Display Authorization for MASSD

Hi,
There is a requirement for giving a user only display authorizations for MASSD.
I've tried various combinations of objects, however have been unsuccessful so far..
Pls. help.
Thanks,
Saba.

Hi Saba,
the proposals (values maintained in SU24) should save time to role administrators.
The developers maintain those values which make sense in their eyes. As example if they provide a transaction for creation of an item, they propably would maintain the activity 01, for a display transaction actvt=03 and so on. That will save time to admins, as they would not have to enter the values once more (compared to an empty field....). Of course, that proposals are still proposals only!
For complex transactions it makes sense, to have a proposal of which authorization objects are necessary to be able to execute that transaction.
Maybe you can remember the old procedure before pfcg had been invented - it was hard work first to identify all the objects checked with its values, then create the corresponding authorizations in SU03, then create the corr. profiles in SU02 and finally assign that profiles to users in SU01. That was really time consuming....
So the invention of pfcg opened a very comfortable and quick possibility for that tasks with a high range of automatism. Of course this automatism can only be as good as the values which are behind it. So having accurate SU24 settings help a lot.
So enjoy pfcg
b.rgds, Bernhard

Similar Messages

  • Display Authorization for webdynpro component

    I have a requirement where , the source code has to be hidden . I have seen programs where it hides ABAP report but none for We dynpro. Is there a way to hide web dynpro code . Or is there any way to revoka even display authorization for the web dynpro components ? Please provide any suggestions.
    Regards,
    Sri

    Hi Srivijaya,
    Go to application, parameters tab give WDDISABLEUSERPERSONALIZATION give value to 'X'. It will disable user personalization settings, user can't see any help regarding component.
    Cheers,
    Kris.

  • Display authorization for all modules Including Basis.

    Hi All,
    Is there any Role or profile for display authorization for sap modules .
    Regards,
    Eswar.

    Dear,
    That ROLE will be SAP_ALL_DISPLAY
    "what is to be done"
    just assign the role to the display user via SU01
    Hope this help!
    Also refer this ,
    DISPLAY ONLY AUTHORIZATION
    Regards,
    R.Brahmankar

  • WEB UI- only Display authorization for LEADS to users

    Hi Gurus,
    I have a requirement like i need to give only display authorizations for users to leads.
    I have created a new business role and assigned only search links. but in that search link we have Create New option. How i need to disable this.
    Users needs only display authorizations for Leads.
    Waiting for reply...
    Regards,
    Ajay.

    Hi Ajay,
    First of all, It is possible to disable the New button on the Search page without any code change. There is an SPRO setting which is to be done in order to achieve this.
    You might have created a new z navbar profile as you have created a new business role as per your business requirement.
    Lets take an example, you want to disable the New button on Contact Search Page. follow these steps:
    1.Go To T. code /ncrmc_ui_nblinks
    2. Select the Z navbar profile you have created for your business role
    3. Double Click on "Define Generic OP Mapping" in left hand side
    4. Select Object Type as BP_CONTACT and remove the Following entry
    BP_CONTACT     D Create     MD-BPCP-CR          MD-CONP-SR
    Please note the Obj. Action here D Create, if you remove this entry it means you are disabling the Create Action for this business role for object Contact.
    Hope this will help you.
    Regards
    Ajay

  • Display authorization for resource planning missing

    Hi,
    while open the Resource planner with log in service manager.it is showing following error
    Display authorization for resource planning missing
    i am not getting this error why it is showing.any one help me to solve this issue
    Thanks & Regards
    Kishore Kumar

    Maintain the authorization Objects for the PFCG role assigned to the user
    Authorization Object
    Description
    Authorization Field
    Value
    Value: System
    Relevance
    WFDS_RPA
    Authorization Object Transaction
    ACTVT
    3
    WFD server
    Service resource planning application (RPA)
    WFDS_RPA
    Authorization Object Transaction
    ACTVT
    2
    WFD server
    RPA
    B_BUPA_GRP
    Business Partner: Authorization Groups
    ACTVT
    3
    SAP CRM
    RPA
    Appointment scheduling
    B_BUPA_RLT
    Business Partner: BP Roles
    ACTVT
    3
    SAP CRM
    RPA
    Appointment scheduling
    B_BUPA_RLT
    Business Partner: BP Roles
    ACTVT
    3
    SAP CRM
    RPA
    Appointment scheduling
    WFDS_JFUNC
    Authorization Object Resource (Type of WFD Resource)
    WFDS_RTYPE
    WFD server
    RPA
    Appointment scheduling
    WFDS_JFUNC
    Authorization Object Resource (Job Function)
    WFDS_JFUNC
    WFD server
    RPA
    Appointment scheduling
    WFDS_JFUNC
    Authorization Object Resource (Job Level)
    WFDS_JLEVE
    WFD server
    RPA
    Appointment scheduling
    WFDS_SAREA
    Authorization Object Resource (Type of WFD Resource)
    WFDS_RTYPE
    WFD server
    RPA
    Appointment scheduling
    WFDS_SAREA
    Authorization Object Resource (Service Area)
    WFDS_SAREA
    WFD server
    RPA
    Appointment scheduling
    S_TCODE
    Transaction Code
    TCD
    /SAPAPO/LRP_ACCESS
    WFD server
    RPA
    Appointment scheduling
    UIU_COMP
    Authorization UI
    COMP_NAME
    WCC_SRV_RPA
    SAP CRM
    RPA
    UIU_COMP
    Authorization UI
    COMP_WIN
    WCC_SRV_RPA/MainWindow
    SAP CRM
    RPA
    UIU_COMP
    Authorization UI
    COMP_PLUG
    SAP CRM
    RPA
    UIU_COMP
    Authorization UI
    COMP_NAME
    WFDRPA
    SAP CRM
    RPA
    UIU_COMP
    Authorization UI
    COMP_WIN
    MainWindow
    SAP CRM
    RPA
    UIU_COMP
    Authorization UI
    COMP_PLUG
    DEFAULT
    SAP CRM
    RPA
    UIU_COMP
    Authorization UI
    COMP_NAME
    WFDRPA
    SAP CRM
    RPA
    UIU_COMP
    Authorization UI
    COMP_PLUG
    DEFAULT
    SAP CRM
    RPA
    UIU_COMP
    Authorization UI
    COMP_WIN
    WFDRPA/MainWindow
    SAP CRM
    RPA

