Blocking User from accessing wrong customer code in VA01

Hi SAP SD GURU,
my finance user uses rebate recipent in sales order creation for rebate settlement.
my operation user uses one-time customer code in sales order for sales.
Both type of customer codes can be used in sales order creation under different order type.
The problem arises when operation staff uses rebate recipent code to create sales order and then billing.
My finance User want this to stop.
How can I block the operation User from continuing the sales entry when they select the rebate recipent in a sales order entry?
Is there any available setting in the customer master that allow me to do so?
Is there any setting in the SPRO that can control this?

Hi Colin,
Well you need to control these through the user profile & roles
you can do this in SU01 which a Basis person can help you out with .....
now as said User X wants authorisation to va01  ( Rebate)
                  User Y wants Authorisation to va01 ( One time)
since here we are not restricting any user for VA01 auth , the Basis person can define the role only till the transaction level not beyond that in standard SAP transaction and here you want to restrict user to not use different customer code
as per my knowledge i dont think that is possible but still have a check with the Basis team
Hope this helps
Cheers

Similar Messages

  • Block users from dba access

    Hi all,
    I am currently using a oracle 10.2.0.1.0. when i create user i want to block user from dba access how can i do that

    connect test/test as sysdba;The problem isn't here with user/password, see below :
    SQL> conn userdoesntexist/fake as sysdba
    Connected.
    SQL> show user
    USER is "SYS"
    SQL> conn / as sysdba
    Connected.
    SQL> show user
    USER is "SYS"
    SQL>As it already said above, the problem is with the usage of password file on the server connection. Try to disable this one.
    Nicolas.

  • Block users from downloading from internet

    I'm curious as to what everyone is using to block users from downloading certain file types (.exe, msi, zip, bat, etc) from the internet? We had websense, now barracuda for a web filter but have major issues with filtering downloads from the internet. The main issues is filtering SSL sites.

    Hello,
    The WSA has a feature called Object Filtering which allows admin's to configure access policy parameters to block certain file types from being downloaded through the WSA. To apply the same settings to HTTPS requests the WSA would need to decrypt the request.
    I Hope this helps.
    Best Regards,
    Michael Hautekeete
    Customer Support Engineer
    Cisco Content Security - Web Security Appliance
    http://www.cisco.com/en/US/products/ps11169/serv_group_home.html
    https://supportforums.cisco.com/community/netpro/security/web
    https://supportforums.cisco.com/community/feeds?community=2091

  • I need to prevent unauthorized users from accessing the application pages

    Hi^^,
    I have created an application in jsp and servlets. It has several pages like manager, supervisor accountant. I need to prevent unauthorised users from accessing these pages. In other words I need to implement a filter. Anyone who types a url other than that of the login page needs to be blocked. However I am not able to conceptualize the code that is going to be inside the doFilter() method. Please help
    Sincerely,
    Prashant

    Hi^^,
    I admit that there were some mistakes in the previous posting. I have corrected the mistakes and now there is going to be no compile time error. However when i put in the login id and the password it is redirecting me to the login page. I think that the front end jsp is directing the control to the controller servlet. But as "YOU" have pointed out in your previous post,
    "by default requestDispatcher.forward(...) does not pass through the filter change. If the user requests the login page from their browser however, then they will still get the error message, which may not be appropriate."
    I feel we need to somehow make the code pass through the requestDispatcher.forward(...) method of the servlet.
    I am again posting the corrected code.
    package com;
    import java.io.*;
    import javax.servlet.*;
    import javax.servlet.http.*;
    public class SecurityFilter implements Filter
      public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain) throws   ServletException, IOException
      HttpServletRequest req = (HttpServletRequest)request;
      HttpServletResponse res = (HttpServletResponse)response;
      String X = req.getRequestURI();
      if(X.equals(http://localhost:8080/MyProject/LoginPage.jsp))
         //writing code for passing through the filter
         final class MyGenericFilter implements javax.servlet.Filter
          public FilterConfig filterConfig;
          public void doFilter( final ServletRequest request, final ServletResponse response, FilterChain chain) throws java.io.IOExeption, javax.servlet.ServletException
          chain.doFilter(request,response);
          public void init(final FilterConfig filterConfig)
          this.filterConfig = filterConfig;
          public void destroy()
    else
       HttpSession session = req.getSession();
       String username = (String)session.getAttribute("username");
       if(null==username)
         request.setAttribute("Error","Session has ended. Please login");
         RequestDispatcher rd = request.getRequestDispatcher("Login.jsp");
         rd.forward(request,response);
         chain.doFilter(request,response);
        else
         RequestDispatcher rd = request.getRequestDispatcher("X");
         rd.forward(request,response);
    public void init(final FilterConfig filterConfig)throws ServletException
          public void destroy()
      Edited by: pksingh79 on Aug 12, 2008 5:23 AM

  • What role needs to be assigned to the user to access existing custom OData services?

