<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authorization level in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-level/m-p/6033601#M1349758</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your inputs.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dear Jurjen: Actually for more security one of my client is asking about these auth levels.&lt;/P&gt;&lt;P&gt;Here he wants to create 3 levels with different authorization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;More clearly 3rd level is hegher level with only user compare authorization, he can do only user comparison then only these authorizations have to get activated. for this if any other way to create 3rd level, means can we give user/role activation etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Nick Loy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 08 Aug 2009 10:13:49 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2009-08-08T10:13:49Z</dc:date>
    <item>
      <title>Authorization level</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-level/m-p/6033595#M1349752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are planning to create authrization levels for user creation &amp;amp; role creation, role assignation and role comparison.&lt;/P&gt;&lt;P&gt;As below&lt;/P&gt;&lt;P&gt;1) first user can create user and role&lt;/P&gt;&lt;P&gt;2) Second user only can assign created role to users&lt;/P&gt;&lt;P&gt;3) Third user only can do user comparison, which means in this step he only can activate user or role.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1st and second steps we can create roles based on su01 and pfcg. But i am not clear about 3rd step how we can assign only activation authorization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if any other possibility for above auth levels.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Regards&lt;/P&gt;&lt;P&gt;Nick Loy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Aug 2009 07:21:43 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-level/m-p/6033595#M1349752</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-08-08T07:21:43Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization level</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-level/m-p/6033596#M1349753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Nick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For 3rd condition you have to restric below authorizations to create, change, delete&lt;/P&gt;&lt;P&gt;S_USER_AGR&lt;/P&gt;&lt;P&gt;S_USER_AUT&lt;/P&gt;&lt;P&gt;S_USER_GRP&lt;/P&gt;&lt;P&gt;S_USER_PRO&lt;/P&gt;&lt;P&gt;S_USER_SAS&lt;/P&gt;&lt;P&gt;S_USER_TCD&lt;/P&gt;&lt;P&gt;S_USER_VAL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Chandra&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Aug 2009 08:14:47 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-level/m-p/6033596#M1349753</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-08-08T08:14:47Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization level</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-level/m-p/6033597#M1349754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Chan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and I accept your reply, but those objects are default objects which will come with SU01 and PFCG Tcodes.&lt;/P&gt;&lt;P&gt;I have clearly mentioned that i want to assing only USER COMPARISON  authorizaton(or user/role activation if any) for 3rd user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How USER COMPARISON will come and with which authorization object?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Nick Loy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Aug 2009 08:35:02 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-level/m-p/6033597#M1349754</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-08-08T08:35:02Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization level</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-level/m-p/6033598#M1349755</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Moved to NW Security forum...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Aug 2009 08:54:02 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-level/m-p/6033598#M1349755</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-08-08T08:54:02Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization level</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-level/m-p/6033599#M1349756</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; 1) first user can create user and role&lt;/P&gt;&lt;P&gt;&amp;gt; 2) Second user only can assign created role to users&lt;/P&gt;&lt;P&gt;To split these two make sure you read [Note 312682 - Checks when assigning users to roles|https://service.sap.com/sap/support/notes/312682] so the person assiging roles does not need change &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; 3) Third user only can do user comparison, which means in this step he only can activate user or role.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And why do you want to separate 2 and 3? Can you tell us more about the reasoning behind this? In most systems I work with the user compare is done by the person assiging the role(s) and by a daily job (PFCG_TIME_DEPENDENCY)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Aug 2009 09:31:52 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-level/m-p/6033599#M1349756</guid>
      <dc:creator>jurjen_heeck</dc:creator>
      <dc:date>2009-08-08T09:31:52Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization level</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-level/m-p/6033600#M1349757</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Nick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't think seperate authorizations are required for role assignment and role comparision. Once the role is assigned to the user it gets activated in the user profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the role assignment to user is done with some future date, it is better to do the user comparision with the program, PFCG_TIME_DEPENDENCY.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Aug 2009 09:44:04 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-level/m-p/6033600#M1349757</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-08-08T09:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization level</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-level/m-p/6033601#M1349758</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your inputs.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dear Jurjen: Actually for more security one of my client is asking about these auth levels.