Deriving roles and profiles

Hi,
i am using pfcg for creating roles. When i want to derive a role from a mother role the profile is not taken with the role. Is there a way to derive not only the role but also the profile from a mother role?
Regards
Florian

Hello Florian
I still do not see the point yet if the derived role should be identical to the master role then you could do the following:
(1) Copy master role -> name of derived role
(2) Update table AGR_DEFINE for the derived role name, i.e.
- select all values from AGR_DEFINE with AGR_NAME = '<name of derived role>'
- set AGR_NAME-parent_agr = '<name of master role>'
Regards
  Uwe

Similar Messages

  • "save derived roles" and "generate derived  roles"

    Can anyone tell the difference between "save derived roles" and "generate derived  roles".

    Hi,
    Save Derived role will save the changes you made to the role(Eg: You might have added a new org value for company code)but this will not be reflect to the users and user masters remain the same unless you generate the role.
    Once the Role is generated user masters and profiles are updated.
    Rakesh

  • Roles and profile in SAP

    what is role and profile in SAP?
    how we can diffferentiate both?

    Hi Swati,
    Role refers to the collection of associated activities (privilages) such as transactions, reports and so on. There are 2 types of Roles, Standard Role and Derived Role. While profile is a set of authorizations that are valid for the transactions defined in that role. Roles contain no actual access. They contain a role menu composed of transaction codes. These transaction codes are then mapped into the profile automatically by profile generator. When a role is generated (once created) the profiles are created automatically by profile generator. Every transaction code is different and may require different numbers of accompanying authorization objects to execute. A single profile can only contain 150 authorizations.  Once that number is exceeded the profile generator will automatically create a second profile, sorted alphabetically by object name.
    Please refer the below links:
    The specified item was not found.
    Re: difference between profile and role
    Difference between Role & Profile
    Regards,
    Sreedhar

  • Security roles and profiles

    Hello,
    Could you please provide information on "security roles and profiles "
    I would appreciate.
    Regards,
    Alex

    Roles give you authorization to specific area of the system. Use TC pfcg and you will see different setting for a role.
    In specific Role -> Authorization -> click on Display Authorization Data.
    Here all specific InfoArea, Cube, ODS, Reporting componets: display, execute and other security rules are defined.
    User Section: defines who has access to this role.
    Multiple authorization are combined to create an Authorization Profile. You defined a profile at TC su01 and under profile section.
    Hope that helps.
    thanks.
    Wond

  • DB table for Derived Roles and Parent Roles

    Hi Expart,
    In which DB table the Derived Roles and Parent Roles are store .that is i need to find out the derived role and parent Role .i have completed the Complex and single role by table AGR_AGRS
    But i have to find out the table for Derived Role
    Plz help me to get those table
    Thanks in advance
    Tarak

    It's the same table as for the master role: AGR_DEFINE (field PARENT_AGR is filled for derived roles).
    ~As from Forum

  • Compliance Calibrator Design - Roles and Profiles

    Hi guys,as you know SAP's authorization concept involves generation of Roles into Profile before it can be assigned to a User. In CC, i wonder why is there a need to segregate Roles and Profiles into 2 seperate functions. Isnt it already sufficient to analyse roles instead of profiles? Profile are names which is too technical which i feel should be omitted unless really necessary.
    Well, unless it is to cater for indirect assignment where profiles are granted to position/org unit etc... I will also be trying out whether there is a difference when you only batch analyse a Role and intentionally excluding the 'profile' whenever a new role is created. Will the system work fine when i do a role analysis?
    Cheers!

    I agree that profiles are old fashioned and should be phased out.  The system has to stop people from being able to maintain profiles directly and assign them directly before they do this though.  SAP_ALL etc can be converted and assigned as a role.  It would make the whole authorisation concept just that little bit easier.  We are talking about a German company though!
    Also, you don't need profiles for indirect assignment.  You can relate roles to the position using PFCG!  Click on the organisational management button on the user-tab, next to the user comparison button.
    Using profiles (ie, maintaining directly and assignment) is highly recommended against.

