Display access to FN8X

Hi experts,
I have a request to have the transaction code FN8X for display only to payoff. I have tried restricting the object FD_BO_BUK to activity 03 only but when i click on pay-off it says that I can not create a payoff.
I then decided to add the acitivty 01 for the authorization object FD_BO_BUK, but the permitted activities are only 02, 03, 07, and 10.
When I put * on the activity it can simulate the payoff but the user can now post it, which I do not want to happen.
Is there any way that I can restrict this transaction code to display only for payoffs or if there are any other transaction code that can simulate a payoff?
Also is it advisable to change a SAP standard authorization object? Since I changed the FD_BO_BUK to have permitted activity of 01?
Thanks.

Below is a copy/Paste from SAP performance assistant, i am sure it gives better insight on the different activities and their usage
The authorization object FD_BO_PK checks whether a user is authorized to process business operations for a certain product type in a certain company code. This check still considers the activity required by the user and the business operation category itself.
The authorization check within the business operations works according a principle of inclusion. This means that a user with the authorization to activate a business operation is also authorized to delete a business operation and the authorization to post implies the authorization to reverse a posting.
Defined fields
BUKRS
Company code
GSART
Product type
ACTVT
Activity. Permitted activities:
02 Change
03 Display
07 Activate / Generate (corresponds with Delete)
10 Post (corresponds with Reverse / Reset)
SBO_CAT
Business operation category, such as Payoff, Borrower Change without Capital Transfer, and so on.

Similar Messages

  • Display access for the tcode SCC4

    Hi all,
    I want only the display access for the tcode SCC4. In which authorization object I can do this.
    Regards,
    R.Suganya

    Good Afternoon yes you can goto transaction SU24 insert transaction SCC4 and execute, click on display indicator, and you will see the object S_TABU_DIS assign activity value (03) to your role for this object which has that transaction SCC4 assigned to it. Also make sure that no other roles for that user has this object other wise the values will overwrite it.
    Make sure you have locked transaction code OY24 as its a duplicate of SCC4.
    Hope this helps
    Edited by: nadim razaq on Sep 17, 2008 4:13 PM

  • Display access in Netweaver 2004s

    Hi all
    How do i give display access to user for Tcode SXMB_MONI and SXMB_IFR in Netweaver 2004s
    Thanks

    Hi Jacko,
    For transaction SXMB_MONI you have:
    - <i>S_XMB_ADM</i>. The authorization object Integration Engine Administrator, determines the global administrator for the monitoring and administration of the Integration Engine. The field can have the following contents:
       X (The user is the administrator and can access XML messages in all clients in the system)
       Empty (User is not the administrator and can only access XML messages in the current client)
    -<i>S_XMB_AUTH</i>. This provides authorization protection for all actions that affect configuration, administration, monitoring, runtime, the cache, and time-controlled and prioritized message processing.
      Activity (Activity executed in the area: change 02, display 03, execute 16, activate/deactivate 63, reorganize 65).
      Area for Integration Engine (CACHE, CONFIG, FILTER,...and so on).
    - <i>S_XMB_MONI</i>. The authorization object XI: Monitoring of XML Messages is used during monitoring of the XML messages that are processed by the Integration Engine and saved in the database. In particular, this includes the transaction Integration Engine Monitoring (Monitor for Processed XML Messages) and the message monitoring in the Runtime Workbench.
    Activity (you must fill with 03 - Display).
    You can not give display access to transactio SXMB_IFR because this tcode let to user open the folder X:\Documents and Settings\<current user>\SapWorkDir.
    I hope helps you.
    Regards, Leandro

  • Adding tcode to role in display access.

    Hello,
    Please can someone suggest how we can add transaction codes to a SAP role with only display access.
    That means users should have only display access when they execute that transaction. Please suggest.
    Thanks.

    >
    adnan shahid wrote:
    > I would like to add the following tcodes in display access. In all the tcodes only auth object present is S_TCODE.
    >
    > OKY9
    > OKYA
    > OKY0
    > OKKM 
    > OKK6
    > OKK5
    > OKG6

    > Please suggest.
    I suggest that your run an authorisation trace to see what objects those transactions reference.
    Create a role with those transactions and objects in display only mode.  Then get a functional consultant to negative test those roles.
    Don't assign with other roles which give change access to the auth objects you have restricted.

  • Cannot display Access Control Rules page --- BUG REPORT

    iWS 4.1sp9 on Linux Admin GUI cannot display Access Control Rules page for Netscape browsers 4.7 and 6.2 or for IE 4.
    It does work for IE 5.5 (running this in Vmware).
    I'm reporting this bug here as I can't see anywhere else to put it.

    It could be a firmware bug, or it could be something else bugging out. If the router hasn't been factory reset and it's been through a few firmware upgrades, try resetting it to factory defaults. Take note of any custom settings you have, so you can go in and manually re-configure the router. I would avoid importing a backed up config file in case the config turns out to be the problem, but it doesn't hurt to download a copy of your config now.
    Give that a try. Others might have some more ideas.
    ========
    The first to bring me 1Gbps Fiber for $30/m wins!

