BI authorization on hierarchy- 2 different hierarchies on InfoProvider

Hello,
Im working with the new Authorization concept (Tcode rsecadmin).
Trying to create an Authorization for 2 different InfoObjects (with hierarchies) , on the same InfoCube.
I've created 3 Authorization object in Tcode rsecadmin:
    1. The first hierarchy InfoObject - 0orgunit -(choosing node in the hierarchy to start from)
    2. The second hierarchy InfoObject - zmarach -(choosing node in the hierarchy to start from)
    3. Authorization for all other InfoObjects exist in the Infocube.
I've created a role with Authorization object S_RS_AUTH which contained all the above.
For example - the InfoCube contains:
record 1 - 0orgunit :under the node selected , zmarach :NOT under the node selected
record 2 - 0orgunit :NOT under the node selected , zmarach :under the node selected 
The Query should return both records ! instead it returning "no authorization" msg.
When I tried the Query with only one hierarchy with authorization, it worked, the problem is when both authorizations are active. (on both hierarchies).
Meaning, the operation between those 2 authorization is "AND" , not "OR".
I need the user to see all the records he is authorized to see by the hierarchy, no matter if the InfoObject 0orgunit or zmarach is authorized to him.
Does anyone have an Idea how can i solve this ?

Hello,
Im working with the new Authorization concept (Tcode rsecadmin).
Trying to create an Authorization for 2 different InfoObjects (with hierarchies) , on the same InfoCube.
I've created 3 Authorization object in Tcode rsecadmin:
    1. The first hierarchy InfoObject - 0orgunit -(choosing node in the hierarchy to start from)
    2. The second hierarchy InfoObject - zmarach -(choosing node in the hierarchy to start from)
    3. Authorization for all other InfoObjects exist in the Infocube.
I've created a role with Authorization object S_RS_AUTH which contained all the above.
For example - the InfoCube contains:
record 1 - 0orgunit :under the node selected , zmarach :NOT under the node selected
record 2 - 0orgunit :NOT under the node selected , zmarach :under the node selected 
The Query should return both records ! instead it returning "no authorization" msg.
When I tried the Query with only one hierarchy with authorization, it worked, the problem is when both authorizations are active. (on both hierarchies).
Meaning, the operation between those 2 authorization is "AND" , not "OR".
I need the user to see all the records he is authorized to see by the hierarchy, no matter if the InfoObject 0orgunit or zmarach is authorized to him.
Does anyone have an Idea how can i solve this ?

Similar Messages

  • How to sort two different hierarchies in one dimension

    Does anyone know of a way to sort two different hierarchies in one dimension and still make drilling work correctly? We have two hierarchies in our item dimension; one called category and the other origin. Simplified, it looks like this:
    CATEGORY
    Hardware (100)
    ..PCs (100.100)
    ....PC 1
    ....PC 2
    ....PC 3
    ..Monitors (100.200)
    ....Monitor 1
    ....Monitor 2
    ....Monitor 3
    Software (200)
    ..Big (200.100)
    ....ERP package
    ....CRM package
    ..Small (200.200)
    ....Solitaire
    ....Mine Sweeper
    ORIGIN
    Vendor A (10)
    ..Site A1 (10.10)
    ....ERP package
    ..Site A2 (10.20)
    ....PC 1
    ....Monitor 3
    Vendor B (20)
    ..Site B1 (20.10)
    ....PC 2
    ....PC 3
    ....Monitor 1
    ....Monitor 2
    ....Solitaire
    ....Mine Sweeper
    ..Site B2 (20.20)
    ....CRM package
    We have numeric codes at each level above item which I represents the sort order (the number in parentheses at each level), and the items themselves should be sorted according to item number. I have implemented this (level code/item number) as an attribute in AWM making this the default sort order. However, as item is the lowest level in each hierarchy, I have only been able to list the items under the correct level in one hierarchy. As soon as I drill using the other hierarchy, the levels above item are sorted correctly, but the items appear at very odd places...
    The AWM documentation states that if default order is not selected on any attribute, hierarchies are sorted in the order they are created. Is there a way to control this order?
    Any input will be greatly appreciated!