  • Display authorization for particular line of table

    Hi Experts,
    I have a Z table contains sales area data. I want to display those records only which user has authorization for the sales area. It is possible through the table maintenance event or there is any other way to achieve this.
    Quick response will be appreciated.
    Thanks in advance for your sincere help.
    Cheers,
    Anil

    Hi Anil,
    Yes,Its possible through table maintainance event itself.
    Only thing u need to do is check for the sales area the user is authorized..using
    FM: SUSR_USER_AUTH_FOR_OBJ_GET
    SEL_OBJECT:- CRM_ORD_OE.
    Hope it helps!!
    Regards,
    PePe

  • Display authorization for plan data

    Dear All,
    I have to split users into two categories as reviewers and planners.
    I have created two roles from rsecadmin. For plan users it is working perfectly but for the reviewers system gives an authorization issue.
    Plan users auth:
    0TCAACTVT - ACTIVITY : 02
    Reviwers auth:
    0TCAACTVT - ACTIVITY : 03
    Is there any possibility to do it but copying queries as not input enabled?
    Thank you very much.
    Alkan

    Dear,
    That ROLE will be SAP_ALL_DISPLAY
    "what is to be done"
    just assign the role to the display user via SU01
    Hope this help!
    Also refer this ,
    DISPLAY ONLY AUTHORIZATION
    Regards,
    R.Brahmankar

  • Roles  for only display authorizations

    Hi Experts,
    Can any one suggest me how to creat the role only for display authorizations for basis.
    Is any standard role like this? if it is please let me know.
    Thanks & Regards.
    Reddy V

    n k wrote:>
    > Hi,
    >
    > just give the tcodes required with the display activity, that is 03.
    I consider that to be dangerous advice because it assumes that activities are checked in all transactions.

  • Authorization for Create a Query

    hi all!
    I need that the users can have access to create queries but I don't have the authorization for this, could you tell me which object i need?
    Thanks!

    Hi Carlo,
    adding to Venkat, there is an other object called:
    <b>S_RS_FOLD</b>
    Display authorization for folder. This object is new in SAP BW 3.0.
    With this the reporting user should only be able to see their Favorites folder and their assigned roles. They cannot look at other InfoAreas to which they have not been granted access.
    Hope it helps.
    Please award points if it is useful.
    Thanks & Regards,
    Santosh

  • Complaints Display Authorization

    Hi Experts,
    My requirement is to restrict complaints Transaction Types to search and Dispaly for certain users.
    I tried restricting autorization object CRM_CMP and CRM_ORD_PR in the PFCG roles. In Autorization object CRM_ORD_PR, though I have given Activity as Display and in Transaction types the companis which I want to be displayed.
    Despite all this in the Web UI it allows me to create complaints. More over I have given display authorization for 3 complaints where as it is pops up for all complaints transaction types.
    Could please guide me, if I am missing any other authorization objects to be restricted??
    Only complaints should be searched and display.
    Regds...
    Arup

    Hi
    check all the PFCG roles if your user has multilple roles assigned and make sure that SAP_ALL and SAP_NEW profiles are not assigned to your user.
    Regards,
    S Reddy

  • Diaplay authorization for all modules

    Hi All,
    Can any one tell me how to assign display authorization for all modules like sd, ps, mm, fico ,hr ..
    is there any profile available for that ???
    any idea would be great.
    Thank for ur help in advance.
    Regards,
    Venki

