Authorization Check on GL Account Group (KTOKS)

Hello,
During Create/Change/Disply of G/L account master, need to apply the restriction on a particulare GL account group.
G/L account group field is a list box and user cna select one account group from the list. When the user selects othere than the one for which he doesn;t have Authorization, we need to raise an error message.
How can we apply the Authority Check to the G/L account group in FS00 transaction.
If any of you come across this kind of requirement, please let me know.
Thanks,
MPREDDY

Hi,
In SU24 for tcode FS00 I cannot find any auth.object for this field. So, you can try to create your own auth.object with tcode SU21 and insert in the ABAP coding of the enhancement SAPMF02H (EXIT_SAPMF02H_001). After, set this auth.object in tcode PFCG for users, users-groups and so on. View how to insert and manage the error message with other auth.object if you want that the logs of tcode SU53 works.
I hope this helps you
Regards,
Eduardo

Similar Messages

  • Authorization checks for bank account number in vendor master

    I am trying to find a way to set up authorization checks for specific fields in the vendor master: LFBK-BANKL, LFBK-BANKN, LFBK-EBPP_ACCNAME and LFBK-EBPP_ACCNAME. I am tring to set ip up so that if you have access to transactions FK03 or XK03, you can view vendor master data except for the above fields.
    Does anyone know of a way to accomplish this? Your help will be greatly appreciated.
    Thanks
    -Peru

    HI Peru,
    To supress a field in FK03 u will have to check
    Financial Accounting (New)>Accounts Receivable and Accounts Payable>Vendor Accounts>Master Data>Preparations for Creating Vendor Master Data-->Define Screen Layout per Activity (Vendors)
    in that Display Vendor (Accounting) for FK03 and Display vendor (centrally) for Xk03
    But there bank account no is not there.
    Moreover there r no authorization objects for all the fields that u gave.
    So try creating screen variant/ transaction variant in SHD0.
    Regards,
    Kiran

  • Authorization by GL Account Group

    Hi,
    Is it possible to restrict authorizations by GL account Group (KTOKS)?
    Regards,
    Raj.

    Hi
    Please go through the below mentioned links
    Authorization Check on GL Account Group (KTOKS)
    how to creat authorisation group for gl posting
    Authorization Group for G/L Account
    Config - Authorization Group in G/L code
    Regards
    Praveen P C
    Edited by: Praveen Chirakkel on May 18, 2011 6:17 AM

  • How to search for vendor account group

    hi expert,
    how to check for vendor account group that contains of certain condition? And where to assign this in PIR?
    thanks

    HI ,
    You can see Vendor account group by XK03, here just enter Vendor code (for which you want to see Account group) and enter company code and Purchase Org. , Tick Address , Tick Accounting info. and press Enter
    Now In Display Vendor Address there is icon in Blue colur *Administrative data (Shift +f8) click on this now
    YOu can see Vendor Account group.
    enjoy
    Regards,
    Vraj

  • Currency vs Account group restriction for vendor master

    Dear All,
    Is it possible to restrict the user from using inr for Import vendors account group and other currencies for domestic vendor account group in standard????

    Hi,
                Through authorization object F_LFA1_GRP (Vendor: Account Group Authorization ) field - KTOKK (Vendor account group) you can restrict user to create particular type vendor i.e Import Vendor or Domestic Vendor etc. Pls refer below screenshot...
    As k your Basis user to restrict as per account group ....Through PFCG transaction..
    Regards
    Abhishek Tiwari

  • Validation of vendor number vs. Accounting Group

    Hello Experts,
    We are using ESO 5.1 with integration package, connected to an ERP 5.0 backend system.
    I've confirmed an issue when creating a vendor in ESO for publishing to ERP, as E-Sourcing does not validate the vendor number the user is assigning. System only checks if the Accounting group has a internal or external numbering.
    Has anyone encontered this issue before? Any standard solutions for this?
    If so, I'll appreciate if you can share how this issue was solved. Validation script? If so, can anybody share or give me some pointers on how to create it?
    Thanks!
    Regards,
    GG

    I can answer by words of Axel Angeli - top level SAP R/3 consultant and R/3 cross-application development coach, the author of classic book "SAP R/3 Guide to EDI, ALE and Interfaces":
    "SAP R/3 delivers a serious of predefined EDI programs. Many project administrators see them as standards which should not be manipulated or modified. The truth is, that these IDoc processing functions are recommendations and example routines, which can be replaced by own routines in customizing."
    and
    "SAP R/3 is delivered with a series of predefined IDoc types and corresponding handler function modules.
    Some of the handler programs have been designed with user-exits where a developer can implement some data post-processing or add additional information to an IDoc.
    You must always see those programs as examples for IDoc handling. If the programs already do what you want, it is just fine. But you should never stick to those programs too long, if you need different data to be sent."
    So now you can feel free to customize
    Regards,
    Maxim.