    Hi all,
    What role needs to be assigned to the user to access existing custom OData services?
    With SAP ALL its working. But cannot assign that to all users. Whats the specific role for this?
    I tried with /IWFND/RT_GW_USER. But it says the role does not exist.
    Thank you,
    Achu

    Hi,
    As usual you need to build a role by yourself based on your requirements. In case of Odata services there are two different TADIR services that needs to be added. One corresponds to authorization to execute logic on backend server and the other one to access service on front end server. You can get specific services by tracing one call using ST01. For Fiori apps from SAP you get role templates. You can use them for inspiration.
    Cheers

  • Blocking users from syncing calendars and contacts from itunes

    Is there a way to block users from syncing the corporate GAL and their Outlook calendars from their company computer?

    Thanks for the answer Simon. That seems simple enough but there are some things which aren't clear.
    If I create accounts on the server for the users independently (ie not ownership of the home folder) they're going to have different UID's. Surely this means that even with the same account name and password, they're going to be treated as unique users. Does that not affect who has write access? I don't know how the Calendar and Contact servers work so this may be irrelevant.
    How do you "have the server host their calendar and contact details"? Copying the files for the existing local users to the new users on the server will leave them with invalid permissions.
    I have read that using the Calendar and Contact components of Server.app is not a supported way of syncing across machines and that they're intended to be used for shared information rather than syncing. But maybe there is no way to avoid an "unsupported method" without moving the home folder. Is this a method you're using?
    I'll do a bit of testing with this but would also be grateful for any additional hints.

  • How to Block user from Sending IM or Hide Presence of there user who is not in his department

    Hi All,
    How to Block user from Sending IM or Hide Presence of there user who is not in his department.
    Thank you

    Hi Jp,
    Method 1:
    You can use the Enhanced Privacy Mode in Lync 2013
    <section class="ocpSection">
    Enable Privacy Mode
    By default, everyone except Blocked Contacts can see your presence status. To modify the privacy settings, you can do the following:
    In the Lync main window, click the Options button.
    In the Lync - Options dialog box, click Status, and then do one of the following:
    Click I want everyone to be able to see my presence regardless of system settings (override default settings).
    Click I want the system administrator to decide - currently everyone can see my presence but this could change in the future.
    </section>
    About Enhanced Privacy Mode
    If your organization has enabled Enhanced Privacy Mode in Lync, you can choose whether to limit visibility of your presence information to only those people you’ve added to your Contacts list. You do that by selecting one of the following on the
    Options->Status window:
    I want everyone to be able to see my presence
    I only want people in my Contacts list to see my presence
    Method 2:
    Using Privacy Relationship, you can block a particular user by adding him to blocked contacts
    Anil Kumar (MCITP)
    Note: Posts are provided “AS IS” without warranty of any kind, either expressed or implied, including but not limited to the implied warranties of merchantability and/or fitness for a particular purpose.

  • Block user from copying media files

    how to block user from saving certain files like Avi,mP3 , ... to their computers by GPO ?
    it is possible?

    I do not think that you can go that by GPOs. However, this is feasible on File servers: http://www.petri.co.il/forums/showthread.php?t=45225
    You might think about creating scheduled tasks that will run periodically and remove files with these extensions from the user profiles (...).
    For GPO questions, please consider asking them here: http://social.technet.microsoft.com/Forums/windowsserver/en-US/home?forum=winserverGP&filter=alltypes&sort=lastpostdesc
    This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.
    Get Active Directory User Last Logon
    Create an Active Directory test domain similar to the production one
    Management of test accounts in an Active Directory production domain - Part I
    Management of test accounts in an Active Directory production domain - Part II
    Management of test accounts in an Active Directory production domain - Part III
    Reset Active Directory user password

