Assign queries to authorization role via PFCG maintenace

Hi,
I would like to assign several queries to existing authorization roles.
Therefore I am using the transaction PFCG > maintain the menu > add "other" SAP BW Query URL and fill in the name as well as object description.
However, the new query will not be shown in the BEx Analyzer in the role folder.
What do I have to administrate that the query will be shown in the role menu (BEx Analyzer)?
Thanks!

Dear Arvind,
thanks for your reply.
As an authorization administrator for SAP BI I do have the authorization for S_USER_AGR already.
I am just testing in our development system.
However, the query will not appear in the BEx Analyzer while selecting "Open Query" and search in "Roles".
As far as I know queries could provided to authorization roles via BEx Analyzer.
But does no possibility exists to maintain the authorization role via PFCG?
Regards, Christian

Similar Messages

  • Replicating authorization roles via HR replication from ECC 6 to SRM 5.0

    Hi,
    I'm interested in knowing whether anyone has used the distribution model to copy roles (AG objects) between ECC 6 and SRM 5.0.
    Someone said that it's possible so I would like to validate that statement as I don't know whether it is possible and practical.
    If you have any knowledge or experience could you please share it?
    Regards,
    Jerry

    Hello Yann,
    I was told that it can be done but I don't know enough about the HR replication process to acknowledge or challenge, hence the question.
    Are you implying that it's not possible or simply that it's not done?
    I had an earlier post regarding assigning roles to positions in SRM Replicating authorization roles via HR replication from ECC 6 to SRM 5.0 that you replied to but never replied to my subsequent question. It can be done because one of my other clients is doing it. We're however unable to get it work at my current client's site. Do you have any experience with this subject?
    Regards,
    Jerry

  • Queries added to role in PFCG don't show up under role folder in BEX

    Hello Guruu2019s
    Currently I am experiencing a very strange problem regarding the visibility of queries in the role menu of BEX. Please find below some investigation already done:
    Just to avoid any authorization questions/assumptions,  I have a user with SAP_NEW and SAP_ALL. He also has 2 roles (R1 and R2, no other roles) in which reports are entered using: PFCG -> +OTHER -> SAP BW Query URL.
    In his SAP user menu all reports from both roles show up and are executable.
    When this user open BEX Analyzer and goes to u2018Openu2019 -> u2018Open Queryu2019 and then go to u2018Rolesu2019 only R1 and its contents is visible.
    The roles however are identical and contain only the following authorization objects (apart from menu entries):
    S_USER_TCD: RRMX
    S_TCODE: RRMX
    The only difference between them is that the R1 has been created some time ago while the R2 is new.
    I expect that people will tell me that S_USR_AGR is required but this isnu2019t the case since he is able to see one of the two mentioned roles (R1) and its contents in SAP BI due to SAP_ALL and SAP_NEW.
    When I copy R1 to R3 and add it to the user he is also able to see this R3 in the Bex analyzer. However, when I remove all reports from R3 and add some myself in PFCG these new entries do not show up in Bex analyzer, even though I re-added the report(s) I removed earlier in the exact same way.
    The same for the original R1, when I add new entries they arenu2019t visible although the u2018oldu2019 ones are.
    When I check the only table I know that holds SAP menu entries all links show up, this also explains why in his SAP user menu he sees all links. Does anyone know how (which tables) the BEX Analyzer gets the appropriate roles and role entries when a user wants to open a query?
    What can be the issue here; to me it feels like something has changed in the system that prevents BEX to read all roles properly?

    Hi Casper,
    there is a known issue at the moment whereby workbooks/queries and roles are no longer
    visable due to the following.....
    The settings in SSM_CUST defines a compress mechanism for the user menu
    known as "Redundancy avoidance" and described in notes 357877 and 357693
    Redundancy avoidance deletes easy access menu entries for doubled
    transaction codes whenever SSM_CUST contains
    1. an entry CONDENSE_MENU with PATH = 'YES' and
    2. either an entry DELETE_DOUBLE_TCODE with PATH = 'YES' or no entry
    DELETE_DOUBLE_TCODES, at all.
    If you don't want doubled transaction codes to be deleted, then simply
    add an entry DELETE_DOUBLE_TCODES with PATH = 'NO' into table SSM_CUST.
    Please enter
    DELETE_DOUBLE_TCODES with PATH = 'NO' into table SSM_CUST
    and retest this issue...
    I hope this helps
    best regards
    Orla.

