Authorization to restrict G/L Account

Dear All
I am looking to restirct postings to GL account based on the user in T Code F-02. Can any one highlight which authorization objects can i use to restrict user for posting to GLs and Cost Elements
Your valuable input is required in this aspect.

HI,
On the GL master in FS00 there is authorisation group field in the control data tab, you can use this. It is a free text and the user will need this assigned to him in his role.

Similar Messages

  • BW report authorization for restrict cost center

    dear all,
    i have problem on BW report authorization for restrict cost center.....when i execute the query, after selection screen, appear error message 'you cannot change zv_cctr for characteristic 0COSTCENTER during query'.
    note : zv_cctr is variable restriction for costcenter, type processing = customer exit.
    below the customer exit :
    WHEN 'ZV_CCTR'.
        IF i_step = 2.
          DATA : gt_mstuidvscc TYPE TABLE OF  ztbw_mstuidvscc,
                 gs_mstuidvscc TYPE  ztbw_mstuidvscc,
                 wa_final2(10) TYPE c.
          SELECT * FROM ztbw_mstuidvscc INTO CORRESPONDING FIELDS OF TABLE gt_mstuidvscc
            WHERE userid = 'sy-uname'.
          LOOP AT gt_mstuidvscc INTO gs_mstuidvscc.
            wa_final2 = gs_mstuidvscc-kostl.
            l_s_range-opt = 'EQ'.
            l_s_range-high = wa_final2.
            APPEND l_s_range TO e_t_range.
          ENDLOOP.
        ENDIF.
    Regards,
    Tony

    i defined variable as ready for input and mandatory.
    regards,
    Tony

  • How can I authorize and access my itunes account on a new computer if I cant access my old computer to enable home sharing

    How can I authorize and access my itunes account on a new computer if I cant access my old computer to enable home sharing

    Authorization
    Macs:  iTunes Store- About authorization and deauthorization.
    Windows: How to Authorize or Deauthorize iTunes | PCWorld.
    In iTunes you use the Authorize This Computer or De-authorize This Computer option under the Store menu in iTunes' menubar. For Windows use the ALT-S keys to access it. Or turn on Windows 7 and 8 iTunes menus: iTunes- Turning on iTunes menus in Windows 8 and 7.
    To deauthorize a computer you don't have:
    De-authorizing Computers (contributed by user John Galt)
    You can de-authorize individual computers, but only by using those computers. The only other option is to "de-authorize all" from your iTunes account.
      1. Open iTunes on a computer
      2. From the Store menu, select "View my Account..."
      3. Sign in with your Apple ID and password.
      4. Under "Computer Authorizations" select "De-authorize All".
      5. Authorize each computer you still have, as you may require.
    You may only do this once per year.
    After you "de-authorize all" your authorized computers, re-authorize each one as required.
    If you have de-authorized all computers and need to do it again, but your year has not elapsed, then contact: Apple - Support - iTunes - Contact Us.
    For more information on authorization and de-authorization: iTunes Store- About authorization and deauthorization.

  • I want to authorizes all computers from my account

    I want to authorizes all computers from my account

    I quote from the document I linked to above:
    Click iTunes Store on the left side of iTunes.
    If you're not signed in to the store, click the Account button, then enter your account name and password.
    Click the Account button again (your Apple ID appears on the button), enter your password, and then click View Account.
    In the Account Information window, click Deauthorize All.
    Note: You may only use this feature once per year. The Deauthorize All button will not appear if you have fewer than two authorized computers. If you need assistance on using this feature, please contact iTunes Store support via email (http://www.apple.com/support/itunes/store/).

  • How to create authorization groups for G/L Accounting

    Hi:
    I have a problem with authorizations groups in FI, I hope you could help me.
    We want to control access to accounting in FI by authorization group so user only can work with some G/L accounts.
    I have seen in transaction FS00, in control data tab, a field called Auth. Group, but I really donu2019t know if this is the right field.
    Do you know how I can control access to G/L Accounts by Authorization Groups? Perhaps must I to create a new Authorization Group by roles? We have 4.6c.
    Please, any help is welcome.
    Thanks in advance.

    Hi
    Update the authorization group field in the GL master with any user defined value and then include the same in the respective user roles against the authorization object - F_BKPF_BES-BRGRU in PFCG
    Ensure you have updated 'Authorization group' for the GL accounts in your chart of accounts
    Thank You,

  • I can't authorize or de-authorize my computer from the account. What do I do?

    I can't authorize or de-authorize my computer from the account. What do I do?

    I would make contact with the carrier, since texting and phone calls are their problem.

