2010 May 17 4:24 PM
Hi
Mr Manisha Nadir helped for BI Hierarchy thread which i have posted earlier but unfortunaltely link is not found .
We took scenarios like users restricting on Infocube (Ex :Booking cube for US) and other hierarchy (On Account manager,Sales Region ).
In Rsecadmin just giving infoprov with infocube booking of US and Heierachy (Not maintained in Node like create and give ' 1' in RSECADMIN kind of thing ) . so just directly giving info objects into Rsecadmin .
Ex :account manager is lowest level and above to that sale area manager . so for salearea manager i am giving both account manger object and sales area manager . (In RSD1 i maintained i maintained Zsaleshier - account manager, sales region (maintained as attributes ) )
2> Other scenario if the user restrcting on DSO too .
Here if i maintain security like this, will it work properly or do i need follow any other way
2> Also if need help Tcodes for Develper and Power User roles. if any body can provide list will be greatly appreciated
Thanks in advance forhelp
Hi
Mr Manisha Nadir helped for BI Hierarchy thread which i have posted earlier but unfortunaltely link is not found .
We took scenarios like users restricting on Infocube (Ex :Booking cube for US) and other hierarchy (On Account manager,Sales Region ).
In Rsecadmin just giving infoprov with infocube booking of US and Heierachy (Not maintained in Node like create and give ' 1' in RSECADMIN kind of thing ) . so just directly giving info objects into Rsecadmin .
Ex :account manager is lowest level and above to that sale area manager . so for salearea manager i am giving both account manger object and sales area manager . (In RSD1 i maintained i maintained Zsaleshier - account manager, sales region (maintained as attributes ) )
2> Other scenario if the user restrcting on DSO too .
Here if i maintain security like this, will it work properly or do i need follow any other way
2> Also if need help Tcodes for Develper and Power User roles. if any body can provide list will be greatly appreciated
Thanks in advance forhelp
2010 May 17 7:16 PM
Hi,
Can you please clarify the whole structure of hierarchies as well as your exact requirements ?
Cheers,
Manisha
2010 May 17 7:42 PM
Hi
We are implementing BI sale organization , we have planned heirarchy for different levels as below
GHGlbal Globa; GHAREA Area,; GOPRTION Operation; GHREGION Region; GSUBRGN Sub-Region; GEUACTMGR User Acct. Mgr
Here if you see my category of heirarchy Account manager is lower level end user . Now as a secuirty person I know that we need to restrict characterstics 0TCAACTVT, 0TCAIPROV ,0TCAKYFNM, 0TCAVALID. For OTCAIPROV i was giving like if we want to restrict on Booking cube for US region , i was giving the ZSDCBK01 ( which shows all the data of US ) , for Heirarchy i was going to RSECADMIN >Heirarchy>create--> able to see only INFOAREHIER .
I checked with developer he said they are not maintained heierachy in RSD1 that is why i was not able to see any other , But he told they have created GSALEHIER with attributes as( GHGlbal Globa; GHAREA Area,; GOPRTION Operation; GHREGION Region; GSUBRGN Sub-Region; GEUACTMGR User Acct. Mgr) .
Now i was confused how to maintain Heirarchy to worl , if you have Tcode list of Developer role and Power User roles please provide
2010 May 18 4:35 AM
Hi
Are you trying to have hierarchy maintained for info providers. If yes you need to go to infoobject OTCAIPROV --> Click on details --> Hierarchy Authrizations > Create-> Click on select hierarchy beside "Hierarchy" and select "INFOAREHIER" --> Click on select hierarchy beside "Nodes" and selec the node(Info area) where you want to restrict the users --> Enter teh values for Type of authrizations --> Click on continue.
Values that can be maintained for type of Authrizations
0 Only the Selected Nodes
1 Subtree Below Nodes
2 Subtree Below Nodes to Level (Incl.)
3 Complete Hierarchy
4 Subtree Below Nodes to (and Incl.) Level (Relative)
If you want to restrict on sales organization then you need to add add the infoobject(characteristics) for Sales organisation(GSALEHIER) and select the characteristics and click on details. Follow the steps for maintaing the hierachy authrizations(Similar to as explained for Infoproviders).
Developer role tcodes
Please see the following discussion
Power user roles
Power user roles should differ from end user roles for teh objects like S_USER_AGR , S_RS_COMP & S_RS_COMP1.