  • Transaction for overview of Queries published in Roles via Query designer

    Hi Guru's,
    in Query designer I have the possibility to publish Queries in roles.
    I have the problem that some Queries have been published twice or more in different folders, so I want to clean it. But I don't know how to delete the Queries via BEx Analyzer as they are there again as soon as I log in again.
    Isn't there any transaction in Backend that I can use to structure my Queries in roles?
    Thanks in advance!

    One way to delete unneeded duplicates....
    Go to Query designer, in development
    Instead of loading the query you want to delete, find it in the folder/role
    Click on the "Trash Can" icon
    Then we have 2 more options to consider....
    - Delete object ...will TOTALLY delete it in the development system.... caution with this one, unless you really do want it to permanently go-away.
    - Delete only the object reference from the Role/Favorites... will delete the one instance in the folder, but leaves it everywhere else, useful when deleting a duplicate report in the folder
    After choosing one of the 2 options above, then click on the 'continue' button.
    "Refresh" to check what was done in development = Menu / Refresh
    When done... transport the role to Q and Production.
    Similar process if the query is located inside of web template and there are multiple instances of the same web template in the roles/folders that need to be cleaned up in the web application designer.

  • Inserting queries in a role

    Hi Gurus,
    i need to assign queries to a role so that users having this role will be able to get the queries in their menu when they log into the system. How can I do it?
    Partha

    Steps 1)PFCG -->create ROLE
    2)SU01 -->assign ROLE to user
    3)RSECADMIN -->create authorization object,assign activities of 0TCT*
    Note - RSECADMIN uses 0TCT* objects
    basis ADMIN should have S_RSEC object to be assigned in order for him to use 0TCT* objects
    Roles - Query
    PFCG - create Role
    Authorization tab -change authorization data
    S_GUI = *
    S_TCODE = RRMX
    S_USER_AGR
    ACTVT = 2,3 and ACT_GROUP = *
    S_USER_TCD = RRMX
    Profiles to be given to developer
    SAP_ALL
    SAP_NEW
    0BI_ALL is the new object which gives all authorizations to users.
    More info-
    Re: How to add a Role?
    Hope it Helps
    Chetan
    @CP..

  • Assigning Authorisation profile to roles

    Hi All,
    I have created a new authorisation profile by copying from the standard profile and activated the same, I have created a role using  PFCG and assigned it to the user via SU01, but still the user has not  got the required authorisations.
    When i try to assign this  profile to the role via PFCG, i am not able to assign
    Either i have to select  the  transactions from the menu tab and the  system is creating  new authorisation profile and  assigning it to the user,
    can anybody  help me out in assigning the  authorisation profile to the  roles
    Regards
    Venkat

    Hi Venkatesh,
    Short of performing an upgrade step via SU25 to convert the profile to a role (which you really don't want to do!), you can't do this to the best of my knowledge.
    PFCG is called profile generator because it creates the profiles for you based on what you enter into the menu tab and the corresponding auth values that you maintain within the role via PFCG.
    I strongly recommend that you build a role via PFCG and create it with the right combination of menu transactions and auth values.  You can then assign this to the user.  This is the standard way of maintaining authorisations now.
    Alternatively you can assign the profile you have created to the user, however if the role build is role based, I would not recommend this approach at all.

  • Assigning authorization role to position in PP02 (SRM 5.0) not working

    Hi,
    We've run into a problem in our SRM 5.0 system that we're not sure how to solve.
    We defined a role where we only set the BBP_APPROVAL_LIMIT attribute in the Personalization tab. It has no other transaction authorizations.
    When we assign this role to the user directly the user inherits the BBP_APPROVAL_LIMIT as expected.
    When we attempt to assign this same role to a position through PP02 and run the PFUD, the attribute values are not transferred to the user personalization attributes.   Doesn't matter what we do, we can't seem to be able to get it to work.
    Does anyone one have any experience with this that they could share?
    Regards,
    Jerry Martinek

    Hello Yann,
    Thank you for the reply.
    This is one of the things that I'm trying to confirm which is whether it can be done. I was told that it does work and that they use PP02. But as we can't get it to work I wanted to know if anyone else is using this process and if yes, how do you do it.
    If people mainly use the explicit user assignment via PFCG, do they manage it manually or systematically?
    Thanks,
    Jerry

  • Assigning Queries and workbooks to user roles

    Hi Guys,
    I was hoping that someone could explain, how the queries, workbooks and Web Templates can be assigned to roles.
    What are the steps involved in creating the roles and assigning the queries.
    How are these reports accessed by the users (by URLs or through SAP GUI) If I would want to use the URLs to access them, how do I open the workbooks?
    I seem to have a lot of questions, hope to find answers to a few of them.
    Thanks,
    Doniv

    Hi Doniv,
    Queries, workbooks and web templates can be assigned to roles during the time that they are being saved. The assignment can also take place in PFCG > role. These kind of roles are usually basic placeholders that are assigned to different users as per requirements. This ensures that the usersa can see only those objects which are on the roles assigned to them.
    The workbooks are not accessed by a URL in the internet explorer, they are accessed in the BEx Analyser.
    Hope this helps...

