<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Security Admin can deactivate Authorization Object (Standard) in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-admin-can-deactivate-authorization-object-standard/m-p/10409593#M1843350</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Security Gurus, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am facing a unique situation with regards to Security Admin’s access in Production to deactivate authorization objects.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Security Admin in Production when opens a role in PFCG, then goes to Authorization tab and tries to deactivate authorization objects with different status, the results are as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Authorization Object (Manually) : Cannot deactivate/ or activate&lt;/P&gt;&lt;P&gt;- Authorization Object (Maintained) : Cannot deactivate/ or activate&lt;/P&gt;&lt;P&gt;- Authorization Object (Changed): Cannot Deactivate/ or activate&lt;/P&gt;&lt;P&gt;- Authorization Object (Standard): Can Deactivate, but cannot activate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the Security Admin can deactivate “Authorization Object (Standard)”, however it cannot reactivate the same or any other authorization object.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The trace is not picking up any check when “Authorization Object (Standard)” is Deactivated, however for every other failed deactivation &amp;amp; re-activation it is showing missing authorization for S_USER_VAL (which is assigned as all ‘’, i.e. No authorization). S_USER_AGR is assigned with 02 access, which is coming in for user assignment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you think it is a bug, or there is a way to that deactivation of “Authorization Object (Standard)” can be limited without affecting access for user assignment ? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 18 Jun 2014 16:43:58 GMT</pubDate>
    <dc:creator>shivraj_singh2</dc:creator>
    <dc:date>2014-06-18T16:43:58Z</dc:date>
    <item>
      <title>Security Admin can deactivate Authorization Object (Standard)</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-admin-can-deactivate-authorization-object-standard/m-p/10409593#M1843350</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Security Gurus, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am facing a unique situation with regards to Security Admin’s access in Production to deactivate authorization objects.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Security Admin in Production when opens a role in PFCG, then goes to Authorization tab and tries to deactivate authorization objects with different status, the results are as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Authorization Object (Manually) : Cannot deactivate/ or activate&lt;/P&gt;&lt;P&gt;- Authorization Object (Maintained) : Cannot deactivate/ or activate&lt;/P&gt;&lt;P&gt;- Authorization Object (Changed): Cannot Deactivate/ or activate&lt;/P&gt;&lt;P&gt;- Authorization Object (Standard): Can Deactivate, but cannot activate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the Security Admin can deactivate “Authorization Object (Standard)”, however it cannot reactivate the same or any other authorization object.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The trace is not picking up any check when “Authorization Object (Standard)” is Deactivated, however for every other failed deactivation &amp;amp; re-activation it is showing missing authorization for S_USER_VAL (which is assigned as all ‘’, i.e. No authorization). S_USER_AGR is assigned with 02 access, which is coming in for user assignment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you think it is a bug, or there is a way to that deactivation of “Authorization Object (Standard)” can be limited without affecting access for user assignment ? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jun 2014 16:43:58 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-admin-can-deactivate-authorization-object-standard/m-p/10409593#M1843350</guid>
      <dc:creator>shivraj_singh2</dc:creator>
      <dc:date>2014-06-18T16:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: Security Admin can deactivate Authorization Object (Standard)</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-admin-can-deactivate-authorization-object-standard/m-p/10409594#M1843351</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sapnote - 312682 - has been very helpful with this issue. Regards, Shivraj &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jul 2014 17:50:05 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-admin-can-deactivate-authorization-object-standard/m-p/10409594#M1843351</guid>
      <dc:creator>shivraj_singh2</dc:creator>
      <dc:date>2014-07-07T17:50:05Z</dc:date>
    </item>
    <item>
      <title>Re: Security Admin can deactivate Authorization Object (Standard)</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-admin-can-deactivate-authorization-object-standard/m-p/10409595#M1843352</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the behaviour should be as is described in note #642359. I suggest to recheck the values you have in s_user_val-auth-fields...&lt;/P&gt;&lt;P&gt;b.rgds, Bernhard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jul 2014 06:39:53 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-admin-can-deactivate-authorization-object-standard/m-p/10409595#M1843352</guid>
      <dc:creator>Bernhard_SAP</dc:creator>
      <dc:date>2014-07-09T06:39:53Z</dc:date>
    </item>
  </channel>
</rss>