  • Account group mapping is not uderstand ?

    Hi Experts,
    I am not understanding the mapping between the account groups.
    If you check under "Customer Account Group" the field name "Group", I dont understand where it is mapping to other account group?
    And how all the account groups linked with eachother? (G/L, Customer, Vendor)
    Please check..
    Thanks

    Hi,
    i had the same error 'account group DEBI not defined - CRM_BUPA_FRG0040' when trying to download my R/3 IS-U business partner from R/3 -> CRM. I checked PIDE settings, groupings and number ranges (internal/ext) settings dozens of times and had no explanation.
    I made the same experience that suddenly my BP were downloaded when i  DELETED  the entry in PIDE (but they were created in CRM not in the customized number range)
    The final reason was that i did not properly download all the csutomizing mentioned in the
    SAP best practice building block configuration guide B09
    There the object DNL_CUST_KTOKD was mentioned - it contains the R/3 account groups which have to be transferred to CRM in spite of the fact that CRM business partners don`t have an account group
    For the sales data the replication object CUSTOMER_MAIN has to be used - this contains the R/3 IS-U SD customer. The replication object BUPA_MAIN contains the R/3 IS-U Business partner. This is also the reason why downloading BUPA_MAIN might work even without the proper account group settings in PIDE, the PIDE settings are important for the R/3 SD customers
    Edited by: sapgipsy on Apr 9, 2010 3:56 PM

  • Authorization check in BW

    Hi,
      I need to run authorization check  for another user in BW ..How can i do it
      if i run SU53 it is doing the authorization check for my account
    Thanks

    Hi Super,
                   You can check Authorization check in BW or in SAP using SU53 and enter user name of the already executed SU53 in the following way
    > enter SU53 -
    > then click on Copy button on left top side----
    > enter the user ID of executed user, you can see SU53 report this is one way you can retrive others SU53 reports. So in the BW authorization check can be done in the following way
    > enter RSSM----
    > in the bottom there is button of trace or error logs -
    > Enter user ID and run the trace or error logs
           Hope you understood, let me know if you need more details
    Thanks
    Qureshi

  • Idoc - Account Group

    Hi All,
    I want to bring replicate customer master from one sap system to another.
    In one system, the account group is DEBI and in the other the account group should be ZABC. I have entered in settings in BD79 where account group was set to constant ZABC.
    After sending the data over, i got this error - Account group in the IDoc is different (Message no. B1 356).
    Is there any way I can change account groups?
    Thanks.
    -Charlene

    Hi Tan,
    Is the account group ZABC exists in the target system?
    =======================================
    Can you check the Inbound funtion module => Is there any check towards the account group like if you pass ZABC, the function check whether it is some other(say DEBI) if not set a message 51?
    Regards
    eswar
    Edited by: Eswar Kanakanti on Dec 19, 2008 5:17 AM

  • Authorization checking in BAPI

    Hi,
    I put in authorization checking for the 'Material group 1' field of a SD document. With this, only authorized users are allowed to change this field while other users without the authorization will not be allowed to change it. When i tested the authorization in VA02, it works fine. I was able to change it as i has been assigned with the required role/profile. On ther other hand, the other user without the role/profile was not able to change the field using VA02. I did another test using a Z program that calls 'BAPI_SALESORDER_CHANGE'. The Z program will change the 'Material group 1' field using 'BAPI_SALESORDER_CHANGE'. My initial thought was me with the required role/profile when running the Z program, will be able to change the field while the other user without the required role/profile will not be able to change it when running the Z program. However, the result shows that both users (with/without the role/profile) was also able to change the field using the Z program. Is there anyway to control the BAPI so that it works the same as in VA02? Thanks much for your advice.

