<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Question Re: BEx Analyzer access in Technology Q&amp;A</title>
    <link>https://community.sap.com/t5/technology-q-a/bex-analyzer-access/qaa-p/5883610#M2170865</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;trying&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 01 Aug 2009 06:09:31 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2009-08-01T06:09:31Z</dc:date>
    <item>
      <title>BEx Analyzer access</title>
      <link>https://community.sap.com/t5/technology-q-a/bex-analyzer-access/qaq-p/5883598</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi experts!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have seen some posts about the subject but still is not very clear to me, i would appreciate your suggestions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We need to restrict bex analyzer access and we want to know if it is possible to do by applying some authorization objects, roles or security settings at BI level.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We need to reinforce control over bex analyzer deployment in client installations, but this is not immediately possible.&lt;/P&gt;&lt;P&gt;Even if that would be possible, we would like to reinforce security using some authorization constraint at BI level.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you in advance&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jul 2009 21:08:54 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/bex-analyzer-access/qaq-p/5883598</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-07-23T21:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: BEx Analyzer access</title>
      <link>https://community.sap.com/t5/technology-q-a/bex-analyzer-access/qaa-p/5883599#M2170854</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the Authorization Objects S_RS_COMP and S_RS_COMP1, make sure the activities are 03 and 16 (Display and Execute respectively). That should remove their ability to create or modifty a BEx Analyzer query.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jul 2009 21:36:32 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/bex-analyzer-access/qaa-p/5883599#M2170854</guid>
      <dc:creator>dennis_scoville4</dc:creator>
      <dc:date>2009-07-23T21:36:32Z</dc:date>
    </item>
    <item>
      <title>Re: BEx Analyzer access</title>
      <link>https://community.sap.com/t5/technology-q-a/bex-analyzer-access/qaa-p/5883600#M2170855</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Dennis&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That's true and actually users already have those restrictions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In fact we want to prevent unauthorized download of data to excel sheets from users who have installed bex analyzer but are not authorized to do that. Certain users only have to access querys from web and shouldn't have to use reports from bex analyzer, even if by accident they have installed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to know if the only way to do that is eliminating bex analyxer from their installations or exists another way to prevent this by using some authorization object(s).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jul 2009 22:11:40 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/bex-analyzer-access/qaa-p/5883600#M2170855</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-07-23T22:11:40Z</dc:date>
    </item>
    <item>
      <title>Re: BEx Analyzer access</title>
      <link>https://community.sap.com/t5/technology-q-a/bex-analyzer-access/qaa-p/5883601#M2170856</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try removing the authorization for the T-Code RRMX. Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Gaurav&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Jul 2009 05:14:44 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/bex-analyzer-access/qaa-p/5883601#M2170856</guid>
      <dc:creator>gaurav_kothari</dc:creator>
      <dc:date>2009-07-24T05:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: BEx Analyzer access</title>
      <link>https://community.sap.com/t5/technology-q-a/bex-analyzer-access/qaa-p/5883602#M2170857</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can do that restrictions in BI level by adding these authorizaiton components.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. S_RS_COMP&lt;/P&gt;&lt;P&gt;2. S_RS_COMP1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in these you have to maintain the info areas, multiproviders and info cubes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in S_RS_COMP1, please maintain the owners as well to restrict in user level.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Activity should be exeucte, display. if they are super users grant them create access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this would help you more.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Jul 2009 07:12:19 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/bex-analyzer-access/qaa-p/5883602#M2170857</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-07-24T07:12:19Z</dc:date>
    </item>
    <item>
      <title>Re: BEx Analyzer access</title>
      <link>https://community.sap.com/t5/technology-q-a/bex-analyzer-access/qaa-p/5883603#M2170858</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mohan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Final users roles already have these authorization objects, they can't modify reports.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe i'm not explaining clearly the problem. The only accepted way to access reports for all users is by using web querys published in our intranet. But many users have bex analyzer installed and we don't want that an unauthorized user download data to a excel sheet via bex analyzer.&lt;/P&gt;&lt;P&gt;I want to restrict bex analyzer access, not all access. We have a complete set of authorizations controlling data acces and of course final users can't create nor modify production querys. The only thing i want is specifically restrict access to bex analyzer. Of course too, if users don't have installed bex analyzer there isn't any problem, so they could only access web reports (the de facto standard) but the true is that yet we have a problem identifying and uninstalling bex analyzer from all the people who shouldn't have permissions to use it. Only a limited amount of authorized users may have the rights to do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Jul 2009 23:30:46 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/bex-analyzer-access/qaa-p/5883603#M2170858</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-07-24T23:30:46Z</dc:date>
    </item>
    <item>
      <title>Re: BEx Analyzer access</title>
      <link>https://community.sap.com/t5/technology-q-a/bex-analyzer-access/qaa-p/5883604#M2170859</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you check whether the users have access to the t-code RRMX ? If so you need to remove this access. Thus they will not be able to acess BEx.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Gaurav&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jul 2009 07:23:47 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/bex-analyzer-access/qaa-p/5883604#M2170859</guid>