  • Assign queries to roles

    Hi,
    I want to be able to assign queries to role. For this purpose I went into PFCG and created two folders. I have assigned the queries to the two folders ( technical names). However they are not showing up in the roles in BEx.
    Can someone tell me Step-by-Step how this is to be done.
    Any help is deeply appreciated and will be rewarded with points.
    Thanks

    I am on BW 3.5.  We have done the following steps.
    1) Created a Role in BW using PFCG.
    2) Created two folders under the Menu option
    3) Assigned BEx queries to the folders.
    I have a question here:
    When assigning queries to the folders, what options do I choose. What Technical name do I give.
    i think the problem lies there as I am not able to execute the queries from within PFCG.
    Please let me know. Any help appreciated and will be rewarded with points.
    Thanks

  • Need procedure for creation of BW Roles, Assigning Queries,Publishing Roles

    Hi Experts,
      Could you please let me know the procedure for creation of BW Roles, Assigning Queries,Publishing Roles in Business Explorer (BEx - BW 3.5)
    Thanks in advance,
    Andy

    Hi,
    Creating BW Roles
    http://help.sap.com/saphelp_nw04/helpdata/en/52/6714b6439b11d1896f0000e8322d00/frameset.htm
    Assigning Queries
    After creating the query, save the query to a role from the query designer.
    Publishing Roles in Business Explorer
    https://websmp101.sap-ag.de/~sapdownload/011000358700002894802003E/HowToBIPortal1.pdf
    Hope this helps you..!
    -Pradnya

  • How to upload authorization role & profile to PFCG

    I have downlaod the authorization role & profile from PFCG at client 100.
    How to upload the authorization role & profile to SAP client 200?

    check with ur basis guys once
    generally it will be dont by them check with them once

  • Authorization check for caller assignment to J2EE security role

    Dears experts, in the default.trc logs in, my Enterprise Portal NW2004s, appear this error:
    #1.#0018714E4A14005E000027E1000057B8000441BB7EF2FC03#1198173451524#com.sap.engine.services.security.roles.SecurityRoleReference#sap.com/irj#com.sap.engine.services.security.roles.SecurityRoleReference#Guest#2126####46ce8210aefd11dcc68f0018714e4a14#Thread[Thread-59,5,SAPEngine_Application_Thread[impl:3]_Group]##0#0#Error#1#/System/Security/Audit/J2EE#Java###: Authorization check for caller assignment to J2EE security role [ : ] referencing J2EE security role [ : ].#5#ACCESS.ERROR#service.jms.default.authorization#administrators#SAP-J2EE-Engine#administrators#
    #1.#0018714E4A14005E000027E5000057B8000441BB7F8BDC21#1198173461543#com.sap.engine.services.security.roles.SecurityRoleImpl#sap.com/irj#com.sap.engine.services.security.roles.SecurityRoleImpl#Guest#2127####46ce8210aefd11dcc68f0018714e4a14#Thread[Thread-59,5,SAPEngine_Application_Thread[impl:3]_Group]##0#0#Error#1#/System/Security/Audit/J2EE#Java###: Authorization check for caller assignment to J2EE security role [ :
    Any idea about it?
    Thanks friends

    Hi Holger,
    Thanks for the tip, it could be the case, I just checked and we are on Patch 0 for JEECOR as you can see here below:
    sap.com/SAP-JEECOR   7.00 SP13 (1000.7.00.13.0.20070907082334)  20071028144036 
    sap.com/SAP-JEE          7.00 SP13 (1000.7.00.13.2.20071026143730)  20071203150628 
    Will inform some people internally to patch to atleast 3 to check if it still occures.
    Anyway, Thanks again..
    Benjamin Houttuin

  • Error :Authorization check for caller assignment to J2EE security role whil

    Hi Experts,
                 i m working as a portal resource .
    after the deployment of standered Sap e-rec package .
    i m getting some error. i have assigned the recruiter role to one test user.
    Now i m getting two issue:
    1)All the services are appearing in Detailed Navigation Pannel but not in Portal content area..
    2) I m able to see few iview for the test user but those are also in detailed navigation view.
       And few ivews are giving following error :
      i)Internal error
    ii)error 2011-12-19 07:59:57:315 ACCESS.ERROR: Authorization check for caller assignment to J2EE security role [sap.com/com.sap.lcr*sld : LcrInstanceWriterNR] referencing J2EE security role [SAP-J2EE-Engine : administrators].
    /System/Security/Audit/J2EE com.sap.engine.services.security.roles.audit n/a EP-DEV-KRT Server 0 0_97989
    Full Message Text
    ACCESS.ERROR: Authorization check for caller assignment to J2EE security role [sap.com/com.sap.lcr*sld : LcrInstanceWriterNR] referencing J2EE security role [SAP-J2EE-Engine : administrators].
    please suggest what can be  done or what is pending from my side.

