Sap xi role in ESOA

Hi gurus
would you please tell me when sap xi is used in ESOA??

Hello raj,
  I am not a guru but i would try to clarify the things. In ESOA we have these three important steps deploy, discover, interact. We have the enterprise service reposity(ESR) part of Process Integration(PI/XI),  which is sigle repository to store the information about all the enterise services across different SAP components. When ever we build application using these enterprise services from ESR the XI/PI is responsible for execution of the implementation behind the service end piont. So we are making using the underlying capabilities of PI/XI for the service orchestration.
Hope things are clear to you,
regards,
Mahamood.

Similar Messages

  • SAP Technical roles and IDM Business roles mapping

    Hi Guys
    Just wondering if there is an easy way to export SAP Positions and create them automatically as Business Roles in IDM and the SAP technical roles that are related to that corresponding position into privledges assigned to that Business Role. Or am I going about this the wrong way? What do you normally do in terms of getting all your sap technical roles from the sap system and assigning them to business roles in IDM. Any help on this is much appreciated?
    Cheers
    Leo

    Thanks Matt,
    I think get I the picture now
    One thing that I am still not sure about is how the sap abap technical roles or profiles are provisioned through workflow
    Here is what Ive done so far
    1. HCM data loaded into productive identity store via vds
    2. Did an initial load of the abap system into the productive identity store (now the technical roles and profiles are loaded as privileges in the idstore)
    3. Through workflow I select a user that already has an abap account and assign that user some additional sap technical roles, for e.g. sap_all and sap_new. The corresponding privileges for these roles are namely PRIV:PROFILE:ECX:SAP_ALL and PRIV:PROFILE:ECX:SAP_NEW .
    4. For the provisioning to occur so that these new privileges are reflected in the ABAP system for this user, I have used the setABAPRole&ProfileForUser task from sap provisioning framework folder and set it as the add/mod/del  event task for the MXREF_MX_PRIVILEGE attribute. That way whenever a privilege is added to a user account the setABAPRole&ProfileForUser task will run and the sap_all and sap_new profiles will be added in the backend. This way I can avoid setting a provisioning task for each abap privilege that gets loaded.
    But it should be obvious now that there is a flaw with this kind of setup, because all non abap privileges that get added or removed will trigger the setABAPRole&ProfileForUser task anyway because the privileges use the same attribute i.e.MXREF_MX_PRIVILEGE. So it brings me to the question how do you provision abap technical roles or profiles through workflow without setting a provisioning task for each abap related privilege.
    Thanks again for all your help!
    Leo

  • SAP USERS ROLE TABLE

    Can some one tell me the SAP USERS ROLE TABLE
    I Will assign point to any input.
    Balance Roll forward     
    Change Vendor Line Items
    Change Parked Vendor Document
    Change/ Reverse Vendor Invoice     
    Check Processing
    Clear Accounts Payable Items
    Display A/P  Balance & Items
    Display Checks     
    Display Vendor Documents     
    Display A/P Master Data     
    Display Parked Vendor Documents     
    Account Payable Interest Calculation     
    A/P Invoice Entry     
    A/P Accounting Key Reports     
    Manual Payment     
    Payments Using Bill of Exchange     Display
    Payment Run Parameters     
    Create and Process Payment Run Proposal     
    Accounts payable period closing     
    Post Parked Vendor Document     
    Maintenance of Accounts Payable Master Data     
    Process Withholding Tax

    go to t code PFCG
    Search for roles with SAP_FI_AP*
    You could always create your own role.
    In the Menu tab add the t codes you have specified.
    You will then need to add the authorization objects in the authorization tabs.
    For the t codes you have I guess it would take an hour max.

  • Is there any SAP substitute role to create expense report for executives?

    Hello,
    In an organization there are executives like MD, CEO and they need to submit their expenses. This activity is basically needs to be done by their secretary (substitute). So is there any SAP provided roles to do this activity?
    I have seen SAP_FI_TV_WEB_ASSISTANT used for My Employees/POWL. Apart from this role do we have any other way for executives?
    Appreciate your help.
    Thanks,
    Chandra.

