<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Structural authorization in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/structural-authorization/m-p/3330350#M797855</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;please tell me the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;do you assign a special authorization profile to that specific user in OOSB? &lt;/P&gt;&lt;P&gt;after the user moved to her/his new department, did you adjust this profile in OOSB or simply let it be?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 07 Feb 2008 11:11:22 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2008-02-07T11:11:22Z</dc:date>
    <item>
      <title>Structural authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/structural-authorization/m-p/3330349#M797854</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to use structural authorization to make sure that a person while making his substitute in the business workplace is allowed to see only his organizational unit and should not be able to view a person from any other organizational unit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And if he is moved to some other department he should only be able to see people from his new department and not from his previous department.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have followed each and every step of the document provided at&lt;/P&gt;&lt;P&gt;"http://sapbasis.msspro.com/securitydocs/structural_authorizations_step_by_step.doc".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would summarize it as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User Profile for structural authorization is created using T-code OOSP by specifying the following options in its maintenance section.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;#149;	Plan Version =1&lt;/P&gt;&lt;P&gt;&amp;#149;	Object Type=&amp;#146;O&amp;#146;&lt;/P&gt;&lt;P&gt;&amp;#149;	Evaluation Path=O-S-P&lt;/P&gt;&lt;P&gt;&amp;#149;	Status Vector =12&lt;/P&gt;&lt;P&gt;&amp;#149;	Period =D &amp;#145;valid records as per today's date&amp;#146;&lt;/P&gt;&lt;P&gt;&amp;#149;	And FM= RH_GET_ORG_ASSIGNMENT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using T-code po13 i.e. for &amp;#145;Maintain Position&amp;#146;   and using IT1017 assign the above created profile to a position.&lt;/P&gt;&lt;P&gt;Now when T-code SE38 will execute the report &amp;#145;RHPROFL0&amp;#146; all the persons assigned to the above positions(i.e. positions for which PD profile has been created) will be assigned this profile keeping the options  as &lt;/P&gt;&lt;P&gt;&amp;#149;	Object type &amp;#145;O&amp;#146;  &lt;/P&gt;&lt;P&gt;&amp;#149;	Un-checking the Test Session Run option&lt;/P&gt;&lt;P&gt;&amp;#149;	Options for Standard and PD Authorization are checked&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; This can be further verified using T-code oosb and clicking on the blue icon next to it .It shall display a list of Object id&amp;#146;s on which that person has the authorization of viewing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now when a person is moved to some other department or some other sub-department within a department after he has been assigned a PD profile he is unable to see his new Org Unit  id&amp;#146;s but he still views  his previous Org Unit ,positions and persons. But if he is not assigned a PD profile and he is moved to a different department and later if he is assigned a PD Profile he sees valid records as per his new relationship with Org Unit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But in our business scenario the transfer of people within the sub-departments and across departments take place very often so we have to look for a solution which allows a person view only the correct department related info i.e. valid as per the new relation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am working on SAP 4.6C.&lt;/P&gt;&lt;P&gt;Any help will really be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Madiha Jadoon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Feb 2008 04:11:18 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/structural-authorization/m-p/3330349#M797854</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-02-07T04:11:18Z</dc:date>
    </item>
    <item>
      <title>Re: Structural authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/structural-authorization/m-p/3330350#M797855</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;please tell me the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;do you assign a special authorization profile to that specific user in OOSB? &lt;/P&gt;&lt;P&gt;after the user moved to her/his new department, did you adjust this profile in OOSB or simply let it be?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Feb 2008 11:11:22 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/structural-authorization/m-p/3330350#M797855</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-02-07T11:11:22Z</dc:date>
    </item>
    <item>
      <title>Re: Structural authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/structural-authorization/m-p/3330351#M797856</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The authorization profile is created using T-code 'oosp' and assigned using T-code po13 to a particular position. &lt;/P&gt;&lt;P&gt;Later the authorization profile is assigned to the person by running the report RHPROFL0 in SE38 which displays all the persons with  a profile assigned to their position and automatically assigns all the persons of that position to that profile.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Feb 2008 03:59:57 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/structural-authorization/m-p/3330351#M797856</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-02-08T03:59:57Z</dc:date>
    </item>
  </channel>
</rss>