Through S_USER_AGR, user should be provided change access for teh resporting role so that can add queries to the reporting role.
S_RS_COMP & S_RS_COMP1 should provide access for creating and modifying queries.
Thanks.
Anjan
2010 May 18 5:08 AM
Hi
You may want to check following links for some details on maintaining hierarchy authrizations.
http://www.bwarea.com/2009/01/sap-bi-70-authorization-part-1.html
Thanks.
Anjan
2010 May 18 10:45 PM
If yes you need to go to infoobject OTCAIPROV --> Click on details --> Hierarchy Authrizations > Create-> Click on select hierarchy beside "Hierarchy" and select "INFOAREHIER" --> Click on select hierarchy beside "Nodes" and selec the node(Info area) where you want to restrict the users --> Enter teh values for Type of authrizations --> Click on continue.
1>I was doing like this but as i want to resrict accordint to hierarchy structure not able to see any node heirarchy like(GHGlbal Globa; GHAREA Area,; GOPRTION Operation; GHREGION Region; GSUBRGN Sub-Region; GEUACTMGR User Acct. Mgr)
Do i need ask to my developer maintain heirarchy in RSD1 to see in Rsecadmin (-->..........>Hierarchy beside nodes and select nodes ?)
2>Second scenario checking to maintain GSALEHIER object(Auth relavent ) , In hierarchy tab -create it is saying no hierarchy maintained .
Initially i want to show an example just lower level (GEUACTMGR) user with display reports for US and EMEA etc and above to that hierarchy GSUBRGN . which he can see the lower level .
Can you give some inputs what i need to request Developer team to create for security
3> if suppose user moves to another location/Region high we maintain hierarchy (We are not using HR system )
4>while i was testing getting "no application data found error " and not able view anything log while i check Rsecadmin -->anlasys auth log -->giving nothing not able to see any log for the error . But i have seen earlier data log for couple of days . why the errors for today not showing to analyze . i have not dates and user and checked also ..we are on EHP 1
2010 May 18 11:43 AM
Hi,
In an analysis authorization, when you directly add infoobjects , you can either give value authorizations to them or hierarchy authorizations or both. Based on your requirement, you may add the info object for ales Organization GSALE HIER and either give value auth to it like the values for nodes GHAREA,GHREGION etc. or you may authorization based on hierarchies for different nodes like GHAREA etc. It all depends on your requirement.
Anjan has already given clarifications on the different hierarchy levels to select or you can do some F1 to find out the documentation for that .
For the developer and power role tcodes, the tcodes won't differ much but the basic difference will be with the authorizations you provide in the authorization objects( create/change/display query , edit data etc. ) . You can also go to table TSTCA and filter the result for RS* which will give you list of TCODES related to BW .
Hope this helps.
Regards,
Manisha
2010 May 19 8:35 AM
Hi,
You have said that you want to give hierarchy based authorization on sales organization hierarchy. For this, first you need to get the hierarchy maintained for sales organization on the infoobject GSALEHIER , ask your developers to do so in RSA1/RSD1.
This hierarchy will have nodes for Global, Area, Operation, Region etc.
Once this is done, you can add the Infoobject GSALEHIER in your analysis authorization and maintain hierarchy by going to hierercahy authorizations for this characteristic and select the " now " maintained hierrachy which will show up in your list. Then you can select the appropriate nodes based on what your requirement is for that specific analysis authorization and accordingly also select the type of hierrachy authorization( node level auth ) .
for OTCAIPROV, you can give the values of Infoproviders accessible through this role . If you also want to give specific values of Info areas, then you can also add characteristic 0TCTIFAREA and then give specific values to it for info areas
If a user changes his position, then in that case you should have roles giving authorization to different nodes in the sales organization hierarchy. So, if a user moves from Region to operation, he will have to be given the role giving node access for Operation and the region level role needs to be removed.
For your RSECADMIN log related query, please clarify as to what exactly was being checked and if cubes don't contain any data then also you will get this error.
Hope this helps.
Regards,
Manisha
2010 May 19 9:33 AM
Hi
Request you to go through the document in the attached link to learn how BI 7.0 Security works(Some of your queries will be resolved after reading through the document).
Click on "View This Presenation" to view the file.
Thanks.
Anjan
| User | Count |
|---|---|
| 4 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |