Authorizations in SAP PI

Hi all,
dealing mainly with authorizations in ERP I am new to authorizations in PI. Therefore I am facing a problem with this situation:
1.Three roles with authorizations in ABAP and Java are expected: Developer, Supporter, Monitoring.
2. HR data is strictly confidential. FI, CO etc. data is not quite so confidential.
I am asked to find out if there is a way to create a scenario that differentiates which data - HR or ERP - are displayed e.g. on the level of the sender.
The display of the payload is another point which I will  have to consider.
I have seen that there are SAP roles but I am not quite sure how and if I can use them and adapt them to my needs.
Help is greatly appreciated.
best regards
August

Hi,
please have a look at <a href="http://help.sap.com/saphelp_nw04/helpdata/en/89/05793c05f0807be10000000a11405a/frameset.htm">Roles and Tool Access</a>, especially at Roles for ABAP and Java Tools, these are the authorizations needed.
You can assign roles from transaction SU01
refer the below link also.
http://www.erpgenie.com/sap/netweaver/xi/xiauthorizations.htm
Regards
srinivas

Similar Messages

  • I want authorization for SAP classes

    my company are provided computer courses.I want authorization for SAP classes.what are i doing for this process

    Hi,
    can you please reformulate your question? Are you looking to become an authorized training partner? If so which country?
    Thanks,
    Arnold

  • Question regarding Authorizations in SAP CRM 7.0

    Hello,
    The problem is this:
    We have a client who will use two ways of accessing SAP CRM 7.0 data -
    1. CRM Web UI
    2. Mobile devices via standard SAP CRM BAPIs
    Now the situation is that the client wishes to control display authorizations based on the Business Role. Certain Business Roles can allow its User to see Accounts where the User is also Employee Responsible and certain other Business Roles can allow its User to see all those Accounts that are associated with that Role. In summary Business Roles control what an User can see.
    This has already been implemented for the CRM Web UI using the Access Control Engine (ACE).
    Now the questions are:
    1. How do we implement this for BAPI Access?
    2. Should we recreate what has been achieved by ACE, via PFCG Authorization Profiles?
    3. Can we not reuse what has been done by ACE?
    4. What are the runtime APIs that allow somebody to use the authorization checks of ACE?
    5. Does the standard Function Module CRM_ORDER_CHECK_AUTHORITY_ACE help in this regard?
    Any help here will be greatly appreciated. Please let me know if you need any clarifications.
    Thanks in advance.
    Best regards,
    Sudhi

    Hello,
    Normally, some notes are recommended in addition to the current support package implementation because they were developed to solve any known issues. These known issues occurred as side effect of any note which belongs to the implemented support package.
    If you take a look at older release notes, you will see the same.
    This is a part of implementation stack.
    1345085  SAP SRM 7.0 SP Stack 04 (09/2009):Release & Information Note 
    1365574  SAP SRM 7.0 SP Stack 05 (12/2009):Release & Information Note   
    1436687  SAP SRM 7.0 SP Stack 06 (03/2010):Release & Information Note 
    Kind regards,
    Ricardo

  • ICSS: authorization in SAP CRM 7.0

    Hello Experts,
    Is it possible to restrict via authorization acces to diffrent types of transaction in ICSS in SAP CRM 7.0? For example some clients can have acces to complaints, some to service request and some for both.
    Regards
    Piotr

    Of course, you can. If you are creating the Z: roles for SAP_CRM_ECO_ISE_WU_B2B, then in this role, in the CRM Component, there is an authorization object called CRM_ORD_PR and a field name PR_TYPE. You can go an change the individual users with access to different transaction types or create Z: object or Z:role for each group as you wish. Use the field name ACTVT to control the access to the transaction type.
    Please note, there may still be some discrepancies in the search selection in the ICSS. Though you may want to restrict the user to not to access "Complaints", the restriction may work at the transaction level, but not at the search level. You may still see "Complaint" object in the Search dropdown list.  I am not sure if SAP has covered all the features of ICSS to abide by this role.

  • Window Authorization of SAP B1

    Hi all,
               what kind of authorization(windows) do we need to run SAP B1. I want to list all the possible reason if add-ons gives error 'cannot connect to DI API, Corrupt Memory'.
    Thanks
    Rahul

    Hi Rahul,
    To install B1, users need admin right. To run it, normal user authorization is fine.
    Thanks,
    Gordon

  • Customized Authorizations in SAP ISA Frame work

    Hi All,
    I am using SAP ISA Frame work in my project and displaying customized Authorizations in my Project and i want to add new Authorizations in my Project.
    Please let me from where these authorization data is coming whether it is coming from back end  or front end.
    If it is front end from which file these data is coming.
    I am expecting it is coming from some xml file and i would like to know from file name of xml.
    regards,
    suresh