    Hi,
    thank you for your answer. Yes, now I also find the class CL_SALV_WD_MULTI_CELL_EDITOR which could be used to set different UIE in one cell. But it is quite limited, just the following UIE could be used
    - LinkToAction 
    - LinkToURL    
    - FileDownload 
    - Button       
    - ToggleButton 
    best regards,
    Wenwen

  • How to select same descendant members from different hierarchies?

    Hi All, 
    please help, how it is possible to select same values for only the same hierarchy member names from different hierarchies?
    Example:
    L1          #L1          L2          #L2          Value
    A          #A          a1          #a1          7
    A          #A          a1          #a2          2
    A          #A          a2          #a2          0
    A          #A          a2          #a1          6
    A          #A          a3          #a3          1
    A          #A          a3          #a3          9
    A          #A          a3          #a1          2
    A          #A          a4          #a2          2
    A          #C          a4          #c1          2
    B          #B          b1          #b1          5
    B          #B          b1          #b2          8
    B          #B          b2          #b2          2
    B          #B          b2          #b1          6
    B          #C          b3          #c1          4
    Query1:
    Select sum(value)
    where L1 = #L1
    Result:
    L1          #L1          Value
    A          #A          29
    A          #A          21
    Query2:
    Select sum(value)
    where L2 = #L2
    Result:
    L2          #L2          Value
    a1          #a1          7
    a2          #a2          0
    a3          #a3          9
    b1          #b1          5
    b2          #b2          2
    Names of level members with or without hashmark are identical (A=#A, a1=#a1 etc.).

    [Hierarchy].[L1]*[Hierarchy].[#L1] returns all possible combination of the two hierarchies.
    Here I would filter those cases only, where [Hierarchy].[L1].MEMBER
    = [Hierarchy].[#L1].MEMBER, in aggregated format (Query1 result).

  • How to use two different hierarchies

    I have 1 business areas product.and i have create trw different hierarchies
    1.Departments->Class->Sub class->Item
    2.Dipertment->Item
    Now I have created two reports on that single business area. I wants Report1 have to follow the hierarchies 1 and Report2 have to follow the hierarchies 2.
    Now where can i define that?
    Please give me some idea about that

    Hi
    If you have two hierarchies then you cannot force one report to use one and another to use the second. You just need to teach the users how to pick the relevant hierarchy.
    When a user clicks on the hierarchy link alongside an item, say the Department, the user should see both hierarchies. If you name the hierarchied items appropriately you will make it easier too.
    Best wishes
    Michael

  • BPC- 3 different hierarchies

    Hi
    We are now in high level BP and my question is how to set 3 different hierarchies on the same building block=Company (Legal, Managerial and Geographical hierarchies)
    The point is to manage the inter company elimination in appropiate and efficiently way in all hierarchies
    Thanks,
    Shmulik

    Hi Shmuel,
    That should not be a problem. In the dimension you can set up number of hierarchies and run the IC elimination on any of these. In this case you can not run full investments/equity elimination but that can be managed with consolidation-type application.
    For simple eliminations with static strructures dimension-based hierarchy is just fine - you just need to configure US Elimination business rules or ELIMINATE_ORG script logic.
    Hope this helps,
    Madis

  • One hierarchy in different versions?