  • Set Up Authorization Check for G/L Accounts  into PO creation

    Dear friends !
    How could I activate check to the access to certain accounts into PO creation ?
    I know that is possible to activate this into Purchasing customizing under path
    SPRO > Materials management > Purchasing > Purchase order > Set Up Authorization Check for G/L Accounts
    But could I use it to give access only to certain GL Accounts by user ? Is this the purpose of this customizing ?
    If yes what´s the object should I use to link with user account !?
    best regards,
    Ale

    Hi ,
    After you setup the configuration in transaction OMRP, please setup up
    the authorisation group in the account code (FS02, the field is on the
    "Control", technical name is BEGRU).
    When a account assigned purchase order is created, the system checks for
    object F_BKPF_BES with values from the BEGRU and activity 01.

  • After getting a txt message from bell today saying I went over on my data usage , I can not access my web browsing at all... There is no restrictions on my account. But I still can't load safari

    After getting a txt message from bell today saying I went over on my data usage , I can not access my web browsing at all... There is no restrictions on my account. But I still can't load safari... I can still makes calls and send txt messages but I can't send iMessages

    Settings > General > Reset > Reset Network Settings.

  • Authorize songs from a previous account

    I have songs on my Itunes that I need to authorize for my current account. These songs were purchased on my first account but then I had to change account information when I no longer had access to that e-mail. Is there anyway that I can authorize these tracks for this account? Thank you

    Purchases cannot be transferred from one account to another. You may be able to sign into the account, even if the email address doesn't actually work, since basically it's just a text string where logging in is concerned. Then you could authorise the Mac for that account.
    However you would be advised to go to http://appleid.apple.com and change the ID email to a functioning one, which can be any non-Apple address that hasn't been associated with an Apple ID in the past. If you do this please follow this procedure:
    Firstly, if you have 'Find My iPhone/iPad/iMac' enabled on any of your devices, turn it off.
    Create a new email address, for example  at Yahoo or Gmail, or anywhere convenient (or you can use an existing address as long as it has never been associated with an Apple ID).
    Go to http://appleid.apple.com and click 'Manage your Apple ID'. Sign in with the current ID.
    Where it says 'Apple ID and primary email address' and gives your current ID email address, click 'edit'.
    Enter your new address and click 'Save changes'.
    Now you will need to go to each of your devices and sign out in System Preferences (or Settings)>iCloud - 'Sign out' on a Mac, 'Delete this account' on an iOS device (this will not delete the account from the server).
    Then sign back in with your new ID. Your iCloud data will disappear from your devices when you sign out, but reappear when you sign back in.
    I re-iterate: before you start, turn off 'Find My Mac' (or whatever) or you will need the services of Support.
    Note that if you have made purchases on another Apple ID you can't have them both up in iTunes at once, and you can't keep swopping between them - there is a 90 day limit on changing to another account.

  • Authorization Group for G/L Account

    Hi,
    What?
    - I wish to restrict the 'posting' of a G/L account to be done by certain users only
    How?
    - What I have done was...
    a) From FS00, I have added a free-text (BANK) into the Authorization Group for a G/L account
    b) From PFCG, a new role was created to allow these 2 Authorization Objects, F_BKPF_BES and F_SKA1_BES
    c) 'BANK' was entered for the Authorization Group for both these 2 Authorization Objects
    d) From there, I have assigned this new role to the user that I wish to allow Posting of the G/L account
    Problem?
    - Other users still can do Posting for this G/L account
    - Any steps which I have missed out here or done wrongly?
    Thanks,
    Brandon

    Hi,
    Some other roles of the users may override and cause the users to post against this GL account.
    Check all the roles relevant for the restricted users. 
    Use SUIM t-code to find if the auth object mentioned above is included in any other role.
    If it be, restrict that again.
    Generally if one role as no restriction against this auth and not all, this issue tends to happen.
    Regards,
    Sridevi

  • How  to Restrict G/L Accounts for One  User

    Hi All,
    I have to restrict the G/L Account when doing FI Postings  for  some particular Users ...
    Ex 100000 Is G/L to be Posted In  XXXX Plant.
         100001 Is G/L to be Posted in  YYYY  Plant 
    I have to give an Authorization  to User in XXXX Plant  to Post only  in 100000 G/L .
    Plz Suggest me at which level I can restrict the Postings ..
    Regards,
    Sriram.

    How about flagging the accounts as "Automatically posted only" and then let customizing take care of the ability to post to the accounts (automatic account determination)?
    That is, if that works for these specific accounts.
    Cheers,
    Julius

  • Authorization group restriction

    Hi ,
    I would like to know how to restrict authorization group FCAR and FCAP.We could see it is related to F_BKPF_BES object .It seems the same authorization object should be given the following access
    --display access for documents asigned to authorization group FCAP
    --should not allow display for documents assigned to authorization group FCAR
    If we restrict using FCAP (displays access)the second condition works fine but the first one it displays line items only for G/L accounts.Vendor line items does not get displayed.
    Please let me know your thoughts on this.