  • Display access to UCWB

    We are trying to create an authorization role that allows display access only to UCWB.  The role we currently have is a "change" role.  Our QA and production systems are closed, so by defualt a user can only display in these environments.  However, we have business users who help develop test scripts and require display access to UCWB in our development environment.  Because the development system is open, the current change role allows the users to change config.  Has anyone created a pure display role for UCWB?

    Hi Deborah,
    You can ask your BW or BASIS consultants to crate a Display role for UCWB, this is a simple job.
    Technically you can first crete a role with UCWB display acces and then assingn to the respective users.
    While giving diaplay access, you can even restrict only the Master data and others if required.  Again better to give restricted display access to UCWB, as it involed many things which users are not aware.
    Hope this resolves your problem.
    All the best,
    Sunil M

  • System with only Display Access

    Hi,
    I have the following question, is it possible to configure a system copy with only Display access (at a sap level or Oracle Display mode,
    et cetera) without creating restrictions in an authorization level?
    Kind regards,
    Luis

    Hi Luis,
    I don't think this is possible, what you can do is create a system copy and assign display only authorizations to the users.
    Regards
    Juan
    Please reward with points if helpful

  • PE51- Display Access only??

    Dear all
    how do we restrict PE51   SAPMPE51       HR form editor for only display access..sooner i gave it it dosent  give any objects for me to maintain the disply authorization..can come one tell me if there any objct goes with this T-code where i can maintain only the Display access to the user..

    Hi,
    Goto SU24> enter the T.code in which u want the user should have only display . Execute it (Button on Appl> Toolbar), it gices 2 objects and on Appl. toolbar its a button as check indicator> click on this button.
    It display a list of objects, select the objects with CHECK AND MAINTAIN priority.
    Now goto the role of that user in which u assigned tat perticular Authorization , Double click on that role, it takes u in PFCG screen, click on Authorization Tab. Check that it shold be in change mode. Now check tat perticular object which v searched in SU24 with check and maintain, (cntrl+F), find tat object, after getting the object , in activity remoce all the selected fields, and just select 03 which is for display. Repeat the same for all objects and generate.
    Now the user has only Display access.
    Regards
    Syed.

  • Authorization roles for display access to PD transactions

    Hi all,
    There is a requirement to create a new security role to allow display access to PD transactions :
    > Organisational and Staffing Display PPOSE,
    > Display Position PO13D,
    > Display Organisational Unit P010D
    With this role, display access needs to be restricted to view organisation units and positions within the line of business where the position with this security role sits, eg position is within Direct Sales and Service 55001641 therefore they can only view organisational structures that report through to this top org unit.
    Any inputs regarding this would be appreciated.
    Regards,
    Manasee

    Try with  object 'S_ENQUE' and ID 'S_ENQ_ACT'...
    Hope it helps!
    Bye,
    Roberto

  • PO display access on Release status

    Hi,
    Is there any way through which we can restrict PO display access (to user ) untill it is release completely. The requirement is ..no other user except procurement dept should be allowed to view PO which is not yet released completely. Once it is released completely, then it should be open for display to all.
    Thanks,
    Dinabandhu.

    Hi,
    This is not the case here. Procurement department wants to restrict other user for UNreleased PO, NOT for Released PO. If we remove access for ME23N, other users will not be able to view released PO.
    As per Internal control, PO should be submitted to supplier by Procurement department only. It affect the orgamisation operation process if PO details is communicated to supplier. What if the PO is rejected by any approval authority which pending, and goods delivered by supplier with reference to unreleased PO ????? these are all the issue for which we want to restrict VIEW access to unreleased PO.
    Thanks,
    Dinabandhu.

  • SM59 Display Access

    Hello All,
              In our Audit Role user needs Tcode SCU0 for Cross System Viewer, after assigning this Tcode to Role, this Tcode in turn calls SM59 which is a Risk of giving this Tcode.
    Is there a way to give SM59 as display access access for SCU0.
    Please help with your valuable experiences.
    Thanks,
    CB

    Hi,
    I agree that S_RFC_ADM can be used to restrict SM59 access to display only. But S_RFC_ADM is available only from ECC 6.0 versions, so how about pre ECC 6.0 versions?
    Currently I am on ECC 5.0 where I don't have S_RFC_ADM and  SM59 program has a authority check for S_ADMI_FCD=NADM hardcoded in it which makes it impossible to make SM59 just display.
    Someone suggested using tcode- RSRFCCHK for displaying the RFC destinations and Execute connection tests but unfortunately this tcode skips SM59 initial screen and calls SM59 internally. In addition to that once the destinations are displayed, and you double click any, it takes you to the SM59 screen with full access to create, change and delete!!!
    Am I missing on something? Please advice
    Thanks
    Sandipan

  • Status Bar displays "Access is denied"

    Hi,
    We have EP 7 SP 11 portal where we are displaying Web Dynpro Java Iviews.
    Whenever a user logs in into the portal, the status bar displays a message" Access is denied" . Though this does not affect the funcitonality of the system but customers are complaining about the same.
    It would be really appreciated if anyone can help us on the following :
    1) What is the reason for this message appearing on the status bar ?
    2) Can this message be completely removed from the status bar ?
    3) If the text can be changed for this message displayed on status bar ?
    Thanks & Regards,
    Bir

    Check for the error message appearing in Netweaver Administrator Logs
    http://host:port/NWA
    goto monitoring and selects logs
    Check in Default Logs after you encounter error
    Definitely the user is missing some permissions . Also check in the ABAp Dumps at ABAP end for missing authorizations on ABAP side.

