2010 Jul 16 3:52 PM
We are implementing BI security sales hierarchy, now we have created analysis role as billing, booking etc .
Now in analysis role we have are giving default characterstics (actvt, validity, infoprovider) . In infoprovider characterstic (WANT TO RESTRICT BILLING PROVIDER ) .
selecting hierarchy and selecting the node
Hierarchy INFOAREAHIER/89991231/INFOPROV
Nodes zdb_bill
Type of authorization - 2
Hierarchy Level -2
validity -2
If i am giving 2,2,2 or 1 ,0, 1 it is working , Here not able to understand how the hierarchy level and type of authorization working . and values need to be given . and in hierarchy node we have only one node INFOAREAHIER do we need create any separate
hierachy nodes other than INFOAREAHIER.
For region we have created separate role and giving all characterstics -zarea,zregion(with *),etc . but user heierarchy is giving in Ztable thru se16 and assigning as developer created this z hierachy table .
Edited by: rao M on Jul 16, 2010 4:52 PM
We are implementing BI security sales hierarchy, now we have created analysis role as billing, booking etc .
Now in analysis role we have are giving default characterstics (actvt, validity, infoprovider) . In infoprovider characterstic (WANT TO RESTRICT BILLING PROVIDER ) .
selecting hierarchy and selecting the node
Hierarchy INFOAREAHIER/89991231/INFOPROV
Nodes zdb_bill
Type of authorization - 2
Hierarchy Level -2
validity -2
If i am giving 2,2,2 or 1 ,0, 1 it is working , Here not able to understand how the hierarchy level and type of authorization working . and values need to be given . and in hierarchy node we have only one node INFOAREAHIER do we need create any separate
hierachy nodes other than INFOAREAHIER.
For region we have created separate role and giving all characterstics -zarea,zregion(with *),etc . but user heierarchy is giving in Ztable thru se16 and assigning as developer created this z hierachy table .
Edited by: rao M on Jul 16, 2010 4:52 PM
2010 Jul 16 5:21 PM
Here is some notes I am sharing from my side see if it helps:
It is Equivalent to value
authorizations in SAP BI security
Look at a, b, and C
a. You can have hierarchy options as below:
1.Only the selected nodes
2.Subtree below nodes
3.Subtree below nodes to level (incl.)
4.Complete hierarchy
5.Subtree below nodes to (and including) level (relative)
& set Validity range with options as follows:
Validity Range gives you Which authorization hierarchy is checked against the currently used hierarchy (strictness of check)?
1.Name, Version Identical, and Key Date Less Than or Equal to
2.Name and Version Identical
3.Name Identical
4.All Hierarchies
b. you can also Add 0TCAIFAREA as
an external hierarchy
characteristic to
0INFOPROV
C. In OTCAIPROV technical object:
You can have Selection of InfoProviders based on InfoArea hierarchy
2010 Jul 16 5:36 PM
Rao,
Now in analysis role we have are giving default characterstics (actvt, validity, infoprovider) . In infoprovider characterstic (WANT TO RESTRICT BILLING PROVIDER ) .
You have to look for BILLING PROVIDER info object and add it to this analysis object ad restrict it on the hierarchy nodes.
Thanks,
Sri
2010 Jul 16 6:33 PM
Thank you frank and sri for your quick help
Frank you have given hierarchy options, but i have seen if you give 1,3 (typer of authorization) than default it is taking as 0 (zero) hierarchy . and if am giving 2 than it is allowing me to give some - type of authorization (either 1,2,3 ..). Not able to understand what exact values to maintain .
As per your C type i am giving characterstic INFOPROVIDER , select hierarchy - INFOAREAHIER/89991231/INFOPROV - selection giveing values , still i was not clear going in right way or not .
Sri, I am confused here to restrict billing or booking heirarchy whether i have to request developement team to create
seperate auth relavent infoobject for billing or bokking (as we are not using adding infoobject ex:adding infoobject in resecadmin and giving values like z*) . But i have created separate analysis roles for billing , booking (z_io_billing) etc giving INFOPROVIDER, activity, validity . In INFOPROVIDER iam giving node which is related to billing or booking etc thru characterstic infoprovider and g INFOAREAHIER hierachy .