&lt;/P&gt;&lt;P&gt;Here he wants to create 3 levels with different authorization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;More clearly 3rd level is hegher level with only user compare authorization, he can do only user comparison then only these authorizations have to get activated. for this if any other way to create 3rd level, means can we give user/role activation etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Nick Loy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Aug 2009 10:13:49 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-level/m-p/6033601#M1349758</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-08-08T10:13:49Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization level</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-level/m-p/6033602#M1349759</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also not sure why you would want the 3rd level because often this is scheduled as a job anyway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But there is a way of doing it: If you take a look in table PRGN_CUST there is a switch which activates a check on transaction PFUD to be able to do the user compare and assign the &lt;DEL&gt;roles&lt;/DEL&gt; profiles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only those users who are authorized for transaction PFUD can do it, regardless of whether they are in PFUD itself, PFCG, the reports, etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also check your Support Pack levels, as there have been several corrections lately which correctly differentiate between role development / admin and user admin. In some cases the checks were too strict or missing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: Julius Bussche on Aug 9, 2009 10:30 AM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Aug 2009 10:30:01 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-level/m-p/6033602#M1349759</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-08-08T10:30:01Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization level</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-level/m-p/6033603#M1349760</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Julius,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have created auth levels as mentioned above, but only one concern...that is i want to kept USER COMPARISON as mandatory to reflect role/authorization changes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Means now when we are assigning new roles to user ids, those are directly getting accessible to user with/without user comparison.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If we do the USER COMPARISON as mandatoru field, then it will be easy to acheive 3rd step.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Regards&lt;/P&gt;&lt;P&gt;Nick Loy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Aug 2009 06:46:56 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-level/m-p/6033603#M1349760</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-08-10T06:46:56Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization level</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-level/m-p/6033604#M1349761</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; If we do the USER COMPARISON as mandatoru field, then it will be easy to acheive 3rd step.&lt;/P&gt;&lt;P&gt;The bugger is that it's not a field... so you would need to permit role assignment via SU01 only and block the ability to use validity ranges there and generally access to the "Users" tab in PFCG, no structural authorizations, etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I think it could be do-able with the above switch for transaction PFUD and S_USER_PRO actvt 22, and then be carefull who you give the access to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There used to be a customizing option at events in SU01 which allowed you to add your own code - which for "SAVE" had a path to PFCG as well. That might have been another possible option to force the compare, but to my knowledge they are obsolete now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, important is that the changes done to the role and assignment are correct and authorized. That the profiles follow-suit as and when needed can be automated in my opinion. There is no additional risk.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Aug 2009 11:12:26 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-level/m-p/6033604#M1349761</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-08-10T11:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization level</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-level/m-p/6033605#M1349762</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes Julius,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created new role only with PFUD tcode for 3rd user, who able to do user comparison.&lt;/P&gt;&lt;P&gt;Hence i acheived 3rd step too....as below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Say A.B and C are 3 different users.&lt;/P&gt;&lt;P&gt;A will be able to create user and role&lt;/P&gt;&lt;P&gt;B only can assign roles to user ids.&lt;/P&gt;&lt;P&gt;C only can compare those assigned roles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These steps are working fine as approval levels.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Regads&lt;/P&gt;&lt;P&gt;Nick Loy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Aug 2009 06:20:13 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-level/m-p/6033605#M1349762</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-08-11T06:20:13Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization level</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-level/m-p/6033606#M1349763</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hai Nick,&lt;/P&gt;&lt;P&gt;I am on ECC6.0...we have applied SPS15 stack recently...afer this &lt;STRONG&gt;Role Comparision&lt;/STRONG&gt; is active only when you create new role...&lt;/P&gt;&lt;P&gt;If the same new/old role needs to given with new T-code then after save and generation,user comparison shows * USer master record compared*...that means as per my understand,by saving and genaration itself the role got compared...is it correct?if yes,then how will you address your 3rd point...please share this also...&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;Gadde.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Aug 2009 07:57:28 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-level/m-p/6033606#M1349763</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-08-11T07:57:28Z</dc:date>
    </item>
  </channel>
</rss>

