<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Role Based Authorizations in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/role-based-authorizations/m-p/3317268#M794610</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jurjens answer is right as the activty is directly related to the purchase ORG values given in this situation&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and besides that: While SAP calls the TRX Display, there is a change that even giving wider activity codes will not allow the user to create /change. But the ONLY way to be certain: Create a test user with both roles and test for yourselve.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: Auke Visser on Jan 21, 2008 6:44 PM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: Auke Visser on Jan 21, 2008 6:46 PM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 21 Jan 2008 17:43:58 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2008-01-21T17:43:58Z</dc:date>
    <item>
      <title>Role Based Authorizations</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/role-based-authorizations/m-p/3317266#M794608</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello:&lt;/P&gt;&lt;P&gt;I have a question related to the role based authorization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a ROLE:A, which includes Display PO (ME23N) transaction with activity 03 and Pur. Org  (M_BEST_EKO) A.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have another role ROLE:B, which includes Create/Change PO transaction with activity (ACTVT) 01-Create and 02-Change and Pur. Org (M_BEST_EKO). B.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I assign these roles to user, Will he be able to create Purchase order for Pur. Org. A?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My situation is I do not want him to be able to create a PO for Pur. Org = A since he does not have access to ME21N transaction in Role A.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How Can I achieve this??&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Jan 2008 16:52:53 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/role-based-authorizations/m-p/3317266#M794608</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-01-21T16:52:53Z</dc:date>
    </item>
    <item>
      <title>Re: Role Based Authorizations</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/role-based-authorizations/m-p/3317267#M794609</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; I have a ROLE:A, which includes Display PO (ME23N) transaction with activity 03 and Pur. Org  (M_BEST_EKO) A.&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;&amp;gt; I have another role ROLE:B, which includes Create/Change PO transaction with activity (ACTVT) 01-Create and 02-Change and Pur. Org (M_BEST_EKO). B.&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;&amp;gt; If I assign these roles to user, Will he be able to create Purchase order for Pur. Org. A?&lt;/P&gt;&lt;P&gt;No&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As long as activity and org.field are in the same object the authorizations remain separated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Jan 2008 17:42:30 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/role-based-authorizations/m-p/3317267#M794609</guid>
      <dc:creator>jurjen_heeck</dc:creator>
      <dc:date>2008-01-21T17:42:30Z</dc:date>
    </item>
    <item>
      <title>Re: Role Based Authorizations</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/role-based-authorizations/m-p/3317268#M794610</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jurjens answer is right as the activty is directly related to the purchase ORG values given in this situation&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and besides that: While SAP calls the TRX Display, there is a change that even giving wider activity codes will not allow the user to create /change. But the ONLY way to be certain: Create a test user with both roles and test for yourselve.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: Auke Visser on Jan 21, 2008 6:44 PM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: Auke Visser on Jan 21, 2008 6:46 PM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Jan 2008 17:43:58 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/role-based-authorizations/m-p/3317268#M794610</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-01-21T17:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: Role Based Authorizations</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/role-based-authorizations/m-p/3317269#M794611</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tridev,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In ur scenario, user will be not able to create PO for Purch.Org.A as per ur activity and maintenance of ORG levels in Role A.He can only create/change PO for Purch.Org.B.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;T-codes does only check for relative Objects along with activities only which r maintened in Roles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ur scenario is only possible when user have 2 roles.&lt;/P&gt;&lt;P&gt;Othercase, if the same user has only one role , then u cannot differenciate Purchasing Organisation.&lt;/P&gt;&lt;P&gt;Still u can do it, but then u have to insert manually into the Object M_BEST_EKO which is not recommended.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;Gadde.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jan 2008 05:53:11 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/role-based-authorizations/m-p/3317269#M794611</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-01-22T05:53:11Z</dc:date>
    </item>
    <item>
      <title>Re: Role Based Authorizations</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/role-based-authorizations/m-p/3317270#M794612</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tridev,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Field values in any object are picked using the AND operator i.e. Activity 03 AND Pur Org A. Similarly it will be ACTVT 01/02 AND Pur Org B. So for every set of authorization values the fields will always have AND. So a user can have multiple sets of values for the same object BUT the field values will always be tagged together !&lt;/P&gt;&lt;P&gt;It will never be a PnC of the authorization values.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you have proposed to do is absolutely correct!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Sachin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jan 2008 06:43:57 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/role-based-authorizations/m-p/3317270#M794612</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-01-22T06:43:57Z</dc:date>
    </item>
    <item>
      <title>Re: Role Based Authorizations</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/role-based-authorizations/m-p/3317271#M794613</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tridev,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;since the user has display activity in org.A, he can only display. And since the user has create activity in org B, he can create in B. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As the organisations are different, the he cannot have both activities in both organisations.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jan 2008 12:08:24 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/role-based-authorizations/m-p/3317271#M794613</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-01-22T12:08:24Z</dc:date>
    </item>
  </channel>
</rss>

