<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Question Re: Complex authorizations in Technology Q&amp;A</title>
    <link>https://community.sap.com/t5/technology-q-a/complex-authorizations/qaa-p/926845#M336635</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Aswin,&lt;/P&gt;&lt;P&gt;  I am around this forum.Since i got registered as a customer my old points got transferred to my new userID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  As you suggest it all depend on how much complex scenario you want to implement.In my case we have 5 levels of security layer and we developed a security model and implemented with user Exit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Arun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 13 Jun 2005 20:18:48 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2005-06-13T20:18:48Z</dc:date>
    <item>
      <title>Complex authorizations</title>
      <link>https://community.sap.com/t5/technology-q-a/complex-authorizations/qaq-p/926841</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm having the following problem with authorizations:&lt;/P&gt;&lt;P&gt;I have one authorization object on e.g. 2 characteristics (0SALESORG, and 0DISTR_CHAN).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A specific user has 2 tasks in the organisation. He is responsible for:&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;UL&gt;&lt;LI level="1" type="ul"&gt;&lt;P&gt;Distribution Channel 'A' for all salesorgs in Europe&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;  &lt;/P&gt;&lt;UL&gt;&lt;LI level="1" type="ul"&gt;&lt;P&gt;All distribution channels for sales org NL&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I gave him authorization for:&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;UL&gt;&lt;LI level="1" type="ul"&gt;&lt;P&gt;0DISTR_CHAN  'A', 0SALESORG: 'EU*'&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;  &lt;/P&gt;&lt;UL&gt;&lt;LI level="1" type="ul"&gt;&lt;P&gt;0DISTR_CHAN  '*', 0SALESORG: 'EUNL'&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;This is a simplification of my actual problem, but describing the essence of the problem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, the user can run a specific query for both combinations. When he start the query, the variables are filled automatically with 0DISTR_CHAN: '&lt;STRONG&gt;', 0SALESORG 'EU&lt;/STRONG&gt;'. When executing the query, the pop up appears: 'No Authorization'. This is correct as the user may not see everything for these combinations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is: how can we make this user friendly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following options were mentioned by my team, but I don't like them:&lt;/P&gt;&lt;P&gt;  1. Create 2 user IDs for the user. One for task 1 and a second one for the second task. Logging on with the correct user ID will use the correct profile.&lt;/P&gt;&lt;P&gt;  2. Create 2 authorization object, two multiproviders, and two reports. When accessing report 1 only one authorization object is checked, and only one set of values is used for authorization. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are there any other solutions, like generating a pop-up where a user can select which profile he wants to use when he executes a report? &lt;/P&gt;&lt;P&gt;Any other ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Frank de Vleeschauwer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Jun 2005 15:14:22 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/complex-authorizations/qaq-p/926841</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2005-06-13T15:14:22Z</dc:date>
    </item>
    <item>
      <title>Re: Complex authorizations</title>
      <link>https://community.sap.com/t5/technology-q-a/complex-authorizations/qaa-p/926842#M336632</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;  you have to implement this logic with a user exit or you can assign authorizations based on the salses organization heirarchy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;with regards&lt;/P&gt;&lt;P&gt;ashwin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Message was edited by: Ashwin Kumar Gadi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Jun 2005 15:21:26 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/complex-authorizations/qaa-p/926842#M336632</guid>
      <dc:creator>Ashwin</dc:creator>
      <dc:date>2005-06-13T15:21:26Z</dc:date>
    </item>
    <item>
      <title>Re: Complex authorizations</title>
      <link>https://community.sap.com/t5/technology-q-a/complex-authorizations/qaa-p/926843#M336633</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt; Please take a look at the User exit for Virtual Characteristics &amp;amp; Key figures? We have implemented custom complex authorization by reading the Infocube data before populating it to the Data provider and modifying the custom field data with '&lt;DEL&gt;-' and set a filter in the template not to show '&lt;/DEL&gt;-' for that security field.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; You need to use the project 'RSR00002' involving 2 exits EXIT_SAPMRSRU_001, EXIT_SAPMRSRU_999 in the CMOD transaction.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Let me know if you need more explaination.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Arun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Jun 2005 19:59:41 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/complex-authorizations/qaa-p/926843#M336633</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2005-06-13T19:59:41Z</dc:date>
    </item>
    <item>
      <title>Re: Complex authorizations</title>
      <link>https://community.sap.com/t5/technology-q-a/complex-authorizations/qaa-p/926844#M336634</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Arun!&lt;/P&gt;&lt;P&gt;    Welcome to SDN. I think you are back to SDN after a long time.&lt;/P&gt;&lt;P&gt;   Regarding this issue... I think this can be solved using the heirarchies also which will be more robust in case of implementing more complex issues wich involve more levels of   dependencies.  whats your openion about  this...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;with regards&lt;/P&gt;&lt;P&gt;ashwin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Jun 2005 20:08:52 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/complex-authorizations/qaa-p/926844#M336634</guid>
      <dc:creator>Ashwin</dc:creator>
      <dc:date>2005-06-13T20:08:52Z</dc:date>
    </item>
    <item>
      <title>Re: Complex authorizations</title>
      <link>https://community.sap.com/t5/technology-q-a/complex-authorizations/qaa-p/926845#M336635</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Aswin,&lt;/P&gt;&lt;P&gt;  I am around this forum.Since i got registered as a customer my old points got transferred to my new userID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  As you suggest it all depend on how much complex scenario you want to implement.In my case we have 5 levels of security layer and we developed a security model and implemented with user Exit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Arun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Jun 2005 20:18:48 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/complex-authorizations/qaa-p/926845#M336635</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2005-06-13T20:18:48Z</dc:date>
    </item>
    <item>
      <title>Re: Complex authorizations</title>
      <link>https://community.sap.com/t5/technology-q-a/complex-authorizations/qaa-p/926846#M336636</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Arun,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for replying to my post. I know the user exits for virtual characteristics and key figures.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm just wondering how you use these in this complex authorization case.&lt;/P&gt;&lt;P&gt;The main problem we have is that we don't know at the start of the report, for what task the user is opening the report. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it for:&lt;/P&gt;&lt;UL&gt;&lt;LI level="1" type="ul"&gt;&lt;P&gt;Distribution Channel 'A' for all salesorgs in Europe OR&lt;/P&gt;&lt;/LI&gt;&lt;LI level="1" type="ul"&gt;&lt;P&gt;All distribution channels for sales org NL&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Depending on this choice, we have to enter the variables in the selection screen (via the variables user exits, this is easy). The problem is that I'm looking for a good way to deal this. I'm not sure that virtual characteristics can help me with this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Frank de Vleeschauwer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jun 2005 07:03:01 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/complex-authorizations/qaa-p/926846#M336636</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2005-06-14T07:03:01Z</dc:date>
    </item>
  </channel>
</rss>