  • Active a role and profile

    Hi Experts,
    Could you guide me on how to activate a role and profile? Kindly suggest to me the proper procedure of doing this.
    One more thing experts do you have any idea on what tcode used to change a password for multiple user's? Could you give to me as well the proper procedure of doing this.
    Regards,

    To activate a profile, choose Profile Activate on the Profile List screen. If an active version of the profile exists, you will see the active and maintenance versions of the profile so that you can verify the changes.
    New or modified profiles must be activated before they can be assigned to users or become effective in the system.Activation copies the maintenance version of a profile to the active version. If the activated profile already exists in a user master record, the changes to it become effective as each affected user logs onto the system. Changes are not effective for users who are already logged on when the profile is activated.
    For it to take effect, you must hand over your role to the User Management Engine. You do so by activating the user role.
    To activate a user role, choose Activate User Role ( ). To undo, choose Deactivate User Role.
    If u want to change password number of user at a time .For my kind of information its not possible need to change password indivisualy.
    Reg.
    Deepak

  • After BI 7.0 Upgrade, Authorization Roles and profiles are not visible

    Hi Gurus,
    We have an issue with authorization roles and profiles are not visible for all end users with new Bex Analyzer (BI 7.0) tool. But still they can see these roles with old Bex Analyzer ( Bex 3.5) tool.
    As a developer I have SAP_ALL acces and I can see all authorization roles in new BEx Analyzer (BI 7.0).
    I verified in SU01 for user access and every are assigned there roles and they are green.
    Do we need to add any new authorization object to fix this issue, please let me know
    Thanks and appreciate your help.
    Thanks
    Ganesh Reddy.
    Edited by: Ganesh Reddy on Oct 26, 2009 4:41 PM

    Hi Ganesh,
    check the behaviour, if you assign
    S_USER_AGR                          
       ACT_GROUP = "..name of the assigned role.."
       ACTVT = 03 (for "display")    
    b.rgds,
    Bernhard

  • After BI 7.0 Upgrade, Roles and profiles are not visible

    Hi Gurus,
                                  We have issue with the roles and profiles, all our users doesnt see any roles or profiles in Bex Analyzer, under there user access after BI 7.0 Upgrade. 
                                   When I go and check there profile in SU01 and I can see all roles are assigned but not able to see in the Bex Analyzer reporting tool.
                                   Do we need to do any configuration settings after BI 7.0 upgrade to visible roles. This problem with every user.
                                   Your help will be really appreciated.
    Thanks
    Ganesh Reddy.
    Edited by: Ganesh Reddy on Oct 22, 2009 5:19 PM

    Hi Mohan/Vijay,
                            Sorry for little bit late. I have all authorization roles access, and users dont have that access. Difference between our roles is I have SAP_ALL and SAP_NEW.
                            But when they login with old bex analyzer they can see all roles, but not with new bex analyzer.
                            Please some suggest me still I need to run SU25.
    Thanks
    Dayaker Reddy.
    Edited by: Ganesh Reddy on Oct 26, 2009 10:19 AM

  • Authorization : roles and profiles

    Hi,
    I have two questions that I need answers
    - How do I check roles that are assigned to reports and
    - roles and profiles needed to execute reports
    thanks in advance

    Hi,
    Roles or profiles are assigned to user not specific reports or queries, if u need u can check what roles are assigned to u in SU01, provide the user name and go to display mode there u will find profiles tab, u can check .
    Hope this helps u a lot.........
    Assigning points is the way of saying Thanks in SDN
    Regards
    Ramakrishna Kamurthy

  • VIRSA tables for users, roles and profiles sync?

    Hello,
    I am in a customer, implementing CC 5.2. At the first time, we tried CC 5.2 in DEV environment, and when everything was OK, we redirect RFC connectors to QA environment.
    After doing user, roles and profiles sync in DEV and in QA environment too, I have 4.500 user (1.100 from DEV + 3.400 from QA) when I recover all users "*" with "user level - risk analysis" from the "Informer" tab.
    It seems that "users, roles, profiles, sync" works like and "APPEND", but I did a COMPLETE syncronization not an INCREMENTAL.
    If I start an analysis for QA environment, CC works properly and only analyse QA users (3.400). But I would like to clean CC tables (users, roles and profiles) in order to have a clean copy of QA in CC.
    Which VIRSA tables (users, roles and profiles) I need to clean?
    It is necessary to do the same with authorization and text objects? Which would be these tables?
    Thanks in advance,
    Victor

    Hi all,
    SAP GRC Support provides a script which allows you to remove a connector since it does delete all data link to it. Anyway, I would recommend a deep analysis of it and find out if it does what you really want to do.
    Víctor, if what you want to do it is just to remove all user, role and profile master data (stored in tables VIRSA_CC_SYSUSR and VIRSA_CC_GENOBJ) you could upload a text file using data extractor functionality with the delete field set to X. Doing so user, role and profile master data will be removed from CC database.
    In order to use data extraction functionlaity you connector must be of type "File Local".
    Be careful about removing data directly from DB since, as Prem states, you might loose the DB consistency.
    Hope it helps. Best regards,
       Imanol

