<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authority Trace and Application Server in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/authority-trace-and-application-server/m-p/9378540#M1733822</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bjoern&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm pretty sure you can allow the SM50/51/SM04 for the Security person to switch app servers without granting S_ADMI_FCD = PADM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;S_ADMI_FCD enables stopping of processes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shivraj is right in the work around. However, depending on how you have implemented SAPGUI with saplogon.ini file you may not want to add it to the SAPLogon. For example, if you have load balancing in place but list all the app servers users are most likely to choose the first.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 10 Apr 2013 03:16:03 GMT</pubDate>
    <dc:creator>Colleen</dc:creator>
    <dc:date>2013-04-10T03:16:03Z</dc:date>
    <item>
      <title>Authority Trace and Application Server</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authority-trace-and-application-server/m-p/9378538#M1733820</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know that I have to execute the authority trace on the same application server to see any results.&lt;/P&gt;&lt;P&gt;Maybe an user and the authority admin are on different application server. So the authority admin could execute transaction SM51 to change the application server.&lt;/P&gt;&lt;P&gt;But when the authority admin has authority for transaction SM51 he can stop processes. That is not secure!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a solution for Release &amp;lt; 7.30?&lt;/P&gt;&lt;P&gt;I heard with 7.30 it is possible to choose the system or server for which the trace should be shown.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you and&lt;/P&gt;&lt;P&gt;Best Regards &lt;/P&gt;&lt;P&gt;Bjoern&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Apr 2013 14:52:53 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authority-trace-and-application-server/m-p/9378538#M1733820</guid>
      <dc:creator>former_member620387</dc:creator>
      <dc:date>2013-04-09T14:52:53Z</dc:date>
    </item>
    <item>
      <title>Re: Authority Trace and Application Server</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authority-trace-and-application-server/m-p/9378539#M1733821</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Bjoern,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One work around for this scenario &lt;EM&gt;i.e.&lt;/EM&gt; switching between servers without using SM51, that I have worked with is to create manual logons directly to the application server in GUI Pad. Then you can check the user's server from AL08 etc. and directly logon to that server. Hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Shivraj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Apr 2013 17:09:54 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authority-trace-and-application-server/m-p/9378539#M1733821</guid>
      <dc:creator>shivraj_singh2</dc:creator>
      <dc:date>2013-04-09T17:09:54Z</dc:date>
    </item>
    <item>
      <title>Re: Authority Trace and Application Server</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authority-trace-and-application-server/m-p/9378540#M1733822</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bjoern&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm pretty sure you can allow the SM50/51/SM04 for the Security person to switch app servers without granting S_ADMI_FCD = PADM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;S_ADMI_FCD enables stopping of processes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shivraj is right in the work around. However, depending on how you have implemented SAPGUI with saplogon.ini file you may not want to add it to the SAPLogon. For example, if you have load balancing in place but list all the app servers users are most likely to choose the first.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Apr 2013 03:16:03 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authority-trace-and-application-server/m-p/9378540#M1733822</guid>
      <dc:creator>Colleen</dc:creator>
      <dc:date>2013-04-10T03:16:03Z</dc:date>
    </item>
  </channel>
</rss>