    Hi all,
    SAP SEM-BCS question:
    Can I use one consolidation group hierarchy in different consolidation versions? Currently I use separate hierarchy version (although the consolidation group hierarchy is the same) for all my consolidation versions. If yes, how can I do that?
    Example:
    Hierarchy Version 100 -> Consolidation Version 100
    Hierarchy Version 205 -> Consolidation Version 205
    Goal:
    Hierarchy Version 100 -> Consolidation Version 100, 205, 206... = always when consolidation group hierarchy is the same
    Hierarchy Version 300 -> Consolidation Version 300, 301, 302... = new hierarchy version only when consolidation group structure has changed
    Anyone knows?
    Best regards,
    Tom

    Ok, so say if I understand it right,
    I go to Master Data > Versions > Special Versions > Assign to Combinations,
    then I choose my Consolidation Version (my combination), which I want to customize
    next on the right side of the window I choose from Hierarchy Structure a Consolidation Group and with right mouse-click on the "Inherit" picture I choose Explicitly Enter Special Version and in Special Version column I choose my preferred hierarchy version of Consolidation Group hierarchy.
    Am I right?
    Or if I go to Rules in Special Versions menu, I can choose Consolidation Group, 2x click and on the right side of the window I can assign the default Special Version to any new Consolidation Versions (combinations).
    Am I right?
    Thanks for the answer,
    Tom

  • Authorization and hierarchy management

    Hi,
    I would like to authorize a user to maintain a hierarchy with RSH1 but I would like to allow him to only access to a part (noed) of the hierarchy.
    I though about 2 possible solutions but I don’t now if it’s possible:
    - I can use the Authorization Object S_RS_HIER. Is it possible to allow access only to a noed (and subtree data) of a hierarchy with this Authorization Object ?
    - I though about the “authorization with hierarchy” (and AO TCTAUTHH ) of transaction RSSM but I think that this functionality is only useful to control/filter data based on hierarchy from a particular cube but that it’s not done to control acces to the hierarchy itselve.
    Do you think I am true?
    Thank you for your help.
    Best regards
    J. Sorel

    Nobody can help me please?
    Many thanks
    J sorel

  • Cockpit - authorizations with hierarchy

    Hello,
    I have a problem in a cockpit, and it is relating to authorizations with hierarchy.
    I have an object of authorization already defined with certain criteria (bucket and node of the jerarquiaa that only I want that agrege deposit a user) this object in a rol, unitedly with a profile of visualizing the cockpit. When I enter with the user to visualize the cockpit I enter to all the nodes, my question is: Why not respecting my authorization for the node of the hierarchy that alone I want to show?
    thank you.
    Mike

    listo ya quedo

  • IHC Cash concentration Account Hierarchy with different currencies - F9H1

    Hello Experts,
    Can someone please help me find out if it In Tcode: F9H1/F9H2, it is possible to create an account hierarchy with sub account in different currency than the Root account?
    I am getting the following error when I try to create an account hierarchy with different currencies in root account(USD account) and subaccount(GBP account)
    "Account XXXXGBPYYYY / GBP cannot be inserted; Currency not possible"
    Is this a system limitation or are we missing some configuration?
    Please advice

    Hi Anya,
    In the new version of IHC, which is available from EA-FINSERV 500 onwards, the cash concentration process generates 2 payment orders -
    1. BCA payment order ( or the OLD IHC payment order - can be viewed via F9I3)
    2. IHC payment order (or the payment order created in the new version - can be viewed via IHC0)
    This happens only when you configure the module IHC_BCA_EXTERNAL_PAYMENT in the BTE 10310 for application IHC.
    This would then call the new version of IHC and post a payment order which you can view from tcode IHC0.
    If instead of module IHC_BCA_EXTERNAL_PAYMENT, another module PAYMENT_EXTERN_IHC is configured in the BTE 10310 then it would look for an entry in the table TBKKIHB4 to create a PAYRQ (treated as external payment). And, on finding the table empty, it throws the error message as mentioned by you.
    Hope this helps!
    Best regards,
    Sidhartha

  • How to do authorizations on unassigned nodes for hierarchies

    Hi,
    Is there a white paper from SAP that shows how to do authorizations for unassigned nodes for the hierarchies? Or has anyone completed this challenge and would be willing to share their approach and strategy?
    Thanks
    Will