    Hi Mekha,
    You can add another object F_BKPF_BES manually and in the first one give
    display access for documents asigned to authorization group FCAP  and in another no display for documents assigned to Auth group FCAR
    **Reward points accordingly
    Junaid

  • Authorization check at G/L Account level!!

    Hello,
             We have a requirement to restrict user to access only particular G/L Account .
    We had look at authorization objects but not able to resolve the problem.Kindly suggest the best possible way to resolve this problem
    Regards
    sam jase

    Please refer to this thread:
    https://forums.sdn.sap.com/click.jspa?searchID=11099062&messageID=4918626
    Reward point if useful

  • Park Invoice-MIR7 - Authorization to restrict PO Reference

    Hi all:
      I'm looking the way to restrict user get data from "PO Reference" when Park invoice(MIR7), only can use "G/L account" option, because we dont want some user to see PO's information. is this possible??
    1. It seems that there is no standard authorization object can do this in MIR7, the object M_RECH_WRK/M_RECH_AKZ not work for this.
    2. I tried used "SHD0 - Transaction Variants" to hide the "PO Reference" option, looks work fine in the begining.
        But then I click "other invoice document", want to test "change" function. if I choose the IR Doc. which with PO reference, the screen transfer to "MIR4" and shows the information about PO, so not a good solution.
    3. and now , I'm trying BADI/Enhancement/exit can do this and still in searching....
    Any idea about this, thanks.
    SAP Environment ECC 6.0

    solved.

  • Files in other user account are restricted to admin account...

    Hi everyone.
    2 weeks ago, I've created a user account for my wife on my Mac Mini for iphone syncing purposes. My account is admin and hers is standard. Everything works great except restricted access to files.
    Besides regular Time Machine backups, I manually back up the iTunes, Address Book and iCal files on an external drive.
    Files on my user "side" are no problem, but when I try to access the files from Macintosh HD/Users/Wife path, I get all these folders with a small red "No Entry" sign just like the traffic one.
    I click "Get Info" and see that only my wife's user acc has "Read and Write", everyone is marked as "No access" and I'm not even there.
    Funny thing is, system asks for my permission to do the changes, but I'm not listed.
    What I do so far is to click "Get Info", go to permissions, unlock (a window pops up with my name as admin and I have to enter my main pass), add my name to the permitted users list, change it from "Read Only" to "Read & Write".
    Repeating these steps for each folder is becoming a bore. Can anyone give me a shortcut where I can have access to all files on any user account?

    Kappy,
    I think you've misunderstood my point. My wife has her own netbook and uses my PC at home just for syncing her phone. Reason is I'm the able one with computing related issues and she is distant to Mac.
    I created the user account for her, but she is the one who insisted on not having admin privileges as she wanted to avoid changing sth irreversibly by mistake.
    I log into her account for backup, but spend a lot of time moving media files from my locations to her itunes folders. That's when I need access to those restricted folders.
    Security in our household is not an issue as my trustworthiness is a BIG yes-yes.
    Now, apart from your guidance on moral issues and appropriate log-in 101, thank you for your clarification.
    Regards

Maybe you are looking for

  • Problem with SNR on CME

    Dear Experts, I have problem with SNR on CME. When I make call from internal, SNR is working, but when calling from outside to one of my SNR extension, its not working - not ringing on mobile device. but from extension 43 I am allowed to call xxxxxxx

  • HT204053 I want to change my apple id on the ipad to use the same id on all devices but how?

    How do I change apple ID on a device such as iPad or iPhone?

  • How to Install oracle 8i on Windows Vista Ultimate

    Hii, I want to install oracle 8i in my laptop. I am using Vista Ultimate OS. I am getting a java runtime error. why is it happening ?

  • OCCI version problem

    Hi, I am having a version problem with 9i. How can i compile OCCI with 9i database installetion? Which library would i need? my server is a SOL-Sparc-64 machine and oracle database server is installed there versiion oracle 9i 32bit. I tried to compil

  • TABLES ARE NOT FOUND

    hI, I WANT TO KNOW WHY AFTER I RUN THE SYSMGMT1 SCRIPT, I STILL CANNOT SEE THE APPLICATIONS, HOSTS AND DATABASES TABLES IN THE OBJECT BROWSER PAGE. iM USING ORACLE DATABASE 10G EXPRESS EDITION. IT SAID IN THE BOOK THAT AFTER I RUN THE SCRIPT I SUPPOS