‎2009 Jun 17 7:38 AM
Hi,
We did upgradation from 4.6B to ECC.We have encountered the below mentioned issue. Please check and advice.
In 4.6B, we can delete Tcodes from S_TCODE also instead of deleting in MENU level in a Role. Previously, our people have deleted Tcodes directly in S_TCODE level instead of deleting from MENU level in some of the roles.
After upgrade from 4.6B to ECC, we have encountered a problem like all the Tcodes which are their in MENU got pushed to S_TCODE and we are also able to find Tcodes which we had directly removed from S_TCODE in the roles.
Is their any possibility to get the list of roles which were affected like that in upgrade?
We should not delete Tcodes directly from s_tcode as per standards. But it happened previously. In ECC, SAP is not giving chance to delete Tcodes directly from S_TCODE.It is good thing.
Please check and advice me on the above mentioned query.
Thanks & Regards,
KKRao.
‎2009 Jun 18 6:32 AM
>
> After upgrade from 4.6B to ECC, we have encountered a problem like all the Tcodes which are their in MENU got pushed to S_TCODE and we are also able to find Tcodes which we had directly removed from S_TCODE in the roles.
>
> Is their any possibility to get the list of roles which were affected like that in upgrade?
Hi,
all your roles, which have different t-code entries in the menu compared to the manual changed S_TCODE authorizations are affected. Please refer to the famous SAP note 113290.
If you have not merged the authorizations yet after upgrade (for instance by going through SU25 2.x), you could try to get that information from SUIM.
First selection Roles by complex selection cirteria (S_BCE_68001425)->enter role name. On the result list press the button 'Transaction assignements' (CtrlShftF11)
-->this shows you the t-codes contained in the menu
Then press 'Profile assignements' (CtrlShftF10). Expand the profile(s) by doubleclicking on the profile name and expand the Object S_TCODE (field TCD). This will give you the list of t-codes contained in the authorization.
If there is a delta, this role will be affected at next merge.
I don't think it is worth the effort to find out which roles are affected. Rather take the upgrade as opportunity to redesign/rebuilt your roles. Sooner or later you will have to do this anyway 8remember that it is necessary to go through SU25...... to get the new authorizations for the new implemented checks and there will be a lot of them as the difference between 46B and 700 is quite big!
So the best idea will be to set up new roles as part of a new authorization concept..... as struggling with the old ones might be much more time consuming than starting from scratch.
b.rgds,
Bernhard
‎2009 Jun 17 12:06 PM
Hi,
Could you please check and advice on the above mentioned issue?
Thanks & Regards,
KKRao.
‎2009 Jun 17 12:54 PM
>
> Hi,
>
> Could you please check and advice on the above mentioned issue?
>
> Thanks & Regards,
> KKRao.
How much are you paying for the SDN support that requires people to give answers at short notice?
‎2009 Jun 17 12:32 PM
> After upgrade from 4.6B to ECC, we have encountered a problem like all the Tcodes which are their in MENU got pushed to S_TCODE and we are also able to find Tcodes which we had directly removed from S_TCODE in the roles.
>
Are those Deleted TCodes (from S_TCODE) are still present in S_TCODE or in Menu? Please clarify..
> Is their any possibility to get the list of roles which were affected like that in upgrade?
>
Check in table CD1251... put the Object S_TCOODE and execute.. let me know if you
> We should not delete Tcodes directly from s_tcode as per standards. But it happened previously. In ECC, SAP is not giving chance to delete Tcodes directly from S_TCODE.It is good thing.
>
You should not add or remove TCode by adding S_TCODE manually in the authorization tab unless it is really necessary.
Regards,
Dipanjan
‎2009 Jun 17 1:37 PM
Hi,
Thanks for your update.
Please find the below information:
Q1) Are those Deleted TCodes (from S_TCODE) are still present in S_TCODE or in Menu? Please clarify..
Ans: Yes, those Tcodes are present in S_TCODE level and Menu level also.
Q2) Check in table CD1251... put the Object S_TCOODE and execute.. Let me know if you
When we run this table, we are getting message like No table entries found for specified key.
Q3) You should not add or remove TCode by adding S_TCODE manually in the authorization tab unless it is really necessary.
