Authorzations

Hi,
A question about HR-authorizations: In our SAP-system it is possible for an employee to change his/her registrations in CAT2 even AFTER the superior has approved the registrations in CATS_APPR_LITE or CAT4. I want to limit this so that it is only allowed to change the registrations when they are not approved. It should of course be allowd to make changes when things are saved/releaed, but NOT after approved in CATS_APPR_LITE/CAT4. Tips?
Best regards,
Thor-Egil Ekeli

hello,
         Check the following link,
http://help.sap.com/saphelp_erp2005vp/helpdata/en/55/2bb33b90131e73e10000000a11402f/frameset.htm
hope it helps,
assign points if helpful

Similar Messages

  • When I try to transfer over songs from my iPad to my computer it says that i need to authorize my computer, but my computer is already authorzie. Why is it doing this?

    When I try to transfer over songs from my iPad to my computer it says that i need to authorize my computer, but my computer is already authorzie. It also says that some of my purchased items are not authorized for them on my computer. How do i authorize these items?

    Hi slt2014,
    Thanks for using Apple Support Communities.  I would try authorizing your computer again, even if it seems like it is authorized, by following these instructions:
    iTunes Store: About authorization and deauthorization
    http://support.apple.com/kb/ht1420
    If this does not resolve the issue, you can also try downloading your purchases directly on your computer by following this:
    Downloading past purchases from the App Store, iBookstore, and iTunes Store
    http://support.apple.com/kb/ht2519
    Cheers,
    - Ari

  • Restricted Authorzation to view the Purchase Order aganist PR

    Hi Experts
    My Client needs to Restict the PO Print Preview .
    This issue is related to authorization for viewing the PO Print Preview, details or taking Print Out.
    i.e
    "access to view the PO generated for only the PR raised by the individualuser. Kindly note that he should be authorised to view and print only the POs raised for his PRs."
    Shall be possible . Guide me please
    Regards
    Navaneethan.M.K

    Hi Mr.Pankaj Singh
    Thanks for your reply
    Every user created in the system are liable to create Purchase Requisition . in order to create ever user as a Purchasing Group . It could be too tidicious process.
    In future for every new user created shall also be considered for purchasing group . It may be lengthy process and complicated.
    Suggest for any other solution ?

  • APEX app using Oracle Text  to index pages that require authorzation

    Hi Gurus and APEX Dev team
    My team need to develop an APEX App that will index all our documents spread across various servers. Some of the documents require Single sign on access (e.g. KIX.oraclecorp.com) and some require other authorization methods (e.g. Metalink) . The Question is , Is it possible to index the pages that require authorization using Oracle text. If yes How? I have implemented the demo app which can index pages that do not require authorization.
    Thanks a million
    regards
    Bala

    Hello,
    Unless I misunderstand you, the fact that the pages require authentication doesn't really matter, it is the underlying data you want to index correct? If so then you would index them in exactly the same way that you would index any table data using Oracle Text/interMedia.
    John.
    Blog: http://jes.blogs.shellprompt.net
    Work: http://www.apex-evangelists.com
    Author of Pro Application Express: http://tinyurl.com/3gu7cd
    REWARDS: Please remember to mark helpful or correct posts on the forum, not just for my answers but for everyone!

  • Getting error when trying to add authorzation in ERM (AC 5.3_SP,)

    Hi Experts,
    I have created a role in ERM and successfully saved it, when trying to add authorization by selecting the functional area->selected the functional are(procurement dept.) -> next i clicked on the authorization data-> aded one row ->when searching for the function id from the description field, it's searching for some time and after that, getting the follwing error .
    "Service call exception; nested exception is: com.sap.engine.services.webservices.jaxrpc.exceptions.InvalidResponseCodeException: Invalid Response Code: (503) Service Unavailable. The requested URL was:"http://xiserver.ep.in:50000/VirsaCCFunction5_0Service/Config1?wsdl&style=document"
    Please do help.
    Best Reagrds,
    Gurugobinda
    Edited by: gurugobinda harichandan parida on Sep 10, 2009 6:29 PM

    Hi Alpesh and Zaher,
    Thanks a lot for all your help and support.
    After applying the note 1279722 my error got resolved, but after that when I am going to the next step to maintain PFCG it is giving me the error as: "Unhandled error; Function template PRGN_CHECK_ROLE_EXISTScould not be retrieved from CPD".
    Please do suggest.
    Regards,
    Gurugobinda

  • One of my computers crashed, how do I remove it's authorzation

    I had a computer crash and it was one of my 5 authorized computers.
    How do I remove it as an authorized computer . It remains in my 5

    Use the Deauthorize All command documented in this article.
    (65922)