    Hi Ashwin,
    The characteristics are 0COSTCENTER and ZDEPT. The Hierarchy structure should be
    -Test Hierarchy
    --Cost center 1
    ---Dept1
    ---Dept2
    ---Dept3
    --Cost center 2
    ---Dept4
    ---Dept5
    ---Dept6
    --Cost center 3
    ---Dept7
    ---Dept8
    ---Dept9
    Etc.
    We have transaction data where a certain Cost center doesn't have the department and when displaying the hierarchy there would be some unassigned nodes for the BW report.
    What would happen if the following hierarchy is in place and I am trying to do authorizations for the 0COSTCENTER and ZDEPT:
    -Test Hierarchy
    --Cost center 1
    ---Dept1
    ---Dept2
    ---Dept3
    --Cost center 2
    ---Dept4
    ---Dept5
    ---Dept6
    --Cost center 3
    Where cost center 3 has no department for it?
    Thanks and regards
    Will

  • Authorization log / Hierarchy node in SQL format

    Hi!
    I execute rsudo on a restricted user and the authorization log tells me that this fails because the user is not authorized for "Content(in SQL format): Node 5 8 0 31 E"
    Now how do I translate this sql format into something I can read? I've looked through the hierachy tables for the relevant characteristic but I can only identify 31 as the hierarchy sid and E as the version.

    Vice -
    We had to do basically the same thing for 0CRM_TR hierarchy, but our steps were a little different since we are on BI 7.0 - 2004S.
    We also had to limit the users visibility to data from certain nodes and below on the hierarchy. 
    1st, we made the 0CRM_TR object auth releveant. 
    2nd, we created an analysis authorization for the object via transaction code RSECADMIN.  In the transaction we had to specify the Hierarchy variable name that would be used in Queries.  We then selected the node (GUID) where we wanted the authorizaion to take place.  We set the Type Auth to 1(subtree and below) and Hierarchy Validity Area as 2(Name Identical).  We set it to 2 since the Hierarchy would always be loaded in the same name.

  • Linking two different Hierarchies

    Hi,
       i have got two external hierarchies for 0Material. i want to link one of the hierarchy to the other at level 4 as both of them are same after level 3. is there any possible way two link both of them.
    Thank you,
    Ravi.

    Hello Ravi,
    no, we can not link two or more external hirarchies.
    Reg.
    michael

  • Hierarchy across different dimension tables?

    Hello
    I have a situation here..
    I have Dim1 and Dim2. They are both M to M relationship to each other. Therefore, I introduced a mapping table called Mapping_F in the middle. So the relationship looks like this:
    Dim1 ---> Mapping_F------> Dim2.. Dim1 and Dim2 don't have any common keys to join directly...
    Now in reality, 1 dim1 can have many dim2, 1 dim2 can also have many dim1 attribute...
    We have a requirement, which is to create a hierarchy drill-down on report featuring Dim1 and other measures.. User can click on Dim1 and it will display the measures for all of the dim2 stuffs under this dim1 attribute value..
    This would require creating a hierarchy that goes from Dim1 to dim2, however, based on the existing model, how can this be implemented?
    Any suggestion will be greatly appreciated..
    Thanks

    You can try creating 2 different reports and navigate from one to another using navigate or Go URL

  • BW Authorization by hierarchy for 1 object/cube/query, rest unrestricted

    Hi all,
    I've just created my authorization object in RSECADMIN to maintain authorizations by 0PROFIT_CTR Hierarchy.
    This is based on a single characteristic, cube, and by technical node name.
    I've tested it and it seems to work fine, however, I would like the same users to have unrestricted access to all other cubes that use  0PROFIT_CTR Hierarchy, but how would I do that?
    I created a seperate role in where I've maintained object S_RS_AUTH for this particular authorization only.
    Normally S_RS_AUTH would give full access to all (*) values, but now it's restricted.
    Still I want the users to display the full hierarchy for any other cubes/queries. Creating a seperate role to give all access obviously doesn't work, as that would bypass my earlier authorization settings.
    Please help, any questions let me know.
    Thanks
    M

    Hi,
    this certainly is an option, but since we have dozens of cubes which use 0PROFIT_CTR as an object.
    It woulld be quite a time consuming solution to set up; besides, the maintenance not just by each new cube but also by role would be pretty significant I believe.
    There should be a more direct and simpler way to set this up, shouldn't there?
    I've tried to create a copy of the hierarchy that is restricted by node for each profit center group, leaving the original hierachy unrestricted for any cube and user.
    Somehow this doesn't work either, probably because I have given (*) unrestricted access in the role, besides the authorization object I specifically created for the restricted access cube/hierarchy, so one overwrites the other!
    Any other suggestions?
    Thanks!
    M.

