manually I still don't have access to sa38 or se38. So how come we always say everything is control by authorization object. We always need T-codes in the role either by menu or manually.  Is that true?&lt;/P&gt;&lt;P&gt;Yes, the S_TCODE check is the first line of defense. This check is done for every transaction start and cannot be switched off.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; We always say don't assign S_Develop in Production, but we need to assign one general role which should have SU53 and by SAP standard SU53 bringing S_Develop authorization object which is very dangers for Production. How come SAP standard conflicting rule not to assign S_Develop in Production?&lt;/P&gt;&lt;P&gt;SU53 does not need S_DEVELOP for its normal use.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Aug 2009 13:42:48 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970762#M1339189</guid>
      <dc:creator>jurjen_heeck</dc:creator>
      <dc:date>2009-08-06T13:42:48Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Object Clarification</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970763#M1339190</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for youu2019re replied&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So we can assign S_Develop in the role without SA38 or SE38 no one can execute the transactions because we don't assign the t-codes but they will have S_Develop, is it harmful in Production? What about S_Develop through SU53 should we deactivate the S_Develop or let it go to Production because it is coming thr SU53?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Aug 2009 14:11:16 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970763#M1339190</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-08-06T14:11:16Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Object Clarification</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970764#M1339191</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Adding few points with Jurjen:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; I have two questions regarding Authorization objects, my first question is, why we canu2019t execute any transaction if we have access to all the authorization objects that has linked to those t-codes for example:&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;&amp;gt; (SA38 or SE38) bringing S_Develop, S_DATASET, and S_PROGRAM if I assign all these authorization objects into the role manually I still don't have access to sa38 or se38. So how come we always say everything is control by authorization object. We always need T-codes in the role either by menu or manually.  Is that true?&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The series of Checks while you are trying to execute some TCode/Report is like below:&lt;/P&gt;&lt;P&gt;1. Check whether the TCode is existing in the system (TSTC, TSTCT, TSTCA, TSTCP etc.) tables. If this check fails, you will get an  error message and system will not go for further checks i.e. Authorization checks against the available authorization instances in User's Buffer content.&lt;/P&gt;&lt;P&gt;2. The first level of Authorization check for any TCode is done against the Object S_TCode.&lt;/P&gt;&lt;P&gt;3. After passing through the point 2, the authorization checks for other Objects take place with an AND operator.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; My second question:&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;&amp;gt; We always say don't assign S_Develop in Production, but we need to assign one general role which should have SU53 and by SAP standard SU53 bringing S_Develop authorization object which is very dangers for Production. How come SAP standard conflicting rule not to assign S_Develop in Production?&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;&amp;gt; Please kindly give your feedback and thoughts&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SU53 doesn't require S_DEVELOP for any user action. Please go through the documentation of S_DEVELOP and available notes to understand the necessity of these critical objects.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Dipanjan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Aug 2009 14:15:55 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970764#M1339191</guid>
      <dc:creator>sdipanjan</dc:creator>
      <dc:date>2009-08-06T14:15:55Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Object Clarification</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970765#M1339192</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In which release you are working currently?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do Not assign any Object Manually in Authorization Data.... Add the Tcode (SU53) in the role menu and let Profile generator decide and pull the relevant Authorization Objects. You will not see S_DEVELOP in this case. Check the proposal for your information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Dipanjan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Aug 2009 14:24:43 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970765#M1339192</guid>
      <dc:creator>sdipanjan</dc:creator>
      <dc:date>2009-08-06T14:24:43Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Object Clarification</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970766#M1339193</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I checked it su24 you will get S_Develop when you assign SU53, that's why I was asking this question&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Aug 2009 14:49:10 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970766#M1339193</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-08-06T14:49:10Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Object Clarification</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970767#M1339194</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What version are you on?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;S_DEVELOP is not in Check Maintain or Proposal = Y status in any of the systems I have access to&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Aug 2009 14:52:15 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970767#M1339194</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-08-06T14:52:15Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Object Clarification</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970768#M1339195</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ECC 6.0  it is check/maintain for su53 for sure.  It is a new system it hasn't  been changed because we are in Relization phase no one touched it yet, I'm the only security person here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: Faisal on Aug 6, 2009 5:00 PM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Aug 2009 14:59:37 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970768#M1339195</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-08-06T14:59:37Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Object Clarification</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970769#M1339196</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sounds like someone changed your SU24 settings to include S_DEVELOP in a role for all users on the strength of SU53 being in the menu.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not a good idea...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SU53 itself is a nice example of the difference between the S_TCODE authority to start something and the authorization objects in the code to actually &lt;STRONG&gt;use&lt;/STRONG&gt; it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can turn the transaction check at tcode &lt;STRONG&gt;start&lt;/STRONG&gt; off for SU53, but depending on the authorizations of the user for the S_USER_AUT object they might only be able to see what failed, or additionally also see what they do have authority for.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;S_DEVELOP is the same. There are many ways (not only limited to transactions) via which you can enter the ABAP Workbench Navigation - but once in there the "real checks" take place. The best known examples are via the menu: System --&amp;gt; Status --&amp;gt; Navigate, and the F1 --&amp;gt; Technical Information --&amp;gt; Navigate routes. (in higher releases there is also an SE80 check).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want the user to have consistent authorizations in the system and not be subject to silly little mistakes in the menu, S_TCODE and other objects and roles they might have, then rather give them the correct authorization to &lt;STRONG&gt;use&lt;/STRONG&gt; the transaction and only in exceptional cases turn the object level checks off in SU24.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My 2 cents,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Aug 2009 15:08:37 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970769#M1339196</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-08-06T15:08:37Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Object Clarification</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970770#M1339197</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Very curious, I wonder why it is setup like that?