  • ESS user Authorzation

    Hai Gurus
    I have assigned the standard Composite role(ZSAP_EMPLOYEE_ERP) of ESS to a user.But if he logs on to his ECC, he is able to create and view the data of the selected infotypes assigned in the role.But i want restrict his permission to view and create in the ECC level.
    Can anybody help...
    Nidhin

    Hi Maorriyan 
    Structural authorizations do use authorization object, it's build on PD objects, relations and evaluation path's.
    You can, in OOSB, using the Info Button, or with the report RHAUTH01, get an overview over which object are accessible for a specific user. In here, check if the approver (object type P and Personal number I Guess) is included in the list, if not you have two option:
    1. If you have a relation in your HR structure defining the approver relation,  you can include this in your structural profile (OOSP), you might need to define a new evaluation path for this (OAW) .
    2. You also be able to skip this check using the authorization object P_ABAP, (but please make sure if you are using this feature that do not enter the logical database in the ABAP field - by doing so you will skip all checks on the logical database) - you can find documentation on P_ABAP Here http://help.sap.com/saphelp_47x200/helpdata/en/16/b8b83b5b831f3be10000000a114084/content.htm
    Regards
    Morten Nielsen

  • Error in 'Maintain PFCG' step when adding authorzation in ERM (AC 5.3_SP7_2

    Hi Alpesh and Zaher,
    Thanks a lot for all your help and support.
    After applying the note 1279722 my error got resolved, but after that when I am going to the next step to maintain PFCG it is giving me the error as: "Unhandled error; Function template PRGN_CHECK_ROLE_EXISTScould not be retrieved from CPD".
    Please do suggest.
    Regards,
    Gurugobinda

    Hi Petra and all,
    i am able to unlock this role by going through the path: configuration->Administration->Lock Management.
    Here I unlocked the role and after taht i am able to go to the change mode now. But after that when I am navigating to add authorization by the path->functional area->added one row-> then slected procurement department from the drop down->clicked on the authorization data, it's showing me the below error:
    Unknown error occurred while performing operation (0017A4AAD5240063000004970000289400047386760D2EF5 : Found 0 operation definitions using keys: Key name:'first-body-element-ns' key value:'urn:VirsaCCFunction5_0VI'; Key name:'SoapRequestWrapper' key value:'findFunctions'; )
    where as I was able to go to the next step previously. Now I am not able to do so.
    Please do suggest.
    Regards,
    gurugobinda
    Edited by: gurugobinda harichandan parida on Sep 15, 2009 2:23 PM

  • Authorzation only to Insert / not to change in P_PERNR

    Hi,
    I have to give the Authoirzation for Employees (ESS/ECC6) to Insert new
    Temporary Address (IT0006 /subtype 2).
    I am using the object P_PERNR. When i give "W" authorization
    it allows both Insert & Change.
    How to give only for Insert and block Edit of the Address.
    Regards,
    Boobalan