    Hi All,
        Any suggestions please
    Regards
    G.s.naidu

  • Authorizations for sap bw consultant

    Hello,
    Need to know that roles and authorization objects must have a bw consultant in the production environment.
    In my project we are two consultants, and we have assigned our profile SAP_ALL. This profile so we have to remove and assign the appropriate permits.
    "I can stay here for a list of the most relevant authorizations?
    Sincerely,

    Hello Pmarques,
    It is always though to come up with this specific role (SAP has no recommended composite role for consultants) list since it depends on specific customer preferences. I would suggest to use the following authorization objects and customize per your needs - this should cover all typical support activities.
    S_RFC             
    S_TCODE                   
    S_BTCH_JOB        
    S_BTCH_NAM        
    S_C_FUNCT         
    S_DATASET         
    S_GUI             
    S_OLE_CALL        
    S_RZL_ADM         
    S_TABU_DIS                
    S_DEVELOP         
    S_TRANSLAT                
    S_ALV_LAYO        
    S_APPL_LOG        
    S_BDS_D           
    S_BDS_DS          
    S_IDOCCTRL        
    S_IDOCDEFT        
    S_IDOCMONI        
    S_IDOCPART        
    S_IDOCPORT        
    S_OC_DOC                   
    S_RO_OSOA          
    S_RS_ADMWB        
    S_RS_BITM         
    S_RS_BTMP         
    S_RS_COMP         
    S_RS_COMP1        
    S_RS_DS           
    S_RS_DTP          
    S_RS_FOLD         
    S_RS_HIER         
    S_RS_ICUBE        
    S_RS_IOBJ         
    S_RS_IOMAD        
    S_RS_ISET
    S_RS_ISOUR
    S_RS_ISRCM
    S_RS_MPRO
    S_RS_ODSO
    S_RS_PC   
    S_RS_TR   
    And S_TCODE containing transactions RRMX, RSA1, RSPCM, RSKC, RSPC, RSPRECADMIN, RSU3O, SE16, SM37, SM50, SOST, ST22, SU53.   
    Hope this Helps!!
    ... Venkat.

  • Reg : Authorization of SAP in CMC

    Hi Mates ,
    i have created the WebI reports using the universe , and have published into Infoview , for that report SAP User with roles assigned , i have tested the query in BW it works fine. but when calling the webi report in Infoview using the sap user its not giving the exact company level data , the authorization doent work , is there any setting to follow in CMC.
    Integration Kit Installed .
    Is there any steps to follow.
    Thanks

    Hi
    When you created the universe did you choose sso when you created the connection? probably you have configured the connection with a fixed username and password?
    Regards
    Roland

  • Authorizations in SAP Solution Manager

    Hello all,
    does anyone know how can i (of if i can) give permissions for the workcenters but only for a Solution ?
    For example, a client has two landscapes and they want to use one solution manager for monitoring, but they want to restrict access to both landscapes by two teams. Each team should ony have access to "their" systems.
    Do you know how to do this ? Is there an organizational level per Solution ?
    Best Regards,
    Maria Serra

    Hi Martha,
    As Jared said, there is always an option to restrict the access to solution via this object:D_SOL_VSBL. You still have a way to restrict access on workcenter via the role :SAP_SMSY_* and inside it on the Authorization object : S_SMSYSYST.
    But i would still suggest to have separate solutions for each landscape considering your requirement as it offers wider authority for each process. Like setup and operation for each elements in monitoring. You can find solution for your scenario in solman [security guide|https://websmp106.sap-ag.de/~sapidb/011000358700000370562009E/SM_SECURITY_SPS23.pdf].
    Hope this helps.
    Regards,
    Jagan

  • Authorization from SAP BW 3.5 in Portal

    Hi Experts,
    i am buidling a scenario in SAP BW 7.0 using the authorization concept from SAP BW 3.5.
    Now i publish the reports in the portal. Everything is working good.
    Now my question:
    That we are using the old authorization concept, will it be a problem to adapt the concept into the portal?
    Could you please provide documents how to deal with BW Roles in Portal or a setps by steps indication?
    Thank you for your input.
    Cheers
    Gilo

    Hi Gilo,
    Below is the thread which has good discussion on the authorizations of BI and BW.
    Re: BI 7 Security
    There should be no issue in executing a BI report which runs on BW authorizations in portal, because the authorizations will be checked in the back end(BI/BW) not in portal.
    Hope this helps !!!
    Thanks,
    Ansar.

  • Authorizations for SAP-BI

    Hi Experts,
    I need access for SAP-BI , So for that Please tell me the T-CODES which i need  authorization to work on SAP-BI
    I need for Modelling, Advanced Modelling ,Reporting and Extraction
    Regards,
    Marasa.