    Hi ,
    You can create travel request from PR05 from ECC or if you have ESS and you want administrators to create on behalf of others provide the below role and you can create from My Employees or you can customize a role specific for administrators using structural authorizations.
    SAP_FI_TV_WEB_ASSISTANT
    Hope this helps,
    Regards,
    S.Srikanth
    Edited by: SrikanthS on May 10, 2011 6:32 AM

  • SAP HR Roles in payroll

    hai all,
    please send the documentaion for SAP HR Roles in payroll for user.
    Thanks
    Sam.

    Payroll Transaction Data Entry
    Payroll Administrator
    Time_Payroll Data Verifier
    You can have managers also
    Payroll Manager
    Edited by: Manikya Raju .Potnuru on Mar 12, 2009 1:26 PM

  • Break sap standard role into two sub roles

    hi,
    i have one SAP standard role. now i want to break this role into two  sub roles. how shall do it.
    please suggest me.
    regards
    ramesh
    Edited by: Ramesh Sammiti on Jul 31, 2008 11:00 AM

    Hi Ramesh,
    When you say that you want to split the SAP Standard role into two roles:
    1.Do you mean to say that you want to split the transactions and authorization data of the SAP Standard role into two separate Z* or Y* roles?
    2.Do you want to copy the SAP Standard role into two different Z* or Y* roles and then modify the authorization data according to your company's requirements?
    In the above two scenarios you must copy the SAP Standard role into Z* or Y* roles in PFCG transaction with the appropriate naming convention and make necessary changes in both the transaction data and the authorization data.
    Please be clear which SAP Standard role you are willing to split into roles and i can provide more details.
    Hope this helps.
    Regards,
    Kiran Kandepalli

  • Workflow Administrator SAP user Role

    I have a question from the customer regarding which SAP User Role should be assigned to and Workflow Administrator?
    From my point of view, basically there are 2 questions here:
    1. Is there any standard SAP user Role for this? (which one?)
    2. If not, then a custom Role need to be configured (from PFCG t-code i think). Can anyone tell me to which workflow transactions should be ground authority for such a Role?

    Hi
    These are the tcode for workflow developer.  Use the SW* and pfac_dis,PFTC_DIS for wflow admin.
    SWL1
    SWLV
    SWNNOTIFDEL_DISPLAY
    SWPC
    SWPR
    SWU0
    SWU1
    SWU2
    SWU3
    SWU4
    SWU5
    SWU7
    SWU8
    SWU9
    SWUD
    SWUG
    SWUI_BENCHMARK
    SWUI_VERIFY
    SWUI_WFUNIT
    SWUS
    SWUS_WITH_REFERENCE
    SWU_EWBTE
    SWU_EWCD
    SWU_EWLIS
    SWU_OBUF
    SWWDHEX_DEBUG
    SWWERRE_DEBUG
    SWW_ARCHIV
    SWW_DISPSWWCLEAR
    SWW_DISPSWWCOND
    SWXML
    S_ALR_87000710
    S_ALR_87000878
    S_ALR_87000881
    WF_EXTSRV
    RSWWERRE
    SBWP
    SCDO
    SLG1
    SWB_COND
    SWDA
    SWDB
    SWDC_DEFINITION
    SWDD
    SWDD_CONFIG
    SWDM
    SWDS
    SWE2
    SWE5
    SWEAD
    SWEC
    SWEINST
    SWEL
    SWELS
    SWEQADM
    SWEQBROWSER
    SWETYPV
    SWFVISU
    SWF_ADM_SUSPEND
    SWF_ADM_SWWWIDH
    SWF_APPL_DISPLAY
    SWH_EXIT_DISPLAY
    SWI1
    SWI11
    SWI13
    SWI14
    SWI1_COND
    SWI1_RULE
    SWI2_ADM1
    SWI2_ADM2
    SWI2_DEAD
    SWI2_DIAG
    SWI2_DURA
    SWI2_FREQ
    SWI30
    SWI5
    SWI6
    SWIA
    MCAP
    MCAQ
    MCAR
    MCAT
    MCAU
    MCAV
    MCAW
    MCAX
    MCAY
    MCAZ
    MCKY
    MCKZ
    MCM+
    MCM-
    MCM/
    MCM?
    MCSW
    MCSX
    MCYY
    PFAC_DIS
    PFTC
    PFTC_DEL
    PFTC_DIS
    PFWF
    PFWS
    PGOM
    PPMS
    PPO4
    PPOS
    PPSS
    PPST
    PSO3
    RE_RHCHECK1
    RE_RHCHECKV
    RE_RHDESC10
    RE_RHEXIST0
    RE_RHNAVIG0
    RE_RHRHAZ00
    RSWEWWDHMSHOW
    RSWEWWDHSHOW
    RSWWCLEAR
    RSWWCOND
    RSWWDHEX
    BSVW
    MC01
    MC02
    MC03
    MC04
    MC05
    MC06
    MC07
    MC08
    MC09
    MC18
    MC19
    MC20
    MC21
    MC22
    MC23
    MC24
    MC25
    MC26
    MC93
    MC94
    MC95
    MC?0
    MC?1
    MC?2
    MC?3
    MC?4
    MC?5
    MC?6
    MC?7
    MC?8
    MC?9
    MCAF
    MCAH
    MCAI
    MCAJ
    MCAK
    MCAL
    MCAM
    MCAN
    MCAO

