<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Su01 Restriction in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/su01-restriction/m-p/3200080#M762676</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks. I  frequntly listen to you as well as read your books ! I am greatly pleased to hear from you directly !!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 11 Dec 2007 22:32:29 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2007-12-11T22:32:29Z</dc:date>
    <item>
      <title>Su01 Restriction</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/su01-restriction/m-p/3200077#M762673</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, i want to restrict the use of Su01 to a particular group tochange user as well as unlock user &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following is the steps I am doing:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Create the  role with a no authorizations except display.&lt;/P&gt;&lt;P&gt;2. Attmept to change the password.th esystem will ntopermit the user. &lt;/P&gt;&lt;P&gt;3. Now do an SU53 and determine whats th eauth object &amp;amp; Edit the auth object.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bur I am finding it very cumbersome, there must be a direct/better way ! can you shed some light ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Dec 2007 16:49:51 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/su01-restriction/m-p/3200077#M762673</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-12-10T16:49:51Z</dc:date>
    </item>
    <item>
      <title>Re: Su01 Restriction</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/su01-restriction/m-p/3200078#M762674</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi George,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check out transaction ST01.  In the transaction help there is some useful info on how to use it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ST01 will let you to switch on an authorisation trace that will record all the auth checks performed when you run a transaction.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An easy way to start is to switch on the trace &amp;amp; using your ID perform one of the tasks e.g. unlock user.  This will tell you which auths are checked (for this one, you need S_USER_GRP ACTVT=05).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The trace will also tell you what auth failures occur etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Use the search for ST01 - there is loads of info on various "features" of the tool that you should be aware of.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Dec 2007 17:09:05 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/su01-restriction/m-p/3200078#M762674</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-12-10T17:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: Su01 Restriction</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/su01-restriction/m-p/3200079#M762675</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi George,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you add a transaction to a role menu (using transaction PFCG) you get the authorization proposals for that transaction after switching to the authorization tab.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Transaction SU24 shows the authorization proposals for a transaction, too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For transaction SU01 you'll find several entries, e.g. for S_USER_GRP (users),  S_USER_AGR (roles), S_USER_PRO (profiles).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can view authorization objects including their documentation using transaction SUIM (or SU21 or SE80).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;Frank Buchholz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Dec 2007 13:34:42 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/su01-restriction/m-p/3200079#M762675</guid>
      <dc:creator>Frank_Buchholz</dc:creator>
      <dc:date>2007-12-11T13:34:42Z</dc:date>
    </item>
    <item>
      <title>Re: Su01 Restriction</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/su01-restriction/m-p/3200080#M762676</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks. I  frequntly listen to you as well as read your books ! I am greatly pleased to hear from you directly !!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Dec 2007 22:32:29 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/su01-restriction/m-p/3200080#M762676</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-12-11T22:32:29Z</dc:date>
    </item>
    <item>
      <title>Re: Su01 Restriction</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/su01-restriction/m-p/3200081#M762677</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;New inputs from Frank Bucholz which needs to be shared and discussed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Dec 2007 23:13:11 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/su01-restriction/m-p/3200081#M762677</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-12-11T23:13:11Z</dc:date>
    </item>
    <item>
      <title>Re: Su01 Restriction</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/su01-restriction/m-p/3200082#M762678</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A small comment from me: If you have prior been able to select the user based on a criteria you are authorized for, and are authorized to navigate into the start screen of SU01 or SU01_NAV (from a report), then only locking the user or resetting the password of the user does not require S_USER_GRP actvivity '03' (display).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You already have the user (based on prior knowledge or report output) =&amp;gt; the system at that point checks S_USER_GRP activity '05' only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Performing user logon data administration &amp;lt;b&amp;gt;after&amp;lt;/b&amp;gt; displaying (F7) the user in SU01 will require more authorizations (display, change,...).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Depending on how you navigate, and when you subsequently run the SU53 check, and how you analyze the ST01 trace, I would think that you will be able to find a correct (authorizations) path to "fine tune" the user admin authorizations. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Though I do not know your requirements (for user group administration), nor how many user groups you have...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2007 00:10:47 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/su01-restriction/m-p/3200082#M762678</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-12-12T00:10:47Z</dc:date>
    </item>
    <item>
      <title>Re: Su01 Restriction</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/su01-restriction/m-p/3200083#M762679</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Juluis,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As said, I want to give the support team -first level of call in- the task of unlocking the users as well as the reseting of PWDS.-Nothing more so no blanket SU01 Access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the value is recommend for S_USER_GRP given that there is Authorizastion for start screen of su01?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Su01 has so wide range of Autho. so yesterday after FB's input I got all the AUth objects and their description. All I now do is tune it up. and then Do a fine tune with SU53/ST01 !Thx&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2007 12:06:50 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/su01-restriction/m-p/3200083#M762679</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-12-12T12:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: Su01 Restriction</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/su01-restriction/m-p/3200084#M762680</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;george, may I suggest you read my previous post on this topic.  It tells you what it needs........&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2007 12:16:59 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/su01-restriction/m-p/3200084#M762680</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-12-12T12:16:59Z</dc:date>
    </item>
    <item>
      <title>Re: Su01 Restriction</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/su01-restriction/m-p/3200085#M762681</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have competed my task.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2007 17:58:58 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/su01-restriction/m-p/3200085#M762681</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-12-12T17:58:58Z</dc:date>
    </item>
  </channel>
</rss>

