<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Roles read only in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/roles-read-only/m-p/6115310#M1362948</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to have all the transactions in single role with display authorizations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Goto PFCG-&amp;gt;Create new role-&amp;gt; Goto Authorizations tab-&amp;gt; change authorizations Data-&amp;gt;Edit-&amp;gt; insert Authorizations-&amp;gt; full authorization&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It ll give full authorization. You can make the ACTVT field to 03.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have any Z transactions add it manually. It wont come.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For any issues. Revert back.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Raja. G&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 17 Sep 2009 10:37:10 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2009-09-17T10:37:10Z</dc:date>
    <item>
      <title>Roles read only</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/roles-read-only/m-p/6115305#M1362943</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We want to make the roles of some users read only. We thought to change all ACTVT fields to 03, but users have over 200 roles, and these have more than 11.000 objects ACTVT. This is a drudgery job.&lt;/P&gt;&lt;P&gt;Is there another way to do this task?.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Sep 2009 09:09:58 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/roles-read-only/m-p/6115305#M1362943</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-09-17T09:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: Roles read only</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/roles-read-only/m-p/6115306#M1362944</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The requirement is to see all the transactions with display authorizations alone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Correct me if am wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pls provide the req clearly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Raja. G&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Sep 2009 09:20:15 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/roles-read-only/m-p/6115306#M1362944</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-09-17T09:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: Roles read only</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/roles-read-only/m-p/6115307#M1362945</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; Is there another way to do this task?.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;Build a specific set of display roles &amp;amp; replace what is assigned to the users.&lt;/P&gt;&lt;P&gt;That is the proper way of doing it and will take you less time than changing 200 roles + the job will be done correctly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Sep 2009 09:25:08 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/roles-read-only/m-p/6115307#M1362945</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-09-17T09:25:08Z</dc:date>
    </item>
    <item>
      <title>Re: Roles read only</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/roles-read-only/m-p/6115308#M1362946</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In addition to the other comments: It will not only be a drudgery job but also a sloppy one. There are somewhere around 200 different activity-related fields and with some of them 03 isn't the read activity. Besides that, there are several objects that will grant change access without having an activity field at all............&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Sep 2009 09:43:55 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/roles-read-only/m-p/6115308#M1362946</guid>
      <dc:creator>jurjen_heeck</dc:creator>
      <dc:date>2009-09-17T09:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: Roles read only</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/roles-read-only/m-p/6115309#M1362947</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Exactly Raja, we want users have the same transactions, but only for reading.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Sep 2009 10:20:37 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/roles-read-only/m-p/6115309#M1362947</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-09-17T10:20:37Z</dc:date>
    </item>
    <item>
      <title>Re: Roles read only</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/roles-read-only/m-p/6115310#M1362948</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to have all the transactions in single role with display authorizations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Goto PFCG-&amp;gt;Create new role-&amp;gt; Goto Authorizations tab-&amp;gt; change authorizations Data-&amp;gt;Edit-&amp;gt; insert Authorizations-&amp;gt; full authorization&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It ll give full authorization. You can make the ACTVT field to 03.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have any Z transactions add it manually. It wont come.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For any issues. Revert back.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Raja. G&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Sep 2009 10:37:10 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/roles-read-only/m-p/6115310#M1362948</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-09-17T10:37:10Z</dc:date>
    </item>
    <item>
      <title>Re: Roles read only</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/roles-read-only/m-p/6115311#M1362949</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN __default_attr="red" __jive_macro_name="color"&gt;This is very poor advice. It will not protect your system in any way.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Sep 2009 11:26:18 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/roles-read-only/m-p/6115311#M1362949</guid>
      <dc:creator>jurjen_heeck</dc:creator>
      <dc:date>2009-09-17T11:26:18Z</dc:date>
    </item>
    <item>