    In your coding change
    IF sy-tcode = 'VA02'.
    to
    IF T180-TRTYP = 'V'.
    Then your coding will also work with BAPI. Try putting a break point before the If clause and execute the BAPI, you can see it yourself.
    SAP will set T180-TRTYP = 'H' for create, = 'V' for change and = 'A' for display.
    T180-TRTYP is a SAP recommended field to be used in user exits to know if the document is being created, changed or displayed
    If sy-tcode = 'VA02' will not work with BAPI as you are actually not executing transaction VA02.
    Also just disabling screen fields for input will not have affect on the BAPI call.
    You would need to ensure it through separate coding

  • Account Authorization Checks

    In SRM 4.0, we use the backend to determine what account authorization a user has.  This has worked pretty well until we applied SP12.
    All of our users were given the Employee job role in SRM in order to create carts.  If the user is considered a central user, they can create carts using any account.  After SP12, these users were only able to create carts to funds centers in their profile and it did not look at the fact that they also had central roles.
    Our programmer has modified his authority check function module.  However, this will look at users that have any central role.  We don't want that to happen.  Without completely modifying the function module, how do other organizations allow their central users to create carts using any account.  Are they given a separate role on the SRM side that differs from the departmental users?
    Would the separate role in SRM override their R3 security?
    Any help and advice would be greatly appreciated.  Thanks.
    Monique Stephens

    Monique,
    We do not limit g/l accounts by user per se.  That is a large task for a company of our size and we have too many exceptions to the rule.
    Instead, we created a custom table, overriden the search help and added custom edits to limit g/l accounts by material group (product catagory).  This guides the usage of g/l accounts which keeps our account group happy.
    BTW, we also doo addtional check for account assignments (orders, WBS elements, etc.) to prevent problems in R/3, which keeps our purchasing group happy.
    I hope this helps.
    Regards, Dean.

  • Set Up Authorization Check for G/L Accounts  into PO creation

    Dear friends !
    How could I activate check to the access to certain accounts into PO creation ?
    I know that is possible to activate this into Purchasing customizing under path
    SPRO > Materials management > Purchasing > Purchase order > Set Up Authorization Check for G/L Accounts
    But could I use it to give access only to certain GL Accounts by user ? Is this the purpose of this customizing ?
    If yes what´s the object should I use to link with user account !?
    best regards,
    Ale

    Hi ,
    After you setup the configuration in transaction OMRP, please setup up
    the authorisation group in the account code (FS02, the field is on the
    "Control", technical name is BEGRU).
    When a account assigned purchase order is created, the system checks for
    object F_BKPF_BES with values from the BEGRU and activity 01.

  • Cost element group authorization check on controlling area level

    Hi!
    When maintaining cost element groups (KAH1, KAH2, KAH3) is it possible to run an authorization check on controlling area level?
    We have one global chart of account but several controlling areas. When we create a cost element group it is created at chart of account level for all the controlling areas. When someone changes a cost element group it changes in all controlling areas. I cannot restrict user's authorization to be able to change cost element groups only in their own controlling area.
    Is it possible somehow?
    Thanks for your help.

    Hi,
    Like how the global chart of accounts is at the client level, the cost element groups are also independent of the controlling areas.  Infact, the cost element groups are created at the global COA level. 
    In such a case, I don't think it is possible to restrict the authorizations to amend the cost element groups at controlling area level.
    Thanks and Regards,
    Bhuvaneswari.S

  • In which tables the GL  account group  field KTOKS

    Hi,
    From which tables the GL  account group  field KTOKS  get
    Regards,
    Siva

    hi
      DKOKS                            Open Item Account Balance Au
      DSKOS                            Balance Audit Trail
      SKA1                             G/L Account Master (Chart of
      T077S                            G/L account groups
      T077Z                            Account Group Names (Table T
    regds
    laks.

  • Error - Account group  does not exist, check classification assignment

    Hi Guys,
    I am having an BP replication issue from CRM to R3 when i create BP from Web IC with role UTIL_IC. BP gets replicated to R3 if i create BP from GUI.
    Bdoc Error - Account group  does not exist, check classification assignment
    i have completed all the required configuration as below
    Setup of no range for BP and assigned to grouping
    PIDE settings in R3
    Setup if account identification profile in IS solutions
    Thanks,
    Nitin

    Nitin,
    Refer to [this|BP replication error; &[this|Contact Person Replication From CRM to R/3; thread.

Maybe you are looking for