  • How can l block users from backing dating transactions

    1. How can l block users from back dating transactions in SAP B1. It was discovered that, in production dept there is this allowance given to them to keep producing for the previous month in the new month; this according to line staff is to enable them meet up their monthly target, after a meeting with the management it was resolved to block that right of backdation of enteries. how can l  correct  this.
    2. How can l change the decimal places backward in the general settings of administration of SAP B1( iniatially it was set to be 5 under Quantity now want to correct it to 3 how do l go about this).
    Joel

    Joel,
    By forum rule, one question for one thread.  I will answer you the second:  If you are using 2007 version, the option to decrease decimal place is not available.  Check this thread to know more:
    Re: REDUCE NUMBER OF DECIMAL PLACES
    Also note: this forum is just for B1 system administration.  Please post it on the main forum.
    Thanks,
    Gordon

  • How to restrict the user from accessing other screens before submittingdata

    Hi All,
      I have some screens developed in Webdynpro ABAP and all these have been linked to Portal as pages. In Portal If i click on the link in detailed navigation i can see the corresponding screen on the right side. Now in one screen i have to input some data and submit the data, Now my problem is if i enter some data and before submitting the data if i click on any other link in the detailed navigation, that corresponding screen is opening and all the data of the previous screen is lost.
    Can any one suggest me, how can i restrict the user from accessing other screens before submitting the data of that screen from portal perspective.

    Hi Prasanna,
    The pages can be restricted from the user access by using the ACL permission or you can restrict the page by making invisible in navigation area which you do not want to show to the user . Open the page properties and select navigation category in the drop down and select the Invisible in navigation area property to yes.By default this property is No.Change the property for all pcd pages which want to hide from user access.
    Hope this helps you...
    Regards,
    Rudradev Devulapalli
    Reward the points if helpful....

  • My Mac is blocking me from accessing one well known shopping website, why? I can access it from my iPhone.

    My Mac is blocking me from accessing a well  known shopping website (no problem at their end with my account).  I can access it from my iphone, so why not my Mac?

    From the Safari menu bar, select
    Safari ▹ Preferences... ▹ Security
    and check the box marked Enable JavaScript.
    If the Develop menu is showing and Disable JavaScript is checked, uncheck it.

  • Block users from retrieving during manual calculation

    Hi Everyone,
    I am wondering if anyone knows how to block users from retrieving or pulling in Essbase while a calculation is running manually in EAS. We have a currency conversion calculation that manipulates the data for several minutes. Users who pull the data see erroneous data for some time and it becomes an issue.
    Thanks,
    Mark

    You would have to log them out, then disable connects while you run your script. You could execute maxl commands from EAS.

  • Blocking Users from Commenting

    Is there a way to block users from posting comments on a blog? We have generic accounts for a labs and our students have figured out that they can login using the generic account and post a comment. Then another user can login sing the same generic account and read the comment even if it is not been moderated. They are using it like a chat system.
    Simply put can we create a "blacklist" of users for the service which would prevent the students from posting as a user. They would still post as anonymous users.

    Hi Vittal,
    use the user-exit described in note: 808971 (RSWUWFML2).
    If you had several users changing dynamically I would create a z_ table for those users and select all in the exit.
    The other way would be to allocate to the users a dummy email adress...but this is surely not so great.
    Regards
    Tibor

  • Prevent a user from accessing Cube Navigator

    Is it possible to prevent a user from accessing the cube navigator in Analyzer so the user can only view reports that are setup? thanks

    In Analyzer 6.2, there are some 'behind the scenes' parameters that can be added to suppress menu items. If you are currently using Analyzer 6.2, try adding the following parameter to your applet tag:<PARAM NAME = HideNav VALUE ="True">Note: this will hide the Navigate button for all users accessing the page.

  • Blocking Users from Posting

    Hi,
    We are auditing this company and we noted that there are three dormant company codes. They became dormant because these companies were already dissolved and liquidated. Currently. these three are set to non-productive.
    My question is: Is there a way to block users, who have access to all company codes, from posting to these company codes? I was hoping maybe there is some configuration that will prevent the users from posting any transaction to these company codes. We don't want to clean up the roles since this is a big exercise.
    Appreciate if you can help me on this matter.
    Thanks in advance.

    Post it in Netweaver--- security forum.
    For your question..I think it can be done through configuration...If there is no existing company code..how can they post?

Maybe you are looking for