      <title>Re: Roles read only</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/roles-read-only/m-p/6115312#M1362950</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jurjen,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The requirement is to see all the transactions with display alone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This role will be assigned to all the top level people and the functional consultants.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So that i suggested this one. We are also maintaining like this. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are also maintaining it for every department level display roles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;May i know what kind of security breach in this? So that i ll also modify the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Raja. G&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: Raja Gunasekaran on Sep 17, 2009 1:47 PM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Sep 2009 11:39:05 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/roles-read-only/m-p/6115312#M1362950</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-09-17T11:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: Roles read only</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/roles-read-only/m-p/6115313#M1362951</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; If you have any Z transactions add it manually. It wont come.&lt;/P&gt;&lt;P&gt;This would only be true if a special config setting had been activated, which it by default is not. I doubt there are many customers out there who have actually done this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you can see, some forum members are itching a bit at the rest of your post. This is an urban legend which has been going around for many years, and causes nothing but security problems and bad (inconsistent) role designs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to take that approach, then you need to know all the fields which are action related and in which objects (so you need to know the objects very well as well) they are used. There are also combinations of objects which are tricky and if you mix it with another role built correctly then you quickly have unintended and unauthorized access. For dialog users starting transactions you will still have the S_TCODE problem anyway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: Julius Bussche on Sep 17, 2009 1:43 PM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Sep 2009 11:41:34 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/roles-read-only/m-p/6115313#M1362951</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-09-17T11:41:34Z</dc:date>
    </item>
    <item>
      <title>Re: Roles read only</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/roles-read-only/m-p/6115314#M1362952</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Raja,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why would you assign FB01 if someone needs to display only and FB03 should be used instead?&lt;/P&gt;&lt;P&gt;The transaction is rendered useless &amp;amp; should not be performed unless there is no other practical way of displaying the data.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The risk is twofold.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Can you guarantee that they will have no other roles with create or change activities which will be inherited?&lt;/P&gt;&lt;P&gt;2.  Are you 100% confident that the authorisation concept hasn't missed a validation on a create or change transaction.  I'm not.&lt;/P&gt;&lt;P&gt;Additionally, what do your internal &amp;amp; external auditors say about it.  If they haven't raised this as a problem then they aren't reviewing properly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Sep 2009 11:57:53 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/roles-read-only/m-p/6115314#M1362952</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-09-17T11:57:53Z</dc:date>
    </item>
    <item>
      <title>Re: Roles read only</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/roles-read-only/m-p/6115315#M1362953</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks all for your answers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the end, the customer wants to change all the ACTVT field in all the roles. Raja, your idea is not possible because they doesn't want that every user can see all transactions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Sep 2009 15:20:38 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/roles-read-only/m-p/6115315#M1362953</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-09-17T15:20:38Z</dc:date>
    </item>
    <item>
      <title>Re: Roles read only</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/roles-read-only/m-p/6115316#M1362954</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Maximino, with the greatest respect intended, the customer are wrong.  As the service provider shouldn't you be telling them the best way to achieve it.&lt;/P&gt;&lt;P&gt;I would recommend that you tell them this to ensure that you are not responsible when they auditors pick this up as an issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Sep 2009 15:25:20 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/roles-read-only/m-p/6115316#M1362954</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-09-17T15:25:20Z</dc:date>
    </item>
    <item>
      <title>Re: Roles read only</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/roles-read-only/m-p/6115317#M1362955</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is still a notch better than merging all the roles into a mother-of-all-display access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But a big problem will be thousands of "changed" status authorizations in roles which might have been previously intact.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Come SP and upgrade time, you will pay for that mistake 10 times over!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;=&amp;gt; Advise your customer not to do it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Sep 2009 16:04:53 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/roles-read-only/m-p/6115317#M1362955</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-09-17T16:04:53Z</dc:date>
    </item>
    <item>
      <title>Re: Roles read only</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/roles-read-only/m-p/6115318#M1362956</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; It is still a notch better than merging all the roles into a mother-of-all-display access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;depending how you do it of course &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would prefer to see a big role made up of only display tx &amp;amp; objects treated properly than the proposed alternative&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Sep 2009 16:48:34 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/roles-read-only/m-p/6115318#M1362956</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-09-17T16:48:34Z</dc:date>
    </item>
    <item>
      <title>Re: Roles read only</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/roles-read-only/m-p/6115319#M1362957</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It also depends on what the chances are of the role being mixed with other roles using different builds.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What he said was:&lt;/P&gt;&lt;P&gt;&amp;gt; but users have over 200 roles, and these have more than 11.000 objects ACTVT. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I am thinking that all users would have this role somewhere, and what is intended to be "the enablers" in a different role.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I could be wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: Julius Bussche on Sep 17, 2009 7:06 PM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Sep 2009 17:05:34 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/roles-read-only/m-p/6115319#M1362957</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-09-17T17:05:34Z</dc:date>
    </item>
  </channel>
</rss>