    Hi Marasanaidu,
    Basically u need authorization for Tcodes RSA1,RSA3,RSO2,RSA5,RSA6 etc.
    You can find better information in below links:
    in first PPT 43 slide u can know how to assign authorizations:
    https://www.sdn.sap.com/irj/sdn/go/portal/prtroot/docs/library/uuid/659fa0a2-0a01-0010-b39c-8f92b19fbfea
    https://www.sdn.sap.com/irj/sdn/go/portal/prtroot/docs/library/uuid/a6c54319-0e01-0010-20a4-fb81ad32f330
    https://www.sdn.sap.com/irj/sdn/go/portal/prtroot/docs/library/uuid/ded59342-0a01-0010-da92-f6b72d98f144
    For Tcodes:
    http://wiki.sdn.sap.com/wiki/display/BI/BI%20FAQ%20-%20Important%20Transaction%20Codes%20in%20SAP%20Business%20Intelligence
    http://wiki.sdn.sap.com/wiki/display/BI/Frequently%2bused%2bTransaction%2bCodes%2bin%2bBI
    http://sap.seo-gym.com/
    http://sbpatil.wordpress.com/2008/02/29/frequently-used-transaction-code-in-sap-bi/
    Hope you get clear picture.
    Ravi
    Edited by: Ravi Naalla on Jan 12, 2010 5:20 AM

  • Authorizations in SAP HR

    Dear Experts,
    we are currently trying to restrict our authorizations per function within our business, eg. HR, IT, CONTROLLING. However, we have the following situation. More than 1 personnel area per company code (SAP Std), and nowhere else in IT0001 do we store this information for an employee. However, tracing the cost center structure, we found field functional area exists for the cost center. Has anyone used this before? Do you know which authorization object this field belongs to?
    Thanks.

    hi,
    I don't think we ca restrict from functional area in HR. Yes we also can restrict according to KOSTL. please check this once again. but it is better to maintainauthorizations according to Personal area. check if the Table P0001 is having any personal area ornot.
    Regards,
    Vasu.

  • Authorizations in SAP BW version 5.x

    I am looking for information regarding the authorizations in BW, primarily for the roles that have limitations, which only have access to certain accounts.
    Why EMVI information.

    Hi,
    Have a look at the following link :
    http://help.sap.com/saphelp_mic10/helpdata/en/69/1810a4c51144dc833353183155ec88/content.htm
    Thanks

  • Authorization in SAP BI

    Hi everyone,
    i am new to this Authorization Concept. I need to create a few Roles for End Users and Developers. Can anyone please guide me through.
    We have a Report A.
    Now ,
    1) I need to provide authorizations for creating a query, modifying an existing query , Executing and Displaying the Query result .This is for the Key User
    2) I need to Provide authorizations only to execute the Query and display the Query Result. This is for normal End User.
    3) I need to provide a Development Role to the IT Manager who is at the client place. He should be able to design the BI Development as well, Like Creating Cubes etc.
    Please provide some valuable inputs.There are no Object level authorizations. Its only Reporting Level Authorizations.

    Rajiv,
    You can create roles via T.Code PFCG.
    There you need to give 4 Authorization objects:
    S_RFC
    S_RS_AUTH
    S_RS_COMP
    S_RS_COMP1
    In Auth Objects S_RS_COMP & S_RS_COMP1 You can define following autorizations for query in activity tab:
    02  Change
    03  Display
    06  delete
    16  Execute
    22  Enter, Include, Assign
    Create different roles Normal user, Key user & BI developer.
    Provide T.code Rsa1 to developer & related autorisation in PFCG
    Regards,
    Shilpi Gupta

  • How to take report for authorization in sap hr

    I am new to this feild . I was inquisitive about taking out reports.Can i take out report based on role.The reports contains which authorization object ,PA/PSA,EG/ESG,which planned version.
    I meant to say every thing which ever appears in the authorization objects..
    Please help

    You can get this info from table AGR_1251
    If you need to report on org levels too then you will need to use agr_1252 as well

Maybe you are looking for

  • IPhone 3Gs Won't Mount In iPhoto 9 After iOS 6.0 Upgrade

    Just upgraded my iPhone 3Gs to iOS 6.0 and now I it won't mount in iPhoto 9. There is a phone icon but no name and photos don't preview for upload. Any ideas?

  • Add one Select-Options : LIKP-LGBZO into Shipment Transaction - VT02N

    Hello, Transaction - VT02N(Change Shipment) -- Now choose Select Deliveries(F6). Now one Selection-Screen will come to Select Outbound Deliveries. In this Screen I want to add one more Select-Options (LIKP-LGBZO) How can I add this  Select-Options in

  • Set OU Attribute via Script

    Is it possible to set the "ou" attribute of a computer object in AD via script?  That attribute is not listed as an option in Set-ADComputer and it doesn't auto-populate based on the OU the object is in.  How can I programatically set the attribute r

  • PSE 11 and camera Raw

    I have recently upgraded to Elements 11, but Camera raw does not seem to work. Have downloaded DNG 7.2 but that doesn't seem to make any difference. Would like to process NEF files from my Nikon D300

  • Itunes locks up when trying to import CD

    My itunes software locks up when trying to import a CD. Specifically, it will import 1 full CD then lock up when trying to access the artwork. I went into "properties" and stopped the software from looking for artwork, rebooted the machine and was ab