<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restricting SPRO IMG Views using SPRO_ADMIN in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/restricting-spro-img-views-using-spro-admin/m-p/3241288#M773579</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Prakash&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.  Add the role to the user to give them the access&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. SPRO contains a very large number of transactions and as you have found out even parts of a node have a good number of tx.  This is standard and the users need access to these to be able to see the relevant node items.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your support people should already have very restricted access in production so additive auths shouldn't be a problem.  Ensure that their other roles don't have S_TABU_DIS activity 02 auth group = *   typically having the system locked and in production status should prevent changes but you need to control at auth object level too.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 21 Jan 2008 15:25:06 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2008-01-21T15:25:06Z</dc:date>
    <item>
      <title>Restricting SPRO IMG Views using SPRO_ADMIN</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/restricting-spro-img-views-using-spro-admin/m-p/3241285#M773576</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our goal is to allow business users, to view only a restricted IMG View in Production, when they use Transaction spro. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our current plan is to do a SPRO_ADMIN project view with IMG view ,and add it as a role to the users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does someone have any notes,help to do this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or Do you guys suggest any alternate ways to restrict the IMG View in Production?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Prakash&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2008 15:13:01 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/restricting-spro-img-views-using-spro-admin/m-p/3241285#M773576</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-01-18T15:13:01Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting SPRO IMG Views using SPRO_ADMIN</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/restricting-spro-img-views-using-spro-admin/m-p/3241286#M773577</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Prakash&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is pretty straightforward.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Create your IMG view/s in SPRO_ADMIN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Fire up PFCG and create a role&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. In menu tab click on Utilities-&amp;gt;Customising Auth&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4. Add the IMG proj/view that you created in SPRO_ADMIN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5. Make sure that there are only display activities in the auth tabs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that is what you are after.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2008 15:41:53 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/restricting-spro-img-views-using-spro-admin/m-p/3241286#M773577</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-01-18T15:41:53Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting SPRO IMG Views using SPRO_ADMIN</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/restricting-spro-img-views-using-spro-admin/m-p/3241287#M773578</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created the role, but&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Do I still have to add member to the project each time? If the member, can be added to the project just by role assignment in PFCG , that would be great.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. How about Authorizations?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently we restrict the support personnel in production, to some defined transactions. When we look at the authorizations in the role for spro, it has several transactions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please suggest me an approach?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our idea is to assign a restricted spro view, as a transaction based production position.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Prakash&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Jan 2008 14:19:40 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/restricting-spro-img-views-using-spro-admin/m-p/3241287#M773578</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-01-21T14:19:40Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting SPRO IMG Views using SPRO_ADMIN</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/restricting-spro-img-views-using-spro-admin/m-p/3241288#M773579</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Prakash&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.  Add the role to the user to give them the access&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. SPRO contains a very large number of transactions and as you have found out even parts of a node have a good number of tx.  This is standard and the users need access to these to be able to see the relevant node items.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your support people should already have very restricted access in production so additive auths shouldn't be a problem.  Ensure that their other roles don't have S_TABU_DIS activity 02 auth group = *   typically having the system locked and in production status should prevent changes but you need to control at auth object level too.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Jan 2008 15:25:06 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/restricting-spro-img-views-using-spro-admin/m-p/3241288#M773579</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-01-21T15:25:06Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting SPRO IMG Views using SPRO_ADMIN</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/restricting-spro-img-views-using-spro-admin/m-p/3241289#M773580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The thing scaring us is that currently support hold other transaction based positions (s_tabu_dis 2) now by adding display SPRO, it should not give them table change option from other functional groups, when the production client is unlocked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How does companies usually handle this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have been putting SPRO in firefighter just because of this scare and we have been asked to reduce our firefighter usage.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So in short can spro display, coexist with a transaction based support position in production?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Prakash&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Jan 2008 16:26:44 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/restricting-spro-img-views-using-spro-admin/m-p/3241289#M773580</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-01-21T16:26:44Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting SPRO IMG Views using SPRO_ADMIN</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/restricting-spro-img-views-using-spro-admin/m-p/3241290#M773581</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Prakash,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First of all general support roles should never have S_TABU_DIS with ACTVT 02 auth gp *.  They should be limited to solely the auth groups on the tables that they need to change via the admin transactions.  BASIS are a typical exception (but that still doesn't make it right!).  They should restricted to only the transactions that they need to execute and there should be no direct table maintenance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this is in place, then the risk of giving SPRO display in prod alongside the support roles is reduced and one which is accepted in many organisations.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As the control over table access doesn't appear to be in place then having SPRO Display in firefighter sounds like a reasonable mitigating control.  As far as I am aware there is no fee for usage in FF so as long as your process is OK there shouldn't be any problem with continuing to do it that way.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Jan 2008 19:48:55 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/restricting-spro-img-views-using-spro-admin/m-p/3241290#M773581</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-01-21T19:48:55Z</dc:date>
    </item>
  </channel>
</rss>

