cancel
Showing results for 
Search instead for 
Did you mean: 

How to create authorisation restriction in S/4Hana embedded analytics story

hoornvm
Discoverer
0 Kudos
578

We have build a new story in embedded SAC and this report is showing the booked hours from the app " Manage my Timesheet'. Now this report contains also the cost center field and on this field we want to setup an authorisation restriction. So we have build an application for this story and then you need to link this to a business catalog. We picked business catalog SAP_FIN_BC_OH_REP_CCA_PC as this catalog contains among others the field cost center as a restricted field. So then I created a new business role containing this business catalog and restricted this role to just one cost center. But when we run the story then we still can see the values from all cost centers. Do we miss something here ? Or is this not the way it is working ? Or do we need to switch something on, on this field in the custom CDS view ? Can you pls. explain how we can assign a restriction to a newly created story ?

Accepted Solutions (1)

Accepted Solutions (1)

OwenLiu
Product and Topic Expert
Product and Topic Expert

Hi Victor,

The authorization for embedded SAC also inherit the authorization of the user you are accessing the S4HC system.

Please check below note about how to maintain restriction:

https://launchpad.support.sap.com/#/notes/2598733

"Point to note: A user which is assigned to multiple roles gets the union of authorizations. The principle of union is a generic principle e.g. a user is assigned an gl accountant role and a co overhead accountant role has the combination/union of the authorizations granted by both roles. Both roles give those authorizations on the same authorization entities (e.g. company code, account type of journal entry). Thus if for example the GL Accountant role has Write Access : No access and the CO Overhead accountant role assign assigned to user has Write Access: Unrestricted. User is able to post in app Post General Journal Entries as user has write accesses in the companies maintained in the restrictions in CO overhead accountant role"

Also check this blog about how to make trace for authorization.

https://blogs.sap.com/2019/09/25/identity-and-access-management-in-s4hana-cloud-part-two/

Best Regards,
Owen

Answers (0)