2012 Jan 27 11:06 AM
HI,
We are using context sensitive authorisations.
We have a user who has 2 roles u2013
ZZ_HR_ORM_TRAIN_COORD (Structural profile u2013 ZZ_ORM) u2013 employee subgroup restricted - Z1,Z2, Z4, Z5
ZZ_HR_TRAINING_MANAGER (Structural profile u2013 ZZ_HR) - * access
Structural profiles are same and has access to objetcs Q, QK , P ( For qualifications) . Just the name are different i.e. ZZ_HR and ZZ_ORM
The qualifications info type -0024 is maintained in both roles and structural profile values are same
So according to user buffer has both the authorisations. User is not able to do any work on employee subgroup u2013 Z3 because the role ZZ_HR_ORM_TRAIN_COORD is taking precedence over the other role - ZZ_HR_TRAINING_MANAGER because it is not allowing to do anything for employee subgroup u2013 Z3 even if the user has access to ZZ_HR_TRAINING_MANAGER which has * access.
HI,
We are using context sensitive authorisations.
We have a user who has 2 roles u2013
ZZ_HR_ORM_TRAIN_COORD (Structural profile u2013 ZZ_ORM) u2013 employee subgroup restricted - Z1,Z2, Z4, Z5
ZZ_HR_TRAINING_MANAGER (Structural profile u2013 ZZ_HR) - * access
Structural profiles are same and has access to objetcs Q, QK , P ( For qualifications) . Just the name are different i.e. ZZ_HR and ZZ_ORM
The qualifications info type -0024 is maintained in both roles and structural profile values are same
So according to user buffer has both the authorisations. User is not able to do any work on employee subgroup u2013 Z3 because the role ZZ_HR_ORM_TRAIN_COORD is taking precedence over the other role - ZZ_HR_TRAINING_MANAGER because it is not allowing to do anything for employee subgroup u2013 Z3 even if the user has access to ZZ_HR_TRAINING_MANAGER which has * access.
2012 Jan 28 10:40 AM
Hi,
There can be various reasons for such behaviour. But before I suggest a solution, can you tell what all Structural authorizations are assigned to the user?
Thanks,
Deb
2012 Jan 28 1:46 PM
Hi,
There are 3 structural authorisations -
ZZ_ALL
ZZ_HR
ZZ_ORM
ZZ_ALL 1 01 O 0
ZZ_ALL 2 01 A 0
ZZ_ALL 3 01 AC 0
ZZ_ALL 4 01 AG 0
ZZ_ALL 5 01 AP 0
ZZ_ALL 6 01 B 0
ZZ_ALL 7 01 BA 0
ZZ_ALL 8 01 BG 0
ZZ_ALL 9 01 BK 0
ZZ_ALL 10 01 BL 0
ZZ_ALL 11 01 BP 0
ZZ_ALL 12 01 BS 0
ZZ_ALL 13 01 BU 0
ZZ_ALL 14 01 C 0
ZZ_ALL 15 01 CP 0
ZZ_ALL 16 01 D 0
ZZ_ALL 17 01 E 0
ZZ_ALL 18 01 EG 0
ZZ_ALL 19 01 EP 0
ZZ_ALL 20 01 F 0
ZZ_ALL 21 01 FA 0
ZZ_ALL 22 01 G 0
ZZ_ALL 23 01 H 0
ZZ_ALL 24 01 I1 0
ZZ_ALL 25 01 I2 0
ZZ_ALL 26 01 I3 0
ZZ_ALL 27 01 IA 0
ZZ_ALL 28 01 IB 0
ZZ_ALL 29 01 IC 0
ZZ_ALL 30 01 ID 0
ZZ_ALL 107 01 S 0
ZZ_ALL 108 01 P 0
ZZ_ALL 109 01 G 0
ZZ_ALL 110 01 H 0
ZZ_ALL 111 01 U 0
ZZ_ALL 112 01 R 0
ZZ_HR 1 01 QK 0
ZZ_HR 2 01 Q 0
ZZ_HR 3 01 P 0
ZZ_ORM 1 01 QK 0
ZZ_ORM 2 01 Q 0
ZZ_ORM 3 01 P 0
____________ ___ __ __ ________
Basically ZZ_HR and ZZ_ORM are same in terms of values.
The role ZZ_HR_TRAIN_COORD takes precednece over ZZ_HR_TRAINING_MANAGER
for infotype 0024
-
I might sound stupid here but i feel if we change the order of roles in SU01 i.e. if Training Coordinator comes up in order than Training manager roles then Co-ordinator takes precedence. ---
does the order to roles cause problem.
2012 Jan 30 2:02 PM
Hi,
1. I don't see Z_ALL have Objects QK, Q, P. If this AA is assigned to the user, how is this accounted for in the Context Solution for the user? Is there any role assigned to the user having PROF Field = Z_ALL?
2. Both ZZ_HR and ZZ_ORM is pulling same Objects and both of them are assigned to the user and both of them are accounted in the roles under PROF field. What do you think SAP is going to do? Objects coming from which AA should SAP consider? Don't you think SAP will be confused here?
3. Go to OOSB and pull out a list of all the Objects retrieved from AAs assigned to the user. Find out Objects QK, Q,P are coming from which AA (The first column will show that). If these objects are coming from ZZ_HR then the P_ORGINCON having ZZ_HR will be used during auth check, else the other one. Ideally both AA with same objects should be listed there.
Can you please provide here OOSB output for both these AA for the user?
2012 Jan 30 3:34 PM
Hi,
1) ZZ_ALL doesnt have access to QK, Q. It has access to P
2) You have a valid point. Which should SAP consider. But i think that auth checks need to pe performed with access to P_ORGINON with both instances of auth in user buffer. In case if instance doesnt get auth; then the other can be used.
3) Maint - checked
ZZ_ORM 003 01 P 0 X
ZZ_ORM 003 01 P 0 X
ZZ_HR 003 01 P 0 X
ZZ_HR 003 01 P 0 X
ZZ_ORM 003 01 P 0 X
ZZ_HR 002 01 Q 0 X
ZZ_ORM 002 01 Q 0 X
ZZ_ORM 002 01 Q 0 X
ZZ_HR 002 01 Q 0 X
ZZ_ORM 002 01 Q 0 X
ZZ_ORM 001 01 QK 0 X
ZZ_HR 001 01 QK 0 X
ZZ_ORM 001 01 QK 0 X
ZZ_ORM 001 01 QK 0 X
ZZ_HR 001 01 QK 0 X
2012 Jan 30 7:21 PM
1. Right. But my question is why is this AA assigned to the user? On what context it is reading PA authorizations? Is there any role assigned to the user having PROF = Z_ALL? might not be directly related to this issue, but is unnecessary confusing SAP on Object P
2. I understand your point, can you remove Z_ALL from the user and then try? Also trace out for authorization check.
Edited by: Debmalya Majumdar on Jan 30, 2012 8:22 PM
| User | Count |
|---|---|
| 4 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |