<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Role Build? in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/role-build/m-p/3581010#M862095</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;&amp;gt; While su24 is used only to specify or check which auth objects are checked or not checked (along with field vaules) during executions of a perticular tcode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only the ABAP controls what auth objects are checked or not checked.  SU24 can have some influence but you cannot add checks via SU24 or inactivate checks for a range of auth objects.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even outside the ABAP code, some checks are performed by the kernel e.g. S_TCODE, S_DATASET&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 Apr 2008 10:40:23 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2008-04-02T10:40:23Z</dc:date>
    <item>
      <title>Role Build?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/role-build/m-p/3581004#M862089</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I  have  received the authorization matrix  for a module.&lt;/P&gt;&lt;P&gt;It  contains field values for auth. objects.&lt;/P&gt;&lt;P&gt;What should be approach during Role build  phase?&lt;/P&gt;&lt;P&gt;How do i decide whether to maintain values in su24 or pfcg?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thankyou ,&lt;/P&gt;&lt;P&gt;Ajit&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Mar 2008 21:23:12 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/role-build/m-p/3581004#M862089</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-03-31T21:23:12Z</dc:date>
    </item>
    <item>
      <title>Re: Role Build?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/role-build/m-p/3581005#M862090</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Use PFCG while creating the role, Choose "do not select templates".  Then click on "Manually" and add the auth.obj given to you and later enter the values as specified.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Mar 2008 21:36:02 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/role-build/m-p/3581005#M862090</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-03-31T21:36:02Z</dc:date>
    </item>
    <item>
      <title>Re: Role Build?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/role-build/m-p/3581006#M862091</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could look in SU24 and make some suggestions back to them regarding which authorizations are included in the matrix, which are not included in the default start SU24 proposals. For those it is typically recommended to maintain SU24, but for some other scenarios it does not make sence.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You might also want to make some recommendations where the combination of the authorizations and the transactions might not make sense, or need to be analyzed closer. For example, an authorization for an object is included in the matrix and at the same time the same object is deactivated from an authority-check (No check) for a transaction which is also included in the role.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Mar 2008 21:40:30 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/role-build/m-p/3581006#M862091</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-03-31T21:40:30Z</dc:date>
    </item>
    <item>
      <title>Re: Role Build?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/role-build/m-p/3581007#M862092</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To maintain values in fields of auth objects you can use only PFCG.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While su24 is used only to specify or check which auth objects are checked or not checked (along with field vaules) during executions of a perticular tcode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So pfcg and su24 both have very diffrent funtionalities.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Apr 2008 10:02:56 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/role-build/m-p/3581007#M862092</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-04-01T10:02:56Z</dc:date>
    </item>
    <item>
      <title>Re: Role Build?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/role-build/m-p/3581008#M862093</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For SU24 values I have followed following procedure:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the transaction is only contained in one role, maintain ALL values within SU24 and use Expert mode for PFCG so that the values are fetched directly&lt;/P&gt;&lt;P&gt;(thus USOBT_C is adjusted).&lt;/P&gt;&lt;P&gt;If the transaction is duplicated across many roles, then update the values in SU24 to be "blank".  Then update the values directly in PFCG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this is rational way to do SU24 updates...!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rakesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Apr 2008 17:36:05 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/role-build/m-p/3581008#M862093</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-04-01T17:36:05Z</dc:date>
    </item>
    <item>
      <title>Re: Role Build?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/role-build/m-p/3581009#M862094</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Rakesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I agree that it is a rational way to perform SU24 updates.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Apr 2008 10:38:29 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/role-build/m-p/3581009#M862094</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-04-02T10:38:29Z</dc:date>
    </item>
    <item>
      <title>Re: Role Build?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/role-build/m-p/3581010#M862095</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;&amp;gt; While su24 is used only to specify or check which auth objects are checked or not checked (along with field vaules) during executions of a perticular tcode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only the ABAP controls what auth objects are checked or not checked.  SU24 can have some influence but you cannot add checks via SU24 or inactivate checks for a range of auth objects.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even outside the ABAP code, some checks are performed by the kernel e.g. S_TCODE, S_DATASET&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Apr 2008 10:40:23 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/role-build/m-p/3581010#M862095</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-04-02T10:40:23Z</dc:date>
    </item>
    <item>
      <title>Re: Role Build?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/role-build/m-p/3581011#M862096</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yip, that sounds rational.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2 possible things you might want to consider non-the-less:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- When deciding to add the transaction to a second role at a later stage, wanting different values, you might have to undo the SU24 values again, particularly if you add values for fields which are not "activity related".&lt;/P&gt;&lt;P&gt;- Ensure not only that the transaction is not included in any other role (menu), but also check that object S_TCODE with that value for field TCD is not in any "Check/Maintain" position for other transactions which you might have in other roles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Apr 2008 10:48:06 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/role-build/m-p/3581011#M862096</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-04-02T10:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: Role Build?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/role-build/m-p/3581012#M862097</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alex and Julius  I agree on that!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maintaining values in Su24 is used in rare scenarios depending on the well maitained role to transaction matrix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would love to use Su24 for Tcodes like MIGO(which calls other tcodes).It should be fine having only the auth objects required for MIGO and you do not necessarily have to have the associated objects included with those called transactions.S_Tcode takes care of it as it is hard coded and does the check asking for the "Called" transactions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rakesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Apr 2008 03:54:19 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/role-build/m-p/3581012#M862097</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-04-03T03:54:19Z</dc:date>
    </item>
  </channel>
</rss>

