Authorization by GL Account Group

Hi,
Is it possible to restrict authorizations by GL account Group (KTOKS)?
Regards,
Raj.

Hi
Please go through the below mentioned links
Authorization Check on GL Account Group (KTOKS)
how to creat authorisation group for gl posting
Authorization Group for G/L Account
Config - Authorization Group in G/L code
Regards
Praveen P C
Edited by: Praveen Chirakkel on May 18, 2011 6:17 AM

Similar Messages

  • Authorization Check on GL Account Group (KTOKS)

    Hello,
    During Create/Change/Disply of G/L account master, need to apply the restriction on a particulare GL account group.
    G/L account group field is a list box and user cna select one account group from the list. When the user selects othere than the one for which he doesn;t have Authorization, we need to raise an error message.
    How can we apply the Authority Check to the G/L account group in FS00 transaction.
    If any of you come across this kind of requirement, please let me know.
    Thanks,
    MPREDDY

    Hi,
    In SU24 for tcode FS00 I cannot find any auth.object for this field. So, you can try to create your own auth.object with tcode SU21 and insert in the ABAP coding of the enhancement SAPMF02H (EXIT_SAPMF02H_001). After, set this auth.object in tcode PFCG for users, users-groups and so on. View how to insert and manage the error message with other auth.object if you want that the logs of tcode SU53 works.
    I hope this helps you
    Regards,
    Eduardo

  • Account Group and partner functions in customer master records

    Hi Gurus,
    I need your help to confirm the following understand if correct:
    1. To create customer master record for partner function Ship-To, need to create a customer master record using the uniquely assigned account group for Ship-To , that is, 0002 . In this ship-to master record, define in its partner function tab, the other partner functions related to it. 
    2. To create the above, it cannot be achieved by just assigning the partner functions in the partner function tab of SOLD-To customer master record , created using account group 0001.
    Question:
    1. How does the system know or allow what codes a user can select (f4) or enter manually when defining in customer master record's partner function tab, the partner functions and their respective codes?
    How is this controlled? Is it by user authorization? or will user / sales administrator be able to select any codes tied to a partner function?
    2. Lets say there are 2 partner functions : Sales employee VE and 9E called Sales Representative. Both of these partner functions are of Partner Type PE.
    When defining in customer master record's partner function tab, how does the system know what codes is selectable for the administrator for each of these partner functions?
    best regards
    M Russo

    hi russo,
    this is to inform you that,
    1. yes you are right.
    2. you need to follow the steps as you said.
    Question:
    1. that you can find in the search basing on account group for partners.  that assignment we should know russo which SH to be assigned to which SP.  no need to have authorization for that, make a note of the list of SH and SP to be assigned that's all.
    yes, he will able to select any SH from the list but make sure that we assign the correct SH to the list of SP.
    2. that you will be defining it in Partner Determination Procedures.  at the time of CMR creation you have to select the correct code that will get populated in sales order.
    hope this clears your issue.
    balajia

  • Vendor account group assign to Reconciliation account

    Hello Experts,
    Is it possible to customize a reconciliation account assignment to vendor account group?
    Our requirement is when you create a vendor, then select a vendor account group, the reconciliation account will automatically be proposed in the field. This is to avoid selecting wrong reconciliation account when creating a vendor.
    I had a look in SPRO but I couldn't find anything that could do that.
    Thanks in advance
    Regards,
    Catherine

    Thanks for your inputs,
    I have checked in the system if there is a user_exit. Could you please confirm me that the user_exit "GLPLAN00 - Enhanced authorization and master data validation" is the good one?
    My objective is to have the correct reconciliation account automatically populated when I am creating a customer/vendor with a specific account group.
    e.g. select account group - XXXX Non-trade customer / Reconciliation acct XXXXXX non trade customer automatically populated.
    Thanks in advance for your help.
    Catherine

  • Vendor search by matchcode - account group authorisation

    We have various vendor account groups including one for paying employee expenses. We are finding that users with access to vendor matchcode search can see vendors for all account groups (including employees) listed in the search even though we have restricted them by authorisation object F_LFA1_GRP to specific groups. Whilst they are not permitted to view full details of the employee the list does show address details. Does anyone know how we can restrict this?

