cancel
Showing results for 
Search instead for 
Did you mean: 

BPC in CUA environment

ivan_blatnik2
Participant
0 Kudos
484

Dear colleagues,

Could you pls share your experience with BPC in CUA environment. I know that OSS note http://service.sap.com/sap/support/notes/1757825 provides the workaround. My questions are:

  • is handling high number of BPC teams with workaround feasible (more then 50 / up to 300)
  • transporting roles to QA and PROD: as far as I understand technical names of the BPC roles may change when they are transported. There is a document which describes this - but I am not sure if it is relevant in our case http://scn.sap.com/docs/DOC-29197

Thank you

Ivan

Accepted Solutions (0)

Answers (2)

Answers (2)

0 Kudos

Hi Ivan,

Just wondering if you would be able to share you experiences with using CUA to manage security in BPC10.0?

Did you find a workable solution for managing BPC users day to day, as well as transporting new roles between Dev, QA and Prod?

There doesn't seem to be much information out there, other than note 1757825.

Thanks in advance,

Carlton.

Former Member
0 Kudos

if you don't get an answer then maybe its a good idea to open a new thread.

ivan_blatnik2
Participant
0 Kudos

Hi Carlton,

I have implemented BPC on CUA environment with approx 300 users previous year. I was involved as a external consultant so I don't have insight into daily operations. There are couple of admin settings for the environment to work and here I cannot give you details as it was done by BC team. After this is ready then daily operations are the following:

So everything is same except user's maintenanance (assign DAP, TP, team). This cannot be done in BPC. Instead you have to find technical names of the roles created during DAP, TP, team creation and assign these roles to users in BW user administration. The technical names of the roles are in tables which you can see in the note 1757825.

Regars

Ivan

0 Kudos

Hi Ivan,

Thanks for your detailed reply. It looks logical and is roughly what I was expecting.

Just a couple more questions if I may?

1. When you create Data Access Profiles, Task Profiles and Teams in BPC, the BW roles are automatically generated in the background. Did you generate these BW roles once in Development, and then transport these roles to QA and Produtcion?

2. Do you remember having to deal with BUI roles called ZBPC__BUI_<userid> ? These roles seem to be generated by the system for any user with task profiles related to the web client (e.g. live reports). The problem with these roles, is that they are user specific, and from a best practice point of view, it doesn't make sense to create them in Dev and then transport them to QA and Prod.

Thanks,

Carlton

Former Member
0 Kudos

Ivan,

While I do not have an answer to your question, this related document might prove beneficial:

SAP's Max Attention service had mentioned this to me, a while back.  I have not moved to this tool, yet, as our security methodology is relatively simple (will change over the next few months, though).  The one thing I remember being concerned with changing over to this is that once you go to this, you would have to rebuild everything in DEV and run a transport to get back to the traditional way of managing security, since the mass user management tool blows away the technical names, as I understand it.

There is another post ("Enhanced....") that acknowledges deletes in this tool have to be done one at a time, though.

I hope this is helpful for you.

Jeff