  • Advice needed: what does your company log for SAP security role changes?

    My client has a situation where for many years, they never logged changes to SAP security roles.  By that I mean, they never logged even basic details, like who requested a change, tested it, approved it, and what changed!!  Sadly their ticketing system is terrible, completely free-form text and not even searchable. 
    Does anyone here use Word docs, Excel sheets, or some other way to capture security role change details?   What details do you capture?  What about Projects, that involve dozens of changes and testing over several months?
    I plan to recommend, at least, they need to use a unique# (a ticket#, or whatever) for every change and update the same in PFCG role desc tab, plus in CTS description of transports... but what about other details, since they have a bad ticketing system?  I spoke with internal audit and change Mgmnt "manager" about it, and they are clueless and will not make recommendations.  It's really weird but they will get into big trouble eventually without any logs for security changes!

    Does anyone here use Word docs, Excel sheets, or some other way to capture security role change details? What details do you capture? What about Projects, that involve dozens of changes and testing over several months?
    I have questions:
    a) Do you want to make things straight
    b) Do you want to implement a versioning mechanism
    c) You cannot implement anything technical, but you`re asking about best "paper" practise?
    The mentioned scenarios can be well maintained if you use SAP GRC Solutions 10 (Business Role Management)
    Task Based, Approvals, Risk Analysis, SOD and role generation and maintenance in a structured way (Business Role Management). Workflow based, staged process with approvals.
    PFCG transaction usage will be curtailed to minimum if implemented fully.
    Do we really want to do things "outside" PFCG?
    @all:
    a) do you guys use custom approval workflows for roles?
    b) how tight your processes are? how much paperwork, workflow, tickets, requests and incidents you have to go through to change a role?
    c) who is a friend of GRC here, raise your hand
    Cheers Otto
    p.s.: very interesting discussion, I would like to learn something here about how it works out there in the wild

  • Modifying SAP standard roles - best practice

    Hi,
    Is there a Best practice How-to guide for configuring SAP BPs roles for client use.  I know I shouldn't change the content delivered by SAP but I'm not quite sure what I should delta link copy into client namespace.
    I am implementing MSS.  Do I just delta link copy the Manager role into client namespace or I should make a delta link copy of the My Staff workset then make changes to the workset and assign it to a completely new ClientManager role?
    I have the TransportEP6Content how to guide but it doesn't say explicitly what is best parctice.  This doc references 'HowTo Use Business Packages in Enterprise Portal 6.0' but it isn't where it says it is on service marketplace.
    TIA,
    J

    Hi,
      'How to use Busiess Packages in Enterprise Portal 6.0' is available in this link.
    http://help.sap.com/bp_epv260/EP_EN/documentation/How-to_Guides/misc/Using_Business_Packages.pdf
    Check out for the best practices.
    Regards,
    Harini S

  • SAP tables used to fetch role names into 'Lookup.SAP.UM.Roles'

    SAP User Management Lookup Recon schedule task is used to populate all the Lookup's defined in 'Lookup.SAP.CUA.LookupMappings'. In case of the lookup 'Lookup.SAP.UM.Roles', the description of the SAP Role is populated in Decode value.
    In our environment, the SAP role description is changed in the table 'USRSYSACTT' for both LANGU types 'E' and 'D'. However, when we run the schedule job, we are unable to see the updated value of description in the lookup 'Lookup.SAP.UM.Roles'. Please let us know which SAP table is actually being used to fetch the role information in OIM.