    HI,
    most of the applications have no authorization checks implemented in their matchcode search....
    Please refer as example to [SAP Note 639188|https://service.sap.com/sap/support/notes/639188]
    I hope, this information helps...
    b.rgds, Bernhard

  • Permissions errors? ./private/etc/authorization, should be 80, group is 0

    in the past 3 days i've been finding a error show up- on several machines- where programs would quit before they would even start up.
    the only way i've found to fix it, has been to run "Disk Utility" and repair the permissions for the drive management.
    Repairing permissions for “Macintosh HD”
    Determining correct file permissions.
    Group differs on ./private/etc/authorization, should be 80, group is 0
    Owner and group corrected on ./private/etc/authorization
    Permissions corrected on ./private/etc/authorization
    has anyone else found this error? where is this coming from?

    Thanks!
    Until I fixed this error using Disk Utility, I couldn't install a 3rd party software app. I didn't log in as root to do it either, just repaired permissions and the install "took" the second time. I'm a member of the admin group... at least I thought I was! My user account says I'm an administrator and I'm the only user on this mac... any way to see what my user account rights are? I know netinfo, but I don't know how to interprate it?

  • Different field groups in the different account groups

    Dear IT Experts,
    I´m working on restructuring authorization in roles concerning the IC and TP customers.
    The goal of this changes is be able to have different field groups in the different account groups (TP and IC), for give you some more detail a good example can be, the same AMS user should be able to change general data and sales views for TP customers  but for IC he should only be allowed to change the sales views, however when the changes are made in the roles they are being ignored because as far as I could check the system does not have as a rule that the field groups are or can be dependent from the account group...
    I can give you a clear example:
    Role A
    F_KNA1_AEN -> VGRUP = 10-16
    F_KNA1_GRP -> ACTVT = 01, 02, 03
    F_KNA1_GRP -> KTOKD = INTR
    Role B
    F_KNA1_AEN -> VGRUP = 16
    F_KNA1_GRP -> ACTVT = 01, 02, 03
    F_KNA1_GRP -> KTOKD = THIR
    Despite it looks fine, the system is not validating the account group with the correspondent field group in each role, so the field groups that the system use is unique, it means it the content of the object F_KNA1_AEN in total independently of used account group!
    So my question is, can we apply any other object that makes the field group being directly depending of the account group, as we can see for example activities for each account group having something similar for field group and account group?
    Can someone please explain me step-by-step how I can do this work even if by another method?
    I´m quite new on this issues and I really need your wisdom to find a solution for this.
    Many thanks
    Katjia

    Hi Manoj
    The debate is each inidividual business unit has defined different account groups for the same vendor in their respective systems.
    The question is : What is the best practice-- Should we keep Vendor account group as main table field and define Vendors with one unique account groups OR we maintain the account group in qualified table each pointing to different business unit.
    In my opinion this is going to be very complex solution. Ideally we need to define all the Harmonization rules before syndicating data to different target systems.
    Is this possibel that the same vendor record which is existing as vendor of different account groups in different systems have same set of attributes. If yes then enabling the remote key for Account group Lookup field is one option and defining a unique Account group 'AG" (which is mapped to say AG1 from remote system1, AG2 from remote system2 and so on..)..
    Managing this via Qualified table will be very complex and not advisabel. As Rajesh also mentioned Account Group in MDM should be considered as Global attribute and all such harmonization rules should be defined in your project. AG1=AG2=AG in above exmaple.
    Hope this clarifies.
    Thanks-Ravi

  • Currency vs Account group restriction for vendor master

    Dear All,
    Is it possible to restrict the user from using inr for Import vendors account group and other currencies for domestic vendor account group in standard????

    Hi,
                Through authorization object F_LFA1_GRP (Vendor: Account Group Authorization ) field - KTOKK (Vendor account group) you can restrict user to create particular type vendor i.e Import Vendor or Domestic Vendor etc. Pls refer below screenshot...
    As k your Basis user to restrict as per account group ....Through PFCG transaction..
    Regards
    Abhishek Tiwari

  • Requirement: Customer account Group wise Sale area Allowed

    HI
    My client Requirement is Based on the account group system will allow few sales areas at the time of creating the Customer master
    Is it possible in SAP if Yes please guide what are settings required
    if No how to achieve this requirement
    Regards,
    Prasanna