2010 Jul 16 6:42 PM
Rao,
I will consult one of our BI Business analyst to give the correct direction , I am not a BI functional expert.
it will take a little time (MST). From what I observe in your postings you are almost in the correct direction
some setting is not done properly
Will get back to you .
When you are maintaining authorizations ( in the Definition of Hierarchy authorization window )
in the NODES ( row ) second button on the right extreme , can you see if you can use Variables ?
2010 Jul 16 6:58 PM
Hi Rao,
But i have created separate analysis roles for billing , booking (z_io_billing) etc giving INFOPROVIDER, activity, validity . In INFOPROVIDER.
This will work
I am giving node which is related to billing or booking etc thru characterstic infoprovider and g INFOAREAHIER hierachy .
I am not sure if that will work, but try.
Thanks,
Sri
2010 Jul 16 7:16 PM
Personally the idea provided by Sri has to work.
the objects and attrubutes checked should be structured correctly including your Hierachial levels.
2010 Jul 16 6:35 PM
Additional information/SAP security DOC.
a. If you have still not achieved this you can use Variables in Authorizations for VALUE / Hierarchy.
Even this will not help you then
b. Assign groups of authorizations:
You can group authorizations into
a hierarchy. Use InfoObject
0TCTAUTH for this hierarchy
(youu2019ll have to activate the content
objects for this InfoObject).
Then you can assign one or
several authorization groups to
the selected user
2010 Jul 16 8:15 PM
Thanks you guys for your answers, but again putting my design queries
We have created custom table for Area, subregion Hierarchy , we are planning to assign an user through se16 table .
so that user will get access to region . Is this right way or not
Second question is that if i create billing, booking analysis role .
giving hierarchy through INFOPROVIDER heirarchy node and giving billing/booking node . My question is if we give INFOPROVIDER characterstic is this right way or we have to create separate billing characterstic and should give hierarchy node .
Third question is what values to maintain in node values
Already i have tested with INFOPROVIDER Characterstic it is working, but after i design it should not get an problem . that is reason checking it feasable way or not
Hierarchy INFOAREAHIER/89991231/INFOPROV
Nodes zdb_bill
Type of authorization - 2
Hierarchy Level -2
validity -2
If i am giving 2,2,2 or 1 ,0, 1 it is working , Here not able to understand how the hierarchy level and type of authorization working
2010 Jul 16 8:27 PM
I will say that this idea is not good, who will maintain the table and why do you want to administer the user through a table?
what is the exact reason to build this table?
Can you list the reasons regarding the table , if you have tried out all options given to you by SAP
I also think table maintenance will be an issue in production ? and who will maintain the table? I mean in production system
Edited by: Franklin Jayasim on Jul 16, 2010 9:38 PM
2010 Jul 17 8:38 AM
rao,
We have created custom table for Area, subregion Hierarchy , we are planning to assign an user through se16 table .
so that user will get access to region . Is this right way or not ?
First you find out from your ABAers how many region you need to restrict. If it is less than 30 regions,then go with
role base design concept.
If regions are more,ABABer will create a table in that table once colum will be for users / second colum will be nodes and third colum will be users.
So when user executes the query, based on run time variable .
eg1: LEt say that user1 has access to region1, then at run time he gets a popup screen to enter variable..so he see tha data for region1
Eg2: Let say user 2 ,should have access to region 1 to region 50 ? (consolidated data)
if you follow eg1. then its tedious process for this user to enter 50 region one at a time.
So best option is to maintain it in table. i.e In the table it self they will link which user has to access to which regions.
So at run time you need out need to enter values for variable. See the word doc.
PS: while creating a role for restricting query you have to include the variable, so that at run time the user will will get the correct region data.
No need to give se16 access to the users.
Thanks,
Sri
2010 Jul 17 6:11 PM
Thanks for your explanation, we are taking second example which we have so many regions and subregions - according to our helpdesk ticket we are going to give the region/subregion selection will be given thru se16 by security person not by any other user (No Other person will have access to se16 in production),so that No need to select variable selection . also thinking if we can create zse16 it would be good .