  • Webservices roles and profiles r/3

    Hi gurus i have a little problem i guess
    i develop a web service and i want that an extern client use this webservice.
    the basis consultan has created an user and he has assigned the sapall and sap new profile and the role.
    the client executes the webservice without problem, but i dont want that the user has this profiles, i need to restric the prmissions of the user created by the basis consultant
    and when the basis consultant take out the sap all and sap new profile and assing other profile an role the webservice cant be executed, the error is that the user has not permission to execute the function group zsd001.
    Does any one knows which roles and profiles does the basis consultant has to assign to the user?
    thanks.

    thanks gurus

  • Su01 recreate old user - lost roles and profiles

    Situation: a person's sap account was deleted, but now that person needs it again with the same sap access as before
    when you recreate an old sap user account in su01,
    sap gives a message "found old user information, do you want to reacreate this".
    Press yess, then all is copied except roles and profiles (empty)....
    You can find them back via the menu : information<change dcuments for users.
    Is there a way to make sure that roles (and/or profiles) are instantly copied from the old records of the sap account (like
    the name, email user group, user parameters, etcetera)?
    Regards,
    ABC

    No. There is no such feature.
    The solution is not to delete the user but rather lock the ID and move it to a "retired" user group where it is protected. From there you can restore it again easily.
    Cheers,
    Julius

  • BW Roles and profiles Tables

    I would like to download a list of all users and what roles and profiles each has.  I did it once before but now I can't remember the table names.  Can anyone help?

    Hi,
    Roles:
    SAP_BW_DEVELOPER
    Profile:
    SAP_ALL
    S_BW_D____
    S_BW_D____1
    Authorizations are
    S_Rs_Admwb_a
    S_rs_adw_a
    S_rs_exp_a
    S_rs_wb_all
    Links for user roles:
    http://help.sap.com/saphelp_nw2004s/helpdata/en/52/6714b6439b11d1896f0000e8322d00/content.htm
    http://help.sap.com/saphelp_nw2004s/helpdata/en/42/271d24d86211d2961a0000e82de14a/content.htm
    http://help.sap.com/saphelp_nw2004s/helpdata/en/e4/15e48efd6c11d296430000e82de14a/frameset.htm
    http://help.sap.com/saphelp_erp2005vp/helpdata/en/d3/559a4271c80a31e10000000a1550b0/frameset.htm
    http://help.sap.com/saphelp_erp2005vp/helpdata/en/4e/52b74065448431e10000000a1550b0/frameset.htm
    For profiles and authorisations:
    http://help.sap.com/saphelp_nw2004s/helpdata/en/52/67151e439b11d1896f0000e8322d00/frameset.htm
    http://help.sap.com/saphelp_erp2005vp/helpdata/en/20/efcbfed8a511d397110000e82de14a/frameset.htm
    Also chk this link..
    http://www.bwexpertonline.com/archive/Volume_04_(2006)/Issue_10_(Nov_and_Dec)/V4I10A2.cfm?session=
    screenshots..
    https://www.sdn.sap.com/irj/servlet/prt/portal/prtroot/docs/library/uuid/1b439590-0201-0010-ea8e-cba686f21f06
    Hope this helps,
    regards
    CSM reddy

  • SAP Roles and Profiles provisioning

    Hi all,
    I am trying to provision SAP CUA using the SAP UM Connector.
    User gets provisioned, but its role and profile do not get assigned.
    The tasks "Add Role" and "Add Profile" are seen as completed.
    But the roles and profiles are not seen in SAP.
    Thanks in advance

    Any inputs from anyone ???

Maybe you are looking for

  • Will firmware version 4.1.7 automatically update to 4.1.9?

    I recently upgraded to OS 10.3 from OS 10.0 on my Imac 700MHz G3. The installation documentation said that I would be prompted to upgrade the firmware if I needed to. I was not prompted so I went ahead and did the OS 10.3 installation. The firmware r

  • Problem getting the selecteditem in tree while fetching data through httpserivces

    I have a mxml file in which a want to display data in tree structure. The supplied to the tree is fetched from database through httpservice the mxml file content is : <?xml version="1.0" encoding="utf-8"?><mx:Application  xmlns:mx="http://www.adobe.c

  • Logic Crashing, food for thought...

    I posted this in another thread, but thought it might be worth posting separately. First, keeping in mind that crashes probably happen to Logic users all around the world running different versions on different computers with varying amounts of plugs

  • Read 0CALMONTH takes long time

    Hi all, I have a performance problem. When I read some data from a large ODS, it takes a very long time. I noticed that during the reading the system spend a lot of time on 0CALMONTH characteristic (select from sid table). I'd like to know why, and i

  • GetAudioClip() not found in class . Help !

    Dear People, I have one error message "getAudioClip() not found in class. I investigated in the AppletContext interface for the signature of the method. It says that the signature of the "getAudioClip()" method has one parameter. That parameter is th