  • CAT2 Org Unit Structural Authorizations - Employees moving to different Org

    Hello, everyone -
    We currently use structural authorizations to restrict time keepers to only maintain time entries for employees in their org units. If an employee moves to an org unit maintained by a different timekeeper, we want to continue to allow the previous time keeper to maintain entries for the time the employee was in their org.
    Example: pernr 1 starts out in org unit X. Org Unit X time entries are maintained by time keeper A. Effective 5/1/2014, pernr 1 moves to org unit Y, whose time entries are maintained by timekeeper B. The standard maintenance data entry profile allows the user to go back 6 weeks. On 5/2/2014, time keeper A tries to enter overtime worked by pernr 1 for his org unit on 4/30/2014. He receives the error "Not authorized to maintain data for personnel number &2 using profile &1".
    How do we allow a timekeeper to make entries for any employee who was in any of their org units, even if they're no longer there?
    Thanks in advance, and I'll definitely reward points for any helpful answers.
    - Steve

    Hi, Rohit -
    The actual scenario is that we are set up to move all withdrawn personnel numbers to a pooled "separated" position in a separate org unit. This frees their previous position to be filled by a new hire. It also means that a LOT of personnel numbers are in this org unit, which the time keeper should not have access to.
    D.  -
    We're using a custom function module entered in T77PR to retrieve the organization units that the time keepers should access.  Here are the entries in T77PR:
    (The "Maint."/Processing Type column is checked for all 3 rows.)
    Z_HRLY_TMKPR 1 01 O          O_S_P 12 3   ZBC_GET_TKEEPER_ORGS_BY_USER
    Z_HRLY_TMKPR 2 01 S          O_S_P 12 3   ZBC_GET_TKEEPER_ORGS_BY_USER
    Z_HRLY_TMKPR 3 01 P          O_S_P 12 3   ZBC_GET_TKEEPER_ORGS_BY_USER
    The function module uses a custom evaluation path ZHT that looks like this:
    15 * B 008 Holder * S
    20 S B ZHT Hourly Timekeeper * O
    30 US A 208 Is identical to * P
    I'm not sure what you'd like to see related to the profile... Is there a way to configure the CAT2 logic to allow a user to maintain a personnel number who is in the org for at least part of the time that the employee was in an organization that the user is authorized to maintain?
    Thanks again,
    - Steve

Maybe you are looking for

  • How do I delete a city in the weather app?

    How do I delete a city in the weather app?

  • Order confirmation output error.

    Hi All, There is an output type which prints the Order confirmation. A new functionality was added to this. If a material has warranty it prints at the end. This can happen for more than one material and this text is taken from SO10. Whenever a print

  • Take Screen Snapshot

    Hello, Is there an API that can take a snapshot/printscreen of the current screen and save it as an image file on the local PC. Basically, I want to create a program and on executing it, capture a snapshot of the current SAP screen and save this snap

  • Outlook 2013 cannot open hyperlinks or attachments

    I have Windows 7 64bit and Office 2013 32bit. For several weeks I have been unable to open attached files, although I could preview attached image files. Since the latest update (Jan 2014) I am unable to open hyperlinks either. Also since the latest

  • IBM T23 and Apple Cinema Displays??

    I have just purchased an Apple 23" Cinema Display for my 4 computers. I have a DVI switcher as well. I have 2 Desktop PCs, a PowerMac G5 and a T23 laptop (for work). My cinema display works great on the 3 other computers because they all support DVI.