  • How to restrict FBL1N only to display access

    Hi,
    I need some help in restricting access for FBL1N.   The requirement is the user should be able to only display the vendor items  for the given opcos.  I created a test role for this tcode and maintained the activity for all the auth objects to 03.   But still user is able to change the vendor details.   When ran trace, it was showing the access to Tcode FB02.  but not sure how the test user is getting this access as the test role does not contain FB02 and user does not have any other role. Please advise
    Regards
    Kavitha

    Raghu Boddu wrote:
    Hi Kavitha,
    >
    > FBL1N internally calls lots of tcodes and FB02 is one among them. Check the table TCDCOUPLES.
    >
    > I don't think this restriction is possible only with adding 03 activity for the F_LFA1*  and F_BKPF* objects.
    >
    > If you check FBL1N in SU24, there are a few other authorization objects that are in check state. You need to make them check maintain and further maintain the activites in the individual roles.
    >
    > However, this may impact on the current roles that have FBL1N transaction code.
    >
    > Hope this helps!!
    >
    > Regards,
    > Raghu
    Despite the SAP_ALL removing the authorization problem.... I would like to enquire about this post.
    Can you please explain each of the statements you have made and provide some evidence?
    If the user has the correct authorizations then they are are wrong and the "check" and "check/maintain" status has no impact on the coding in customer type systems.
    Cheers,
    Julius

  • Transaction similar to VKM1 with only display access

    Hi,
    I would like to ask, do you know the transaction which would be similar to VKM1 (Blocked SD documents), but its user would be granted with display mode only?
    I tried to check the rest of the transactions from VKM* group but it seems there are none such reports.
    This kind of transaction shall be used by our Logistics to check which current orders are blocked and what is the reason behind it (lack of credit
    limit/overdue items on customer account) – but they mustn’t be authorized to release anything.
    Regards,
    Kiran

    Just wanted to add to Siva's response that user access is regulated not just using the transaction codes but the authorization objects within those transactions. Just like in this case, the same transaction may be used for the change and display purposes.
    There is authorization trace available in ST01 transaction that can be used to see what objects are checked when running a transaction. There might be other tools as well (I'm not a Security expert), but this one worked well for me so far.

  • Display access to be made on the Maintenance Plan.

    Hi Experts
    On the Preventive Maintenance Plan Creation in IP41/ IP42 / IP43 when I enter the Equipment Number all the master data gets copied in the Plan.
    But I am able to change the Planning Plant and also the Planner Group. I would like to have these two fields on the Display mode only. When Equipment number is entered all gets copied automatically and I should not have access to change it in creation of plans.
    Similarly I would also like to make the Tack List mandatory on the maintenance plan.
    I checked in the SPRO but not able to find the node. Should I go for an enhancement ?
    Regards
    Venkat

    Venkat,
    Just a practical issue here.
    What if you create the MP using the equipment data (say PG1), then at some point in the future you change the PG in the equipment to PG2.
    How would you now update the MP with the new PG since the fields would be display-only???
    PeteA

Maybe you are looking for

  • How to add/create a new keyboard ShortCut?

    There is no shortcut to color code or label an image for purple, if there is one I have not found it.  If you know of one, please send it & presuming there isn't one, what are the steps for creating one or modifying one to apply it as desired? Thanks

  • FW CS4 too Slow on 64bits systems

    Has someone with this problem? I downloaded the update for text engine and it's OK! But the SW continuous with very slow save works, and other things. It's almost impossible to work becouse the tools have 3 or 4 seconds of delay. Write text, after cl

  • Camera Profile Impossible to select for Fuji X100 pictures

    Hi All, I hope someone can help me with this. I am experimenting with a new Fuji X100. I imported my images (raw) with no issues and created a custom DNG profile with X-Rite colorchecker. When I open a Nikon NEF file I can eventually select this X100

  • Bootcamp 'Glowing' windows logo freeze after gfx driver install

    Bootcamp 'Glowing' windows logo freeze after gfx driver install Last week suddenly, after having changed or installed nothing, trying to boot into windows resulted in a frozen glowy window logo 'Starting Windows', which resulted in having to format t

  • Visual Composer - MDA in SAP universe

    Hello all, OMG released a bunch of standards around model driven architecture (MDA). From my point of view Visual Composer is the tool inside CAF to design solutions according to the MDA philosophy. But Visual Composer uses its own proprietary standa