    Hi,
    There is no way doing that but however you can go for Double Verification Principle (using S,E,D) values to do that.
    This might help in this regard,
    The double verification principle requires that at least two persons are involved in changing HR infotype data. This principle can be used for all infotypes except 0000 (Events), 0001 (Organizational Assignment), 0002 (Personal Data), 0003 (Payroll Status) and 0031 (Reference Personnel Number).
    The double verification principle is implemented by setting a lock indicator. If an infotype record is locked, this record is (physically) available on the database but is not taken into account in HR evaluations. (For example, if a "recurring payment/deduction" record is locked, it is not selected in HR payroll and is therefore not handled like an existing record). The lock indicator limits the validity period of records. Only records without a lock indicator are "valid" records. When the double verification principle is applied, one user stores locked data and another deactivates the lock indicator (unlocks the record). There are two ways in which two users can write a "valid" record to the database.
    Asymmetric variant
    User A is authorized to edit locked records (he/she is assigned authorization level 'E' (edit) and 'R' (read locked or unlocked) records. User A is authorized to:
    create or copy locked records. Records created (or copied) by user A are locked. Locked or unlocked records can both be used as models.
    change locked records,
    delete locked records,
    read locked or unlocked records.
    User B is authorized to:
    set (lock) or remove (unlock) the lock indicator (authorization level D),
    read infotype records (authorization level R).
    B checks the data created or changed by A and declares this data valid by unlocking it. Once the data has been unlocked, user A can no longer change it. To do so, user B must first lock the data so that user A can change it. User B must then check and unlock it, etc.
    Please note the following: User A can copy existing (and unlocked) records. This copy is initially locked. If user B unlocks this copy, the unlocked model would be deleted either completely or partially if the time constraint is 1 or 2.
    Example: You want to apply the double verification principle when entering a recurring payment (wage type nnnn [time constraint 2] in infotype 0014). User A (authorization level E) creates a record with subtype nnnn and enters a certain amount. The system sets a lock indicator for the record. This record is not taken into account in evaluations (payroll) while it is locked. Only when it is unlocked by user B does the entry of user A become active. An incorrect amount can be changed in two different ways:
    1. B locks the record, A changes it, B checks and unlocks it, or
    2. A copies the existing record and corrects the amount (in the copy); B checks the copy and unlocks it. Since the time constraint is '2', the existing unlocked record (with the incorrect amount) is deleted. The copy with the corrected amount then becomes valid.
    Symmetric variant
    User A and B have identical authorizations. Both have a read authorization and an authorization which allows them to edit locked records and unlock these (authorization level S). User A and B are both authorized to:
    create (or copy) records. These records are locked (both locked or unlocked records can be used as a model),
    change records (records which have been changed are locked even if they were previously unlocked),
    lock records,
    unlock records if the last person to change the record is not identical with the current user.
    Here, user A and B check each other's work. When A creates or changes a record, it is locked. B checks the record and unlocks it (A can also perform B's work and vice versa). It takes two users (with identical authorizations) to create or change a valid (unlocked) record. Users with authorization level S cannot delete records.
    Example: You want to apply the double verification principle (symmetric variant) when entering a recurring payment/deduction. User A enters the data. The record is locked. User B unlocks it. If data needs to be changed after the record has been unlocked, both A or B can do this. The data is changed and the record locked. The other user can now unlock this record. Alternatively, A or B could create a 'locked' copy. In this case, the model remains an unlocked record. If the copy is unlocked, the copy overwrites the model (time constraint 2).
    The following applies to the symmetric variant of the double verification principle.
    The person who last changed an infotype record must not have changed it explicitly: Even if the validity period of a particular record changes when user A creates or deletes a different record (due to time constraint 1 or 2), A is nonetheless entered as the person who changed the record. For example, both A and B have an 'S' authorization. A changes an existing infotype record (time constraint 2) with a validity period from 01/01/96 - 12/31/99. Then B creates the same type of record for 07/01/96 - 12/31/99. The result is two locked records with validity periods from 01/01/96 - 06/30/96 (1) and 07/01/96 - 12/31/99 (2); in both cases, B is entered as the last person who changed the record. However, B did not explicitly change the first record; he/she merely delimited it by creating the second record. As a result, A can unlock the first record.
    Hope this helps
    Manohar

  • Check free goods in inqury (Failed)

    Hi Guru:
    It seemed that I failed to check the free goods via transaction va11 when creating the inquiry,I have no authorzation to use va01 since I am not CSR person,I just wanne to check the free goods which I had created  before to see if it works no matter the exclusive or inclusive one,is there another method to check the accuracy of the free goods? Any solution? Thanks.

    Hi,
    Generally free goods activated in sales order only not in inquiry not in quotation also.
    So you have to go to VA01 only to check your free goods determination.
    It depend upon the sales document category.
    In inquiry you will find A and in sales order C which makes all the difference.
    Talk your administrator for the authority over VA01.
    Regards
    Raj.

  • HT1420 I have two email accounts associated with one iTunes account

    I have two email accounts associated with one iTunes account with two passwords,  I guess it happened when i changed my internet service provider. 

    Could be, but i do have an old email account, whis is not used, changed carrriers.  I have noticed that some songs have a cloud with a line through it.  I try to play it and a dialog box from Itunes pops up: "THIS COMPUTER IS NOT AUTHORIZED TO PLAY "THE THINGS WE DO FOR LOVE(SOUND TRACK VERSION, would you like to authorize it?  THe apple ID haxe my old  email address " and an empty block asking for my password.  Well all i know is when you start trying to authorze with an old ID or something of that nature, the account is block and you need to do a new setup again.  And who knows what other problems that will cause,
    I just want the songs (i think there are several songs) assosiated with this old account to move to my new account.
    Any ideas?
    Tom
    <Email Edited by Host>

  • How to configure ACS 5.2 for policy condition on TACACS+ Service

    In https://supportforums.cisco.com/message/3953175#3953175 thread, I was able to get the ACS 5.2 work with SRX for both SSH CLI and J-Web TACACS+ accounts. However, I found the behavior is different on our production environment. I found our ACS 5.2 was configured authorization rule with condition "TACACS+ Service" = "junos-exec". I don't know how to configure this on my ACS 5.2 Please guide me how to configure this.
    I found there was NO TACACS+ "Authorization Request" when access via J-Web in our production SRX and ACS. However, there were TACACS+ "Authorzation Request" when access via J-Web in our production SRX and ACS. The difference between my lab ACS and production ACS is the authorization rule condition. In my condition, I configure with all "SRX" Device Type. but in our production ACS 5.2, it was configure to TACACS+ Service=junos-exec. so I like to test it in our lab to find out the difference. Thanks.

