<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BI Authorization Issue in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/bi-authorization-issue/m-p/7764443#M1583960</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey siva &amp;amp; sandipan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;          Both of your answer's helped a lot. Finally the BI team has to tweak their query to fix the issue. It seem's that the navigational attribute was not really necessary. Thanks for the help. Assigning points for both of you and closing this thread &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: saranya.j on Mar 21, 2011 10:29 PM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: saranya.j on Mar 21, 2011 10:29 PM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 21 Mar 2011 21:28:16 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2011-03-21T21:28:16Z</dc:date>
    <item>
      <title>BI Authorization Issue</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/bi-authorization-issue/m-p/7764440#M1583957</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gurus,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;          We are having problem with analysis authorizations for a particular query. The report is for the vendor balance, it has balance, cumulative balance as key figures and vendor as characteristics. We wanted to restrict the report by account group level. we have 4 account groups. The account group is a navigational attribute of creditor account group. account group [char] is auth relevant but the creditor account group [char] is not. so we gave respective auth group for accnt grp [char] but the query fails. The analysis log is follows, any help will be appreciated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Authorization Check   &lt;/P&gt;&lt;P&gt;  Detail Check for InfoProvider ZFIAP_S01   &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  Preprocessing:   &lt;/P&gt;&lt;P&gt;Selection Checked for Consistency, Preprocessed and Supplemented As Needed &lt;/P&gt;&lt;P&gt;Subselection (Technical SUBNR) 1 &lt;/P&gt;&lt;P&gt;Check Node Definitions and Value Authorizations... &lt;/P&gt;&lt;P&gt;Node- and Value Authorizations Are OK &lt;/P&gt;&lt;P&gt;End of Preprocessing &lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;HR originaltext="-------------------------------------------------------------------------------" /&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Filling the Buffer... &lt;/P&gt;&lt;P&gt;...Buffer Filled &lt;/P&gt;&lt;P&gt;  Main Check:   &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;HR originaltext="-------------------------------------------------------------------------------" /&gt;&lt;P&gt;  Subselection (Technical SUBNR) 1   &lt;/P&gt;&lt;P&gt;Supplementation of Selection for Aggregated Characteristics &lt;/P&gt;&lt;P&gt;  No Check for Aggregation Authorization Required   &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following Set Is Checked  Comparison with Following Authorized Set  Result  Remaining Set  &lt;/P&gt;&lt;P&gt;Characteristic  Content in SQL Format  &lt;/P&gt;&lt;P&gt;0ACCNT_GRPV &lt;/P&gt;&lt;P&gt;0TCAACTVT &lt;/P&gt;&lt;P&gt; 0TCAACTVT = '03' &lt;/P&gt;&lt;P&gt;AND 0ACCNT_GRPV LIKE * &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; Characteristic  Content in SQL Format  &lt;/P&gt;&lt;P&gt;0ACCNT_GRPV  I EQ : &lt;/P&gt;&lt;P&gt;I EQ ZCON &lt;/P&gt;&lt;P&gt;I EQ ZCOR &lt;/P&gt;&lt;P&gt;I EQ ZFRN &lt;/P&gt;&lt;P&gt;I EQ ZGAR &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;0TCAACTVT  I CP * &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; Partially or Fully Authorized (Intersection)   Characteristic  Content in SQL Format  &lt;/P&gt;&lt;P&gt;0ACCNT_GRPV &lt;/P&gt;&lt;P&gt;0TCAACTVT &lt;/P&gt;&lt;P&gt; NOT 0ACCNT_GRPV IN ('ZCON','ZCOR','ZFRN','ZGAR') &lt;/P&gt;&lt;P&gt;AND 0TCAACTVT = '03' &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Value selection partially authorized. Check of remainder at end &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following Set Is Checked  Comparison with Following Authorized Set  Result  Remaining Set  &lt;/P&gt;&lt;P&gt;Characteristic  Content in SQL Format  &lt;/P&gt;&lt;P&gt;0ACCNT_GRPV &lt;/P&gt;&lt;P&gt;0TCAACTVT &lt;/P&gt;&lt;P&gt; NOT 0ACCNT_GRPV IN ('ZCON','ZCOR','ZFRN','ZGAR') &lt;/P&gt;&lt;P&gt;AND 0TCAACTVT = '03' &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; Characteristic  Content in SQL Format  &lt;/P&gt;&lt;P&gt;0ACCNT_GRPV  I EQ : &lt;/P&gt;&lt;P&gt;I EQ ZCON &lt;/P&gt;&lt;P&gt;I EQ ZCOR &lt;/P&gt;&lt;P&gt;I EQ ZFRN &lt;/P&gt;&lt;P&gt;I EQ ZGAR &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;0TCAACTVT  I CP * &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; Not Authorized    &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;All Authorizations Tested &lt;/P&gt;&lt;P&gt;  Message EYE007: You do not have sufficient authorization   &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  No Sufficient Authorization for This Subselection (SUBNR)   &lt;/P&gt;&lt;P&gt;Following CHANMIDs Are Affected: &lt;/P&gt;&lt;P&gt;2596 ( ZFIAP_S01___F2 ) &lt;/P&gt;&lt;P&gt;  Authorization Check Complete&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Mar 2011 04:50:57 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/bi-authorization-issue/m-p/7764440#M1583957</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2011-03-11T04:50:57Z</dc:date>