Ans: Yes, I will agree for this.
Please check and advice me if their any possibility to get the list of roles.
Regards,
KKRao.
‎2009 Jun 17 2:37 PM
>
> Q1) Are those Deleted TCodes (from S_TCODE) are still present in S_TCODE or in Menu? Please clarify..
>
> Ans: Yes, those Tcodes are present in S_TCODE level and Menu level also.
>
Then it become simple... just remove them from the menu and generate the profile by entering into the Authorization in "Expert Mode" -> "Change Old status and Merge with New Data"... Also I would like to suggest you to reassess the authorization structure of your Landscape for more efficient usage. Instead if searching those roles where TCodes were removed manually from S_TCODE rather than menu.
> Q2) Check in table CD1251... put the Object S_TCOODE and execute.. Let me know if you
>
> When we run this table, we are getting message like No table entries found for specified key.
>
hmmm..... can you please try SCU3 and change log of AGR_1251 (if logging is active)? really speaking, it is a tough Job or merely impossible to sort out those roles where these changes were carried out on 4.6B
> Q3) You should not add or remove TCode by adding S_TCODE manually in the authorization tab unless it is really necessary.
>
> Ans: Yes, I will agree for this.
>
> Please check and advice me if their any possibility to get the list of roles.
>
One more question .. what did you get in the 2C and 2D steps during Security Upgrade? Also please think about to go for restructuring Role design as you have crossed a long way from 4.6B to ECC --- a big jump..!!
Regards,
Dipanjan
‎2009 Jun 18 6:32 AM
>
> After upgrade from 4.6B to ECC, we have encountered a problem like all the Tcodes which are their in MENU got pushed to S_TCODE and we are also able to find Tcodes which we had directly removed from S_TCODE in the roles.
>
> Is their any possibility to get the list of roles which were affected like that in upgrade?
Hi,
all your roles, which have different t-code entries in the menu compared to the manual changed S_TCODE authorizations are affected. Please refer to the famous SAP note 113290.
If you have not merged the authorizations yet after upgrade (for instance by going through SU25 2.x), you could try to get that information from SUIM.
First selection Roles by complex selection cirteria (S_BCE_68001425)->enter role name. On the result list press the button 'Transaction assignements' (CtrlShftF11)
-->this shows you the t-codes contained in the menu
Then press 'Profile assignements' (CtrlShftF10). Expand the profile(s) by doubleclicking on the profile name and expand the Object S_TCODE (field TCD). This will give you the list of t-codes contained in the authorization.
If there is a delta, this role will be affected at next merge.
I don't think it is worth the effort to find out which roles are affected. Rather take the upgrade as opportunity to redesign/rebuilt your roles. Sooner or later you will have to do this anyway 8remember that it is necessary to go through SU25...... to get the new authorizations for the new implemented checks and there will be a lot of them as the difference between 46B and 700 is quite big!
So the best idea will be to set up new roles as part of a new authorization concept..... as struggling with the old ones might be much more time consuming than starting from scratch.
b.rgds,
Bernhard
‎2009 Jun 18 4:23 PM
>
> I don't think it is worth the effort to find out which roles are affected. Rather take the upgrade as opportunity to redesign/rebuilt your roles. Sooner or later you will have to do this anyway 8remember that it is necessary to go through SU25...... to get the new authorizations for the new implemented checks and there will be a lot of them as the difference between 46B and 700 is quite big!
>
> So the best idea will be to set up new roles as part of a new authorization concept..... as struggling with the old ones might be much more time consuming than starting from scratch.
>
> b.rgds,
> Bernhard
Yes.. I am also agree with this ... in fact I have already mentioned this in my post. Please do this..
Regards,
Dipanjan
‎2009 Jun 18 9:06 PM
I add my vote to Bernhard and Dipanjan as well.
> We did upgradation from 4.6B to ECC.
Too long, too many changes, too many manual entries, too many bugs, too many "original" entries, too many new objects and improved "proposals", major change in the buffering mechanism, many new and obsolete transactions not all of which are in SU25 step 2d, etc..
Starting on a clean slate should be considered as a serious option for future sustainability and ease of administration of the role concept.
Cheers,
Julius
‎2009 Jun 19 4:27 AM