2006 Dec 26 2:44 AM
Hi. I have a question on assigning authorization to user.
For example, user couldnt execute t-code ksv1, I have the authorization object information from t-code su53.
Method 1: from pfcg->role tab, I can assign the t-code ksv1 to the role by Add transaction and save
Method 2: from pfcg->authorization tab->change authorization data, + selection criteria of the authorization object from su53, generate and save.
Question:
whatre the difference between the 2 methods above to assign authorization? What would be the preferred method?
Appreciate any guidelines on this.
2006 Dec 29 9:08 PM
Hi,
Whenever you add a new Tcode in a role using PFCG suing method 1, respective authorization objects which are maintained for the particular tocde will be picked automatically .
You can see the authorization obejcts by using method 2, Under the authorization object defalut values will appear.(Green Color), esle if there is any missing value (yellow color/light)then you have to maintian the values.
The SU53 will show the missing values for the particular authorization object.
Note: Before you make changes to the roles please always select "read old status& edit new data" i.e. while follwing step 2 to avoid Yellow light problem.
Second before you edit any SAP Default values , first copy the authorization object from the standard and make the standard as Inactive and do the changes to the copied one(new)
Cheero
Pradeep Gali
Hi. I have a question on assigning authorization to user.
For example, user couldnt execute t-code ksv1, I have the authorization object information from t-code su53.
Method 1: from pfcg->role tab, I can assign the t-code ksv1 to the role by Add transaction and save
Method 2: from pfcg->authorization tab->change authorization data, + selection criteria of the authorization object from su53, generate and save.
Question:
whatre the difference between the 2 methods above to assign authorization? What would be the preferred method?
Appreciate any guidelines on this.
2006 Dec 26 3:54 AM
Dear Goay,
Both methods will do the need, but i feel the second method is more preferable, since, along with the authorization objects we can even specify the permission too. i.e., Display, create, delete etc, we can set for a particular authorization object using the second method.
with regards,
Raj
2006 Dec 26 4:47 AM
Hi,
if T-code is missing you need to add tcode or edit S_tcode object
if Tcode is existing and only perticular activity is missing then add manually(second method)
samrat
2006 Dec 26 1:01 PM
Hi Goay,
The concept of Auth is not just adding the Tcode to any Role or the Objects. With the advent of SOX, you have to keep in mind various things.
Please check in these lines when ever u get any SU53 screen from the end user.
1. IS the SU53 screen correct one or is it giving any worng display as some times users handle it wrongly thereby generating wrong SU53 screens ( typically S_TRANSLAT object is shown some times ).
2. Once its OK, check why the End user needs it if its a Tcode. The only thing is if its a new requirement its OK else we need to check why the end user is looking for this new Tcode.
3.If decided and approved that the User shd get this Tcode, then check for any existing roles that have the Tcode and look if its OK to provide that role to this User.
4. If provision of that role provides the user lot many tcodes which he is not supposed to then check if it can be added to his existing matrix.
For Eg, If a user perfoprming the role of a BUYER needs a Tcode XXX, then check if XXX is in any Role, else check if any roles specifically created for Buyer are available and add XXX to that role so that the matrix is not disturbed.
Coming to option 2 in ur Q, then i think its not advisable to checnge the Objects manually, as tracing why the object is given and when and for which request cannot be traced. So its better to add the Tcode in PFCG role tab and he edit the relevant Objects.
I go with metyhod 1 and as said, if S_TCODE does not contain your new Tcode, then there would be no use ammending the other Auth.
Hope it Helps.
br,
Sri
<i>Award points for helpful answers</i>
2006 Dec 29 9:08 PM
Hi,
Whenever you add a new Tcode in a role using PFCG suing method 1, respective authorization objects which are maintained for the particular tocde will be picked automatically .
You can see the authorization obejcts by using method 2, Under the authorization object defalut values will appear.(Green Color), esle if there is any missing value (yellow color/light)then you have to maintian the values.
The SU53 will show the missing values for the particular authorization object.
Note: Before you make changes to the roles please always select "read old status& edit new data" i.e. while follwing step 2 to avoid Yellow light problem.
Second before you edit any SAP Default values , first copy the authorization object from the standard and make the standard as Inactive and do the changes to the copied one(new)
Cheero
Pradeep Gali