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Aug 2009 15:10:14 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970770#M1339197</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-08-06T15:10:14Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Object Clarification</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970771#M1339198</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Beleive me no one changed it, it is standard unless there is some issue with patches when it installed.  What about your system is it check.maintain or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should I talk to my basis team about that.  I can change the su24 setting but I checked my sandbox and all the other client in sandbox and Dev all are check/maintain.   &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you say?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Aug 2009 15:22:08 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970771#M1339198</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-08-06T15:22:08Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Object Clarification</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970772#M1339199</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First check in SU22 whether some nilly added it there, and then transfered to SU24 later.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It should show up as "original" data in SU22, where the author is not 'SAP'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately in some releases the SU22 data was also delivered with the ID and not the 'SAP' anonymization which can be confusing, but that should not be the case here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Aug 2009 15:29:40 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970772#M1339199</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-08-06T15:29:40Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Object Clarification</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970773#M1339200</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the version of ECC6 I have access to at the moment, S_DEVELOP is set to Check with proposal = No, so will not be pulled through in to a role.  There are no change logs for this during the time installed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Aug 2009 15:32:06 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970773#M1339200</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-08-06T15:32:06Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Object Clarification</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970774#M1339201</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you check the SAP Proposal also? The check indicator you are viewing there is the Customer Table proposal.&lt;/P&gt;&lt;P&gt;If you check in the Application tool bar, there is a Button called "&lt;STRONG&gt;SAP Data&lt;/STRONG&gt;". Please click on that button to see the SAP proposal (entries of table USOBT and USOBX) and let us know what you are getting for S_DEVELOP as SAP Data.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Dipanjan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Aug 2009 15:32:54 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970774#M1339201</guid>
      <dc:creator>sdipanjan</dc:creator>
      <dc:date>2009-08-06T15:32:54Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Object Clarification</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970775#M1339202</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It says SAP propsl = YS and also proposal is = YS.   What you guys say?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it installation or patches? My sandbox and Dev in all clients are same.  one more thing I checked my IDES system that is the only system doesn't have YS, it has NO in the proposal.  SO IDES system is correct or whatever?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But in IDES system for the SAP propsl still = YS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: Faisal on Aug 6, 2009 5:47 PM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: Faisal on Aug 6, 2009 5:50 PM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Aug 2009 15:46:33 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970775#M1339202</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-08-06T15:46:33Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Object Clarification</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970776#M1339203</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; What you guys say?&lt;/P&gt;&lt;P&gt;Someone hacked your SU22 data...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Aug 2009 15:51:52 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970776#M1339203</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-08-06T15:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Object Clarification</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970777#M1339204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I modified su24 I changed propossal = No for the S_Develop but SAP propsl I didn't touch it its still = YS. but after I changed it it is still brigning the Object into the Role.  Can you please tell me what's wrong&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;do I have to change SAP Propsl also &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please Advice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Aug 2009 18:25:39 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970777#M1339204</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-08-06T18:25:39Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Object Clarification</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970778#M1339205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Has step 1 of SU25 been run before in these systems?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After changing SU24, you need to do a "Read old status and merge with new data" in expert mode for the authorizations of the menu objects to be adjusted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But it would be wise to first check how the roles have been built and how intact the authorization data is to start with, as you could be in for a surprise... particularly if standard authorizations have been deleted in the past and the merge has not been used! Why standard authorizations can be deleted at all I actually don't know...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Aug 2009 18:32:45 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970778#M1339205</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-08-06T18:32:45Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Object Clarification</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970779#M1339206</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please advice me !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These are brand new systems, Sandbox and Dev never upgradet from  SU25.  As I mentioned in my pervious post its pretty vaired that SU53 pulling S_Develop, S_USER_AGR, S_USER_AUT, and S_USER_GRP.  I had to fix these su24 standard propossal they are all SAP Proposal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I changed all the proposals for the above Authorization objects to  "NO" but I didn't touch the SAP proposal which was the last column. and then I went to one of the role which has su53 and went through EDIT mode I still see S_Develop pulling, I don't unserstand why.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advice &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Aug 2009 18:52:03 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970779#M1339206</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-08-06T18:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Object Clarification</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970780#M1339207</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; I modified su24 I changed propossal = No for the S_Develop but SAP propsl I didn't touch it its still = YS. but after I changed it it is still brigning the Object into the Role.  Can you please tell me what's wrong&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check the status of the Object showing in the Profile Generator. If it is manually (I presume this is the reason of not getting the effect of check proposal you modified) and if maximum objects are manually added then I would suggest to delete that role and then create a new role. Add the TCodes in Menu tab and then maintain their authorizations in Authorization tab to generate the profile at last.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; do I have to change SAP Propsl also &lt;/P&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No. never.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Dipanjan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Aug 2009 18:52:49 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-clarification/m-p/5970780#M1339207</guid>
      <dc:creator>sdipanjan</dc:creator>
      <dc:date>2009-08-06T18:52:49Z</dc:date>
    </item>
  </channel>
</rss>