    Dear Satish,
    Do you have any red alerts on top of your change request?
    If yes, you cannot change the status of this change request.
    Do a double click on the alert flag and clear/maintain any alerts first.
    I had just the same problem.
    Yours
    Markus

  • SAP Business Roles

    Hi,
    Has anyone ever worked with business roles. I am new to the OCM side having worked on the security side for many years. I am working on a project developing business roles and needed more details on how business roles link to security roles?

    Thanks Matt,
    I think get I the picture now
    One thing that I am still not sure about is how the sap abap technical roles or profiles are provisioned through workflow
    Here is what Ive done so far
    1. HCM data loaded into productive identity store via vds
    2. Did an initial load of the abap system into the productive identity store (now the technical roles and profiles are loaded as privileges in the idstore)
    3. Through workflow I select a user that already has an abap account and assign that user some additional sap technical roles, for e.g. sap_all and sap_new. The corresponding privileges for these roles are namely PRIV:PROFILE:ECX:SAP_ALL and PRIV:PROFILE:ECX:SAP_NEW .
    4. For the provisioning to occur so that these new privileges are reflected in the ABAP system for this user, I have used the setABAPRole&ProfileForUser task from sap provisioning framework folder and set it as the add/mod/del  event task for the MXREF_MX_PRIVILEGE attribute. That way whenever a privilege is added to a user account the setABAPRole&ProfileForUser task will run and the sap_all and sap_new profiles will be added in the backend. This way I can avoid setting a provisioning task for each abap privilege that gets loaded.
    But it should be obvious now that there is a flaw with this kind of setup, because all non abap privileges that get added or removed will trigger the setABAPRole&ProfileForUser task anyway because the privileges use the same attribute i.e.MXREF_MX_PRIVILEGE. So it brings me to the question how do you provision abap technical roles or profiles through workflow without setting a provisioning task for each abap related privilege.
    Thanks again for all your help!
    Leo

  • Find user SAP Portal role in an abap program

    Dear all,
    We would like to check the SAP Portal role of a Portal user in a R/3 abap program.
    do you know if there is a bapi or a RFC module function to do that ?
    For example : the user CCDEMO (exists in EP and in R/3 backend) has a Buyer Portal role. In an abap program, I would like to have this information.
    Thanks
    kind regards
    Véronique

    Dear all,
    We would like to check the SAP Portal role of a Portal user in a R/3 abap program.
    do you know if there is a bapi or a RFC module function to do that ?
    For example : the user CCDEMO (exists in EP and in R/3 backend) has a Buyer Portal role. In an abap program, I would like to have this information.
    Thanks
    kind regards
    Véronique

  • Re-Engineering SAP Complex roles

    Last week I visited a large European telecomm company in order to assist and consult them on their SAP system access rights.
    In the first couple of days, we dedicated the time to analyze the data that was imported into Eurekify/Sage and generate many cleansing reports. A cleansing project is an essential process before any RBAC project.
    By the way, the import of data was done by using the Eurekify built- in connectors to SAP.
    The cleansing analysis was done on 2 levels:
    1.     Roles (complex and simple)
    2.     Authorization objects and fields.
    The second phase of the analysis revealed astounding facts about their current roles:
    1.     The complex roles covered only 2% of the users!!
    2.     Most of the access rights were not via complex roles, but rather directly to simple roles. Only 4% of the access rights to simple roles where via complex roles.
    3.     They had many dual access rights to “simple role” which means that a user had access to the simple role directly and also via a complex role.
    4.     They found that they had many simple roles that could be merged.
    The highlight of the project was the SAP complex role re-engineering. We reversed engineered the “complex roles” and deleted the roles.
    Within 1 day of (partial!!) role engineering, we managed to create new complex roles (less than what they had before by 20%), however:
    1.     The new roles covered 40% of the users!!
    2.     The new roles covered 26% of the access rights to “Simple Roles”!!
    In the upcoming weeks the project will continue in 2 layers:
    1.     Cleansing the SAP access rights data from complex roles down to the fields.
    2.     Continuing with the Role Engineering in order to create a full model of complex roles.
    Are you interested in applying this experience to your SAP system?
    If yes, feel free to contact me.
    Ilan Sharoni
    <b><REMOVED BY MODERATOR></b>
    Message was edited by:
            Alvaro Tejada Galindo

