cancel
Showing results for 
Search instead for 
Did you mean: 
Read only

Inquiry Regarding Removal of TCD: SU01 from Authorization Object S_TCODE

SAPSupport
Employee
Employee
0 Kudos
172

Dear SAP Support Personnel,

 

I would like to remove TCD: SU01 from the Authorization Object: S_TCODE for a specific role.
However, since the object containing TCD: SU01 is part of the standard configuration, it cannot be deleted directly.
I would appreciate your guidance on the following two points:

 

1.When Authorization Object: S_TCODE is standard, is removing the SU01 node from
PFCG > Menu > Hierarchy > Role Menu the only way to delete the transaction?

 

2.After removing the node and updating the profile, several authorization objects were added or suggested in the Authorization Data.
Could you please advise on a simple method to compare the authorizations before and after the profile update?

 

Thanks and best regards,
A.

 


------------------------------------------------------------------------------------------------------------------------------------------------
Learn more about the SAP Support user and program here.

Accepted Solutions (1)

Accepted Solutions (1)

SAPSupport
Employee
Employee
0 Kudos

Dear Sir,

 

If the value SU01 is part of an s_tcode authorization with status 'Standard', the only way to remove it is, to remove that t-code from the menu of the role. 

After that change is saved on the menu tab of PFCG, the status of the authorization tab turns red. That means, that menu change requires a merge of the authorizations.
Now the rules of SAP note #113290 are important to understand, what happens during the merge.

After the merge it is possible to identify the changes on one hand by checking the status of the existing authorizations ('new', 'updated'), and on the other hand, deleted authorizations can be found when using the ALV-tree display on the right screen of the split screen. The ALV-tree display can be activated on the authorization maintenance screen, in the menu->Utilities->Settings.

Alternatively, simply open the authorizations tab of the role in display mode in a different GUI-mode, then perform the merge in the first mode and compare the result with the second mode.

 

b.rgds, Bernhard

Answers (0)