    Prajakta2602 wrote:
    Hi Experts,
    >
    > the previous issue got solved..
    > it was due to servies pack miss match and applying notes
    > the Basis guy  checked the SLD logs and accordingly found that the base components J2EECORE and JTECHS required paching as per
    > notes 1445294 and 1175239 were applied.
    > now the issue is:
    >
    >
    >  After implemetation and  i assigning the standerd sap roles
    > 1)Recruiter Administrator
    > 2)Recruiter
    > to the test user .
    > but for few iview it is showing error as in
    > 1) you are not a authorized user
    > 2) internal error
    >
    > please help experts.
    >
    >  i m working on portal side have i to assign any role to that test user..
    >
    >
    > Thnaks & Regards,
    > Prajakta
    You can run a quick check using the below steps:
    1. Check in backend whether there is any authorisation errors... you may use transactions SU53 or ST22 for any ABAP errors
    2. Also check in NWA -> log viewer -> last 24 hours log for the particular user to see any java related issues.
    Regards,
    Mahesh

  • Bulk assignment from Queries to a role

    Hey folks,
    we would like to transport more than 100 queries (not Workbooks) - from an Excel-list.
    Unfortunantely, it is not possible to filter queries in Transport Connenction, compared to Workbooks.
    Therefore we created a temp-Role, assigned all Queries to this role, selected that role in the transport connecntion and we had our 100 queries selected by selecting only the temprole - this is much faster.
    As we´d like to improve this, I would like to know, what is the fastest way, to assign 100 reports to a temp-role? Any suggestions on that?
    Best regards,
    Christian Röttgers

    Any suggestions?

  • How to create authorization role for just displaying query prefix Q and X.

    Hi Expert,
    I hope someone can help me on how to create authorization role for just displaying and executing  BEX  Queries prefix Q and X. I'm currently using SAP BI 7.1.
    Actually, I already created one role called : Z_FORINDO_ONLYDISPLAY_QX
    where I only put in the Authorization Component (in the Role Maintenance - Tcode 'pfcg'):
    -->Manually Business Information Warehouse
        --> Manually Business Explorer - Components
    Activity : Display, Execute, Enter, Include, Assign
    InfoArea : *
    InfoCube : *
    Name(ID) of a reporting component : *
    Type of a reporting component : Calculated key figure, Restricted key figure, Template structure
        --> Manually Business Explorer - Components
    Activity : Display, Execute
    InfoArea : *
    InfoCube : *
    Name(ID) of a reporting component : Q* , X*
    Type of a reporting component : Query
    But, the problem is I still can make changes on that queries (Q* and X*). Even, I still can run query with prefix Z. I use S_RS_RREPU Tamplete for Query Display and execution.
    Please assist. Very much appreciate your help. Thanks.
    Edited by: nadiyah salleh on Mar 18, 2008 11:22 AM

    Question close. This issue has been resolved.

Maybe you are looking for

  • Premiere Pro CC 2014 (8.0.1.21) crashes when opening or creating a project

    I just downloaded the trial for Premiere Pro CC (2014), and the program keeps crashing every time I open or create a new project. I can idle at the "Startup Screen" but as soon as I open a project the program closes without warning. I've re-installed

  • Recording audio from iPad to Mac

    I have an iPad app that allows you to download different audio presentations.  However, the audio is trapped in the iPad app, which means I can't listen to it anywhere but the iPad.  I'd like to transfer this audio to an MP3 so I can listen to it on

  • Remove default event listeners

    I am trying to use JComponent(JList, JTable) with a different behavior on mouse events. JTable for example selects the cells while dragging. I want to remove all curent listeners, I found removelistener, but I dont find getlisteners (removelistener r

  • How can i add my contacts to my note2

    How to add contact from cloud to note 2 how

  • Security in OBIEE

    Hi Guru's, I have a challenge where i need to enhance my existing security setup by customising or by following short cut.Currently with the existing set up we have database authenciation for users by setting up two user group. we have have heerarchy