    </item>
    <item>
      <title>Re: BI Authorization Issue</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/bi-authorization-issue/m-p/7764441#M1583958</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Make sure that you use the objects 0TCAACTVT, 0TCAIPROV and 0TCAVALID in your analysis authorization.&lt;/P&gt;&lt;P&gt;2) Make sure that you also have assign to this analysis authorization all characteristics that are "Authorization relevant" .&lt;/P&gt;&lt;P&gt;3) If the consolidation group is authorization relevant, always put " * ". &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Siva&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Mar 2011 05:36:44 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/bi-authorization-issue/m-p/7764441#M1583958</guid>
      <dc:creator>sivakumar_kilari3</dc:creator>
      <dc:date>2011-03-11T05:36:44Z</dc:date>
    </item>
    <item>
      <title>Re: BI Authorization Issue</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/bi-authorization-issue/m-p/7764442#M1583959</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per SAP Note 642072 (Authorization check on : for char./navigation attribute):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;P&gt;In new BI 7.x releases, the authorization logic has been enhanced and navigation attributes have the same status as 'normal' characteristics. An overlay of characteristic A and navigation attribute B__A no longer occurs. They are now treated as completely seperate objects.&lt;/P&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you said, account group (0ACCNT_GRPV) is a navigational attribute of creditor account group (say 0CREDITOR), so the characteristics here becomes 0CREDITOR__0ACCNT_GRPV. &lt;STRONG&gt;So you have to mark 0CREDITOR__0ACCNT_GRPV as auth relevant by tcode RSD1&lt;/STRONG&gt;&lt;DEL&gt;&lt;STRONG&gt;&amp;gt; go to 0CREDITOR&lt;/STRONG&gt;&lt;/DEL&gt;&amp;gt; in attribute tab check 0ACCNT_GRPV as auth relevant and activate it.&lt;/P&gt;&lt;P&gt;As per the trace you posted, it seems currently its just checking for 0ACCNT_GRPV and not 0CREDITOR__0ACCNT_GRPV which is treated as separate entity in BI7.x versions. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, for restriction on navigational attributes, you need to create an authorization variable on your navigational attribute (i.e 0CREDITOR__0ACCNT_GRPV ) and make it input ready  in your query. This will pull the user's authorized values and input them into the query. Also, maintain the desired authorized values for your navigation attribute (0CREDITOR__0ACCNT_GRPV) in the Analysis authorization assigned to the user. Leaving it blank or no values entered will make the query check for "*".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;P.S (edited)&lt;/STRONG&gt;: Most importantly, the query should have a check on auth relevant characteristics (in your case 0CREDITOR__0ACCNT_GRPV) otherwise it is not possible to restrict the characteristics to specific values and BI will by default check for "*" and atleast ":" has to be added to the analysis authorization for successful execution of query but that does not serve the purpose as ":" shows aggregated data for all account groups. Please see note # 1140831&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;Sandipan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: Sandipan Choudhury on Mar 11, 2011 12:36 PM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Mar 2011 05:56:53 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/bi-authorization-issue/m-p/7764442#M1583959</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2011-03-11T05:56:53Z</dc:date>
    </item>
    <item>
      <title>Re: BI Authorization Issue</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/bi-authorization-issue/m-p/7764443#M1583960</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey siva &amp;amp; sandipan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;          Both of your answer's helped a lot. Finally the BI team has to tweak their query to fix the issue. It seem's that the navigational attribute was not really necessary. Thanks for the help. Assigning points for both of you and closing this thread &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: saranya.j on Mar 21, 2011 10:29 PM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: saranya.j on Mar 21, 2011 10:29 PM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Mar 2011 21:28:16 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/bi-authorization-issue/m-p/7764443#M1583960</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2011-03-21T21:28:16Z</dc:date>
    </item>
  </channel>
</rss>