    Hi
    As of my understanding we use account group for:
    1. Controlling Number Range
    2. Controlling fields (Display, Hide , Mandatory)
    3. Partner Functions.
    Now to control the Account Group for Sales Area  might not be possible (Please do check at your end).
    Here is a suggestion , if the master's are created by different user's try controlling it through Authorizations.
    And , use the number range as a criteria to identify the as like, Domestic customer no range 110001--1199999
    Export customer no range 220001--2299999.
    And also you can use the sale office and sale group from the Authorization control point of view , reporting point of view.
    Thanks...................Rishi

  • Customer Account Group Mark for deletion

    Hi Experts,
    As per the business requirement i need to block some of the customer account groups like(z001,z002 and z003)
    is there any config settings available for marking these account groups as blocked or only  deletion is possible.
    Thanks in advance
    Regards
    Satprk

    I am not sure whether the account group can be blocked by any means. I would not recommend deleting from the SPRO account group table data as it will affect the historical data.
    However, you can control using these account group using authorization objects. Check with basis personal to exclude these account groups from using in XD01 t.codes.
    Regards,

  • Authorization to Vendor Accout group in FBL1N

    Hi All,
    I want to restrict users in FBL1N based on the account groups. For example I want to authorize set of users to see a particular group in FBL1N.
    -- Syed Abid Hussain

    Hello,
    As standard it is correct that object F_LFA1_GRP is not checked in FBL1N.  So it is not possible to restrict using this authorization object.                                                                               
    This object is normally specific to only the master data area and not      
    related to the documents, therefore it is not checked.                                                                               
    You can check SAP Note 1166486.      Any problem, please let us know.            
    REgards,
    REnan

  • Manual posting to reconciliation account under asset account group

    We need to maintain Asset Group (G007) to allow manual input in order to post a period end-closing adjustment as required by our external auditors. ( i.e in the reconciliation account under the asset account group, we need to check the 'allow manual input' option so as to do posting to this account manually).
    Under normal circumstances, the posting should have been from WBS Element, to AUC, then to Fixed Assets.  However, since all the procedures have been completed until Depreciation Run, we have no option but to input this manually.
    Similar Recon accounts which allow manual inputs are Accounts Receivable (GL Code 115000) and Accounts Payable (GL 210000). 
    My intention is to have this captured in the system as of Dec. 31, 2008; Reversed the same transaction on 01-Jan-09 and process it normally as mentioned above.
    Valuable assistance will be highly appreciated.
    Best regards,

    You can make manual postings on the asset reconciliation account with the transaction ABF1
    Use PK 70 or 75 , G/L account and transaction type 100.
    The result is that asset accounting is no longer in line with your G/L accounts.
    Put this transaction in your authorization make the posting and reverse and take the transaction out off the authorization!

  • Restrict FI postings from FB60 at vendor account group level

    Hi Experts,
    We have a requirement whereby the authorization for posting from T-Code FB60 should be controlled at vendor account group level (LFA1-KTOKK).
    We are also fine with restrictions at vendor master authorization group level (LFA1-BEGRU/BRGRU).
    So a particular user should be able to post to a vendor in acct grp A but not acct grp B from FB60.
    However, it seems that T-Code FB60 checks only objects BKPFBLA, F_BKPF_BUK, F_BKPF_GSB, F_BKPF_KOA.
    Neither of the above 2 fields are available in these 4 objects.
    In case you have a solution for restricting FB60 postings, please reply.

    Hi.
    In vendor maser data you can maintain LFB1-BEGRU='vendor group', and check it in F_BKPF_BEK-BRGRU

  • Account group for Customer

    Hi is there any Transcation to find Account group for particular Customer. Other than XD07 as we dont have authorization for XD07 in production.
    Regards
    Nagesh

    Hi,
    in XD03, enter customer number, view the customer and go to "Extras / administrative data", there you can see the account group.
    Best regards, Christian

  • Object assignments for account group

    Hi,
    In customer when I click on assigned object in additional data,I am getting the following error,
    "Account group ZSP1 is not registered for object assignments"
    Where ZSP1 is my account group.
    Where I can register my account group for object assignments
    Regards

    Hi Sandeep,
    for what you are looking for object name of release group.???
    If you want to add release group in Authorization profile,it is not possible.
    You can add Release code in authorization profile...not release group.
    If you have any specific requirement,please let me know.
    Regards,
    Manish.
    If ans is usefull,don't forget to reward.

Maybe you are looking for