      <dc:creator>gaurav_kothari</dc:creator>
      <dc:date>2009-07-27T07:23:47Z</dc:date>
    </item>
    <item>
      <title>Re: BEx Analyzer access</title>
      <link>https://community.sap.com/t5/technology-q-a/bex-analyzer-access/qaa-p/5883605#M2170860</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Gaurav&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank's again for your post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did a test, removing t-code RRMX from test user authorizations. This avoid access to bex from the transaction, but still let me use a report directly by executing START-&amp;gt;Programs-&amp;gt;Business Explorer-&amp;gt;Analyzer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As i seen removing t-code only avoids calling bex from "inside"  the system, but don't restrict using analyzer from "outside".&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jul 2009 19:04:50 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/bex-analyzer-access/qaa-p/5883605#M2170860</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-07-29T19:04:50Z</dc:date>
    </item>
    <item>
      <title>Re: BEx Analyzer access</title>
      <link>https://community.sap.com/t5/technology-q-a/bex-analyzer-access/qaa-p/5883606#M2170861</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the Authorization Object S_RS_COMP, do you have the following Activity values set for the users that you want to provide access to?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;01 - Create or generate&lt;/P&gt;&lt;P&gt;02 - Change&lt;/P&gt;&lt;P&gt;06 - Delete&lt;/P&gt;&lt;P&gt;22 - Enter, Include, Assign&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm assuming that this Authorization Object is already setup with Activity values:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;03 - Display&lt;/P&gt;&lt;P&gt;16 - Execute&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jul 2009 19:30:17 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/bex-analyzer-access/qaa-p/5883606#M2170861</guid>
      <dc:creator>dennis_scoville4</dc:creator>
      <dc:date>2009-07-29T19:30:17Z</dc:date>
    </item>
    <item>
      <title>Re: BEx Analyzer access</title>
      <link>https://community.sap.com/t5/technology-q-a/bex-analyzer-access/qaa-p/5883607#M2170862</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's right Dennis, actually authorization object S_RS_COMP only have activities 03 (Display) and 16 (Execute) in users roles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you say "for the users that you want to provide access to", remember that the thing i need to do is restrict access via bex analyzer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The scenario is this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Of all the users we have, only a restricted amount of them must access reports via bex analyzer ... all the rest should only access reports via portal/intranet.&lt;/P&gt;&lt;P&gt;The problem is that, from the group of users who only have this access, there are many of them who have bex analyzer installed and access reports directly from their front end installation (Start-&amp;gt;Programs-&amp;gt;Business Explorer-&amp;gt;Analyzer, not from RRMX).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other team is leading the task of remove bex analyzer installations from unauthorized users, but i want to know if there is also another way to prevent access from bex analyzer for users who should only access reports via portal/intranet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jul 2009 21:45:24 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/bex-analyzer-access/qaa-p/5883607#M2170862</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-07-29T21:45:24Z</dc:date>
    </item>
    <item>
      <title>Re: BEx Analyzer access</title>
      <link>https://community.sap.com/t5/technology-q-a/bex-analyzer-access/qaa-p/5883608#M2170863</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From my recollection, there is no way to be able to allow a user to only use BEx Web while not allowing the use of BEx Analyzer, because the Authorization Objects for BEx are based on queries, query elements and objects (e.g. InfoProviders, et. al.). Since they have access to a query, they can execute that query by any means they have available to them.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jul 2009 23:03:08 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/bex-analyzer-access/qaa-p/5883608#M2170863</guid>
      <dc:creator>dennis_scoville4</dc:creator>
      <dc:date>2009-07-29T23:03:08Z</dc:date>
    </item>
    <item>
      <title>Re: BEx Analyzer access</title>
      <link>https://community.sap.com/t5/technology-q-a/bex-analyzer-access/qaa-p/5883609#M2170864</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dennis, i think you are right, certainly we have to examine certain practices and policies.&lt;/P&gt;&lt;P&gt;This leads me to make other questions, but i think the particular issue is clear. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks to all you for your answers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Aug 2009 06:05:19 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/bex-analyzer-access/qaa-p/5883609#M2170864</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-08-01T06:05:19Z</dc:date>
    </item>
    <item>
      <title>Re: BEx Analyzer access</title>
      <link>https://community.sap.com/t5/technology-q-a/bex-analyzer-access/qaa-p/5883610#M2170865</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;trying&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Aug 2009 06:09:31 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/bex-analyzer-access/qaa-p/5883610#M2170865</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-08-01T06:09:31Z</dc:date>
    </item>
    <item>
      <title>Re: BEx Analyzer access</title>
      <link>https://community.sap.com/t5/technology-q-a/bex-analyzer-access/qaa-p/5883611#M2170866</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;closed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Aug 2009 06:10:24 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/bex-analyzer-access/qaa-p/5883611#M2170866</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-08-01T06:10:24Z</dc:date>
    </item>
    <item>
      <title>Re: BEx Analyzer access</title>
      <link>https://community.sap.com/t5/technology-q-a/bex-analyzer-access/qaa-p/5883612#M2170867</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just saw this thread in search for another.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IMHO it is possible to restrict the use of BEx analyzer. You can do this at userlevel. Mark the webquery users as "Communication users". Mark the BEx analyzer users as "Dialog users".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We used this in SAP BW version 3.1.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Oct 2010 07:06:37 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/bex-analyzer-access/qaa-p/5883612#M2170867</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-10-18T07:06:37Z</dc:date>
    </item>
  </channel>
</rss>