    Maybe you use the CAF for the project? You shall then be able to use any technology you want to use or are comfortable with and then integrate the different objects as part of a process.
    Sameer

  • SAP Standard Roles

    Hello everyone.
    What is SAP's best practice for using (customizing) the SAP standard roles? I have always used the standard roles as templates to customize for my customers. Is there a stated SAP best practice for this?
    If I use a standard role, customize it and copy it to the company namespace and the standard role it is customized off of changes, does my customized role change?
    How do release upgrades affect the standard SAP roles?
    Thanks!
    Todd

    Hi Todd,
    If you copy the roles to a your own namespace then they won't be touched during upgrade.
    I can't comment on what happens to standard roles during upgrade as I tend to avoid them.
    There is no accepted best practice around using standard roles, though there is reasonably wide belief that developing your own from the ground up is a better way to develop roles to meet your customers business processes. 
    I find that where standard roles have been used, the end user roles have generally a lot of unused transactions.  Functional & business people see a large list & choose most of them rather than building up from a subset of inscope transactions which are also used for training, BPP's etc.
    There is also the consideration that using standard roles guides you to building in the same way.  That's not to say it is a bad way, just can limit flexibility if you build down to a task level (nasty, nasty, nasty) or higher at a job or function level.
    Cheers
    Alex

  • Deletion of SAP standard roles

    I have been asked by the client if we could delete all of the SAP standard roles. I think there are many good reasons not to delete them, but does anyone know what SAP's official recommendation would be to that question and could you point me to the documentation or SAP Note where that recommendations is written?
    So far all I have found is the following documentation(http://help.sap.com/saphelp_47x200/helpdata/en/52/67164b439b11d1896f0000e8322d00/frameset.htm) saying that:
    Do not change the delivered standard roles (SAP_), but rather only the copies of these roles (Z_). Otherwise, the standard roles that you have modified will be overwritten by newly delivered standard roles during a later upgrade or release change.
    But it does not say that you should never delete them.
    Br,
    Jon

    Christensen Jon Jagd wrote:>
    > The client want's to "clean up" the authorizations concept by deleting all of the unused roles. And all the SAP_* roles are not assigned to any users (and not generated neither).
    I've seen that before, the urge to clean up...... unused roles aren't the worst thing to happen on a system, as long as they're part of the concept.
    Come to think of it. I'd delete them from my test and prod systems to avoid confusion and/or (mis)use, but not from dev. On dev the majority of roles is not assigned to users anyway........
    > But I would like to know if for example "SAP recommends that you do NOT delete system delivered roles".
    I don't think such advice exists. Try to convince the client they should be kept on dev for future reference. Delete them on the other systems to clean up. Everybody happy.
    Jurjen
    Edited by: Jurjen Heeck on Feb 12, 2008 10:16 AM

Maybe you are looking for

  • How do i reinstall Lion OS from App store?

    I needed to reinstall a new harddrive and i only have snow leopard on my macbook pro now. i had previousy downloaded Lion from the app store but cant find it on there now. how do i re download Lion OS?

  • How to delete decimal point and adding leading zeros....

    Hi, I have one requirement in the report   i.e.         <b>Present Value    :</b>  44567.98         <b>Expected Value  :</b> 0000004456798 In the present Value how will I remove that decimal point and how to add those six ing zeros. I tried with CONV

  • Changing look and feel with radio buttons

    k this is the code that i have so far, Yes i read the tutorial and stuff but it doesnt seem to make any sense and all. tell me what else i need in this code to do what i want, its the action performed part i didnt put the other code, what else do i n

  • Internal Error 2330. 1392...(plug_ins\PaperCapture)

    My Acrobat file folder is corrupted. I can't uninstall, install new, or even open the folder. It causes the message: Internal Error 2330. 1392, Program Files\Adobe\Acrobat 7.0\Acrobat\plug_ins\PaperCapture I have Windows Vista and customer support wo

  • Date & Time are wrong, how is this possible.

    I am having a look at my inlaw's computer. Late 2008 15" MPB, 10.6.8/iLife 11. One of the more strange things I've seen is that in Date & Time preferences the small section above the calendar where it should show the date i.e. 2/19/2012 is essentiall