    > And best would be if you can share the created copy of SAP_ALL with SDN users - hope moderators wouldn't mind this sharing.
    Davinder,
    I'm afraid you're chasing ghosts here, as have many before you and I'm afraid it will not stop here.
    The reason a search didn't bring up an easy solution (see your other thread, SAP BASIS Display only Role) is because there's no easy way to get to a display only role.
    Some thoughts:
    1- The amount of authorization objects varies from system to system, due to patch levels and installed add-ons so sharing a role built on a 'strange' system will have it's flaws and due to the amount of objects in SAP_ALL or a copy will make it very difficult to spot those.
    2- There are somewhere between 150-200 different activity related fields in an ECC systems' authorization objects and for quite a few 03 is not display. Some do not have a display activity. See below as well.
    3- There are a lot of objects that do not have any activity related field so putting them in a role and claiming it is read-only is downright dangerous.
    To create proper display roles you will need to get requirements from the business, not only to build the roles but also to be able to test them. I've seen long lasting discussions whether printing is a display activity or not......
    Jurjen

  • Necessary Authorizations for BI Consultant

    Dear All,
        What are the necessary Authorizations for BI 7.0 Consultant to work on a BI development system ?
         I have created source system (ECC Dev system), installed Bex analyser and I would like to verify if there are any standard tasks to be performed to make the system ready for BI consultant and required authorizations to perform all the activities.
    Thanks,
    Nick.

    Hi,
    The basic authorizations you need are RSA1, then you need to have access to all the infoareas, objects. You need access to modify, create, activate objects. In addition you'll need access to maintain master data for master data objects, monitor job loads, process chain access, query creation and change access. Query execute access. Authorizations to replicate datasources, activate them and access for creation, change and activation of DTPs, Infopackages and Transformations is also needed.
    These are some of the basic authorizations you need in the development system.
    For all other systems, you only need display authorizations for all objects.For data viewing, it'll be based on what security you get. Based on the client strategy in some places, you might get authorization to create, change and activate infopackages and DTPs. But to maintain the integrity of the Process chains and the environments, the best practice would be create these objects in dev and then transport them.
    Cheers,
    Kedar

  • Restricted Recruiter Authorization for Requisition (ERC_A_REQ_MGMT)

    Dear Friends,
    My client wants to only give the display authorization for requisition (application "ERC_A_REQ_MGMT" ) to restricted recruiter(SAP_ERC_RES_RECRUITER_CI_4) role.
    In standard system restricted recruiter can change any field data for requisition, which we don't want.
    Kindly tell me any way out through which we can achieve this.
    Chohan

    You can create an application configuration for that application, than assign component configurations for the webdynpro which you create where you define all fields as read-only.
    Than you give the restricted recruiters the links with the application configuration.
    Or you do an enhancement of the webdynpro, but that should be plan B

  • Data model 0G: No authorization for entity type Account (Company Code) - activity Display

    Hello Expert,
    I have a problem with authorization in MDG-F.
    I want to create Account with Collective processing. After, entered Entity type, Edition and Chart of account,  Blocking message "Data model 0G: No authorization for entity type Account (Company Code) - activity Display" is displayed.
    But, i checked in PFCG transaction, for this user profil, activity are : create or generate, Change and display. So, for me , it is correct.
    Please, check screen shot below :
    Blocking message :
    and in PFCG transaction
    Could you help me to solve this point?
    Kind regards,
    Heri RAOELISON

    Hi Heri,
    the system behavior is correct. The account in company code consists of three entity types:
    1) COA - Chart of Accounts (Type 3)
    2) ACCOUNT - Account (A-Segment, related to ECC table SKA1, Type 1)
    3) ACCCCDET - Account in Company Code (B-Segment, releated to ECC table SKB1, Type 1).
    3) includes 1) and 2) whereas 2) includes 1). If you grant authorization only for 3) but not for 1) and 2), you cannot do anything.
    Best regards
    Michael

  • HR authorization for Display the documents  in SAP DMS

    HI experts,
    We want to control display authorization depending on the entry made in object link tab in DMS( DOcument Management System). We developed screen for HR master object link. When user executes cv03n and enters document No. system should check hr master number entered in object link. If the user has authorization for that hr master number in PA (personnel administration), then he should be allowed to display the document. Otherwise it should restrict him to display the DIR.
    Now my query is how to achieve it. Can anybody provide me some solutions
    I have one solution, whenever user enter document number in cv03n screen, system will first check hr master number entered in object link and it will check the Personnel Area, Employee group and employee subgroup aginst this hr master number. Say for ex: PA:1000, EG:1 and ESG:01 for HR number xyz.
    Now system should check in roles assigned agaist user id for these PA, EG and ESG values. If user has got authorization for PA:1000, EG:1 and ESG:01 in HR roles,then he should allowed to display the document.
    Now my query is how feasible this approach? is this tough task for abaper? or is there any easier approach than this.
    regards
    sham

    Hi,
    Try to use the User Exit: CNEX0002.
    Check with your ABAP er for the enhancement.
    Hope it helps..
    Thanks!!!

Maybe you are looking for