<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PFCG authorization objects vs SU53 checks in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/pfcg-authorization-objects-vs-su53-checks/m-p/7334472#M1538642</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Laurent&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know how you feel &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't rely too heavily on an SU53 (especially an S_* object/FDKUSER/others I can't remember - it only shows the last failure and may not be relevant to the tcode you are working on, try also running ST01 just in case/if you don't trust the SU53.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 02 Nov 2010 18:49:55 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2010-11-02T18:49:55Z</dc:date>
    <item>
      <title>PFCG authorization objects vs SU53 checks</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/pfcg-authorization-objects-vs-su53-checks/m-p/7334471#M1538641</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was thinking I have understood for a long time authorization checks. But no.&lt;/P&gt;&lt;P&gt;So Here's my question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I ahd a transaction in PFCG menu, PFCG gets the authorization objects to maintain automatically (from SU24 checks). OK.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When testing the role in ECC : : error. SU53 qays that authorization objects are missing. How the tests are working regarding SU53 and PFCG ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i.e tcode_de = MDBT in PFCG, PFCG gets M_MTDI_ORG object to maintain =&amp;gt; OK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When testing my role, SU53 says that other objects is missing, i.e S_ADMI_FCD. I don't understand because this object is checked with 'NO' in ECC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx.&lt;/P&gt;&lt;P&gt;Laurent&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Nov 2010 17:31:17 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/pfcg-authorization-objects-vs-su53-checks/m-p/7334471#M1538641</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-11-02T17:31:17Z</dc:date>
    </item>
    <item>
      <title>Re: PFCG authorization objects vs SU53 checks</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/pfcg-authorization-objects-vs-su53-checks/m-p/7334472#M1538642</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Laurent&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know how you feel &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't rely too heavily on an SU53 (especially an S_* object/FDKUSER/others I can't remember - it only shows the last failure and may not be relevant to the tcode you are working on, try also running ST01 just in case/if you don't trust the SU53.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Nov 2010 18:49:55 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/pfcg-authorization-objects-vs-su53-checks/m-p/7334472#M1538642</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-11-02T18:49:55Z</dc:date>
    </item>
    <item>
      <title>Re: PFCG authorization objects vs SU53 checks</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/pfcg-authorization-objects-vs-su53-checks/m-p/7334473#M1538643</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; When testing the role in ECC : : error. SU53 qays that authorization objects are missing. How the tests are working regarding SU53 and PFCG ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The auth checks performed are dependent on lots of things: system config, functional config, master data setup, use of the transaction.&lt;/P&gt;&lt;P&gt;The config in SU24 can't cater for all of those options so SAP gives us the ability to make them more accurate for our particular situations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; i.e tcode_de = MDBT in PFCG, PFCG gets M_MTDI_ORG object to maintain =&amp;gt; OK&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;&amp;gt; When testing my role, SU53 says that other objects is missing, i.e S_ADMI_FCD. I don't understand because this object is checked with 'NO' in ECC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can't deactivate a check on an S_ or P_ auth object.  These auths are fundamental methods of protecting the SAP application (S_) and personal data (P_)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As David says, the SU53 only shows the last auth failure and there is often lots of spurious stuff reported that isn't required to allow the transaction to process.  In this respect ST01 is more useful as it (usually) shows you all the auth checks being evaluated so you can more easily focus on the important ones.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Nov 2010 19:12:25 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/pfcg-authorization-objects-vs-su53-checks/m-p/7334473#M1538643</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-11-02T19:12:25Z</dc:date>
    </item>
    <item>
      <title>Re: PFCG authorization objects vs SU53 checks</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/pfcg-authorization-objects-vs-su53-checks/m-p/7334474#M1538644</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;in most of Functional tcode, authority check is done with values in some master tables....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so such failures show STRANGE check failure in SU53.......&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the object may be in no way related to your tcode and adding that object, will also not resolve the issue.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what i do in such cased is debug......... Breakpoint at...... 'Message'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Surpreet&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Nov 2010 04:12:19 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/pfcg-authorization-objects-vs-su53-checks/m-p/7334474#M1538644</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-11-03T04:12:19Z</dc:date>
    </item>
    <item>
      <title>Re: PFCG authorization objects vs SU53 checks</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/pfcg-authorization-objects-vs-su53-checks/m-p/7334475#M1538645</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In such cases, and especially if you are finding it a hard time to go through the program itself and looking for "Authority check" statements, its easier to perform ST01 auth traces against the test user, as pointed out in an earlier reply, and rely on the findings of missing auths on the report produced.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the issue is with an Z-transaction, would advise updating the SU24 entry for that code to reflect the missing auths found.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Nov 2010 16:32:09 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/pfcg-authorization-objects-vs-su53-checks/m-p/7334475#M1538645</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-11-03T16:32:09Z</dc:date>
    </item>
  </channel>
</rss>