    I would suggest you to go through the below two link.
    http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.2/migration/guide/Migration_Configure.html
    http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.2/user/guide/common_scenarios.html

  • How do I copy a song from my itunes library to my wifes phone?

    How do I copy a song from my itunes library to my wifes phone? We share one pc and have seperate itunes accounts.  Her phone is authorzed on the computer as well as mine.  How can i get a song from my library to her phone/

    Drag the songs from the iTunes library or iTunes Music folder to the device in the Finder. If it doesn't show up there or that doesn't work, check the device's documentation.
    (109837)

  • How do I resolve this Adobe error on E_LIC_ALREADY_FULFILLED_BY_ANOTHER_USER on MAC 10.9.5

    I've already tried de-authorzing, re-authorzing, tried ADE 4.0 and 2.0.  Nothing works.  I need someone from Adobe to resolve this license issue.
    Thanks

    Same problem here.  Individually loaded my ebooks to my Adobe Editions.  The last 4 books won't download. Says:  E-lic_already_fulfilled_by_another_user.

  • Error during Database instance installation of NW04s Portal installation

    Hello All,
         This is our system environment:
       Portal - NW04s SR1 (SCS instance on one host) -- finished successfully
       Database - MS SQL Server 2005 on a separate host
    We are doing a domain installation. The database was installed successfully, but when trying to install the database instance during the NW04s installation, I am getting the following errors:
    <b>ERROR      2007-01-03 11:30:10 [syxxsyshlp.cpp:78]
               syslib::printOSError(const iastring &, int, DWORD, const iastring &, CMessage::eLogMessage) FSL-00001  System call failed. Error 5 (Access is denied.
    ) in execution of system call 'CopyFile' with parameter (
    DCASAPHR05\sapmnt\EPD\SYS\profile\DEFAULT.PFL,
    DCASAPHR05\sapmnt\EPD\SYS\profile\DEFAULT.1.PFL, FALSE), line (478) in file (synxcfile.cpp).
    ERROR      2007-01-03 11:30:10 [syxxcnode.cpp:402]
               CSyNodeImpl::move(const CSyPath &
    DCASAPHR05/sapmnt/EPD/SYS/profile/DEFAULT.1.PFL, ISyNode::CopyMoveMode_t 0x3) FSL-02039  Unable to move or rename node
    DCASAPHR05/sapmnt/EPD/SYS/profile/DEFAULT.PFL with type file/directory to
    DCASAPHR05/sapmnt/EPD/SYS/profile/DEFAULT.1.PFL: Overlapped I/O operation is in progress.
    ERROR      2007-01-03 11:30:10
               CJSlibModule::writeError_impl() MUT-03025  Caught ESyException in Modulecall: ESAPinstException: error text undefined.
    ERROR      2007-01-03 11:30:10 [iaxxgenimp.cpp:736]
               showDialog() FCO-00011  The step createDefaultProfile with step key |NW_Java_DB|ind|ind|ind|ind|0|0|NW_System|ind|ind|ind|ind|6|0|createDefaultProfile was executed with status ERROR .</b>
    Could anybody please help me through this process?
    Thanks much in advance,
    Sunitha

    Hi,
    I would try adding epdadm and SAPServiceEPD accounts to Administrators group and give Administrators full access to sapmnt shared area. Also double check SAP_EPD_GlobalAdmin domain admin authority and SAP_LocalAdmin and SAP_EPD_LocalAdmin accounts.
    Open
    DCASAPHR05\sapmnt\EPD\SYS\profile folder using explorer and created file and see if there is any authorzation issues with domail\sapinst account.
    good luck
    Kondala Rao

Maybe you are looking for

  • Purpose of getContentPane()

    what is the purpose of method: getContentPane() like: JButton btn1=new JButton(); JPanel panel=new JPanel(); add(btn1); getContentPane().add(panel);

  • How do i Fresh intall?

    How do i intall a fresh copy os os X on my macbook im used to the install routine on windows xp, does it format on its own? is there a guide?

  • Inbound MQ with extended character sets

    Hi We are trying to send to PI data containing Swedish characters in both xml and non xml payloads. The message is placed on an MQ queue (version 6.0.2.3) with a JMS header that has a ccsid of 1208 specified. The PI adapter is specified as JMS | Webs

  • Is there a way to make your own Invisible Shield?

    I thought I remember reading that you could by the same kind of plastic coating at art or hardware stores... and make your own, which would be cheaper. Does anyone remember this? Or am I imagining it... thanks!

  • Problem upgrading an iPhone 4 CDMA (Verizon) to ios 5. Can anyone help?

    Trying to upgrade an iPhone 4 CDMA (Verizon) to ios 5 and am getting and error saying - "The iPhone could not be restored.  This device isn't eligible for the requested build."  It is currently running ios 4.2.10. It completes a backup, does the extr