ERM - Adding Function to a Role

Hi all,
        I have the following problem. when we add a Function to a Role in ERM, the transactions are added but the authorization values don't. Does anyone know something about this issue??
Kind Regards!!
Isaac

We are under SP12 and we are not able to add transactions or auth objects to the role through Functions or Manually. Both functions and transactions are found but when selecting them and saving and error is raised.
We are in the right VIRSANH and VIRSAHR SPs.
We have upload the XML files
We have run job sync taks to import transactions, auth object and org value
We are having an OSS Message...
Get back to you when solution is found / provided.

Similar Messages

  • Error in adding Function to the role

    Hi Experts,
    We are on AC-ERM 5.3_10_0. I was trying to create a test role in ERM. When adding a function to the role it's throwing the following error.  Unknown error occurred while performing operation (Cannot assign a java.lang.String object of length 57 to host variable 2 which has JDBC type VARCHAR(50). in method insertOrgLvlsForRole).
    Not able to find out, what's going wrong. Can anyone please guide me in resolving the error.
    Thanks,
    Gurugobinda

    Hi Zaheer,
    Thanks a lot. You are right. I am not facing this error in other functions. Only in for functions like PR91, PR01, HR02 I am getting this error. In fact, when I am adding the function it is showing the error, but when i am coming back  to function TAB, I am finding the function has been added successfully. Can you please tell me how to rectify this error.
    Regards,
    Gurugobinda

  • Custom role for adding functional position.

    Custom role for adding functional position.
    I added a custom role for to allow only OrganizationDesigner capabilities. I could see functional positions but I could not modify or add them. What permissions I have to assign to role for adding and modifying functional position in organization designer.
    I tryed everything bot noting works unless I give site addministrator privilages to the user.

    Hi Indulis,
    I have just replicated the behavior you are describing in our training environments. This is not the expected behavior. I will immediately open a case with Customer Care, and I suggest you do the same.

  • Restricting an administrator to only adding or removing Business Roles

    Hi:
    Is there an out of the box rule or form in IDM that can restrict an administrator to only adding or removing business roles from accounts?
    Thanks.

    Hi Dwayne,
    This BU ruling is somewhat of a newer function with OIA. For mass alteration, the old-school way would be to execute a SQL script directly towards the DB.
    Simply change the last line on what correlation you wish (in this situation, it's looking at the BU Name and the GU office name)
    delete from BU_GLOBALUSERS where businessunitkey > 0;
    insert into BU_GLOBALUSERS(BusinessUnitKey,GlobalUserKey)
    select BU.BusinessUnitKey, GU.GlobalUserKey from BUSINESSUNITS BU, GLOBALUSERS GU
    where BU.BusinessUnitName = GU.officename;
    Regards,
    Daniel Redfern
    Technicalconfessions.com

  • Import roles to the ERM without using the "Mass Role Import

    Hello,
    I want to know if there is another way to import roles to the ERM without using the "Mass Role Import.
    Im'm using SAP GRC AC 5.3
    Best Regards.
    Pablo Mortera.

    Hi.
    There is NO other way to import roles..
    We need to use only ERM for "Mass Role Import.
    Regards
    Gangadhar

  • Benfits or added functionality in ecc 6.0

    Hello All,
    Can any one list down the benfits or added functionality in ecc 6.0 from abap point of view.
    ManyThanks,
    Vibha

    Hi
    Refer this link for ECC 5.0 & 6.0:
    http://help.sap.com/saphelp_erp2005/helpdata/en/43/68805bb88f297ee10000000a422035/frameset.htm
    A similar post
    /message/1783778#1783778 [original link is broken]
    You can go through the Release Notes for each of the versions after 4.6B (4.6C, 4.7 , ECC 5.0 & ECC 6.0)
    http://help.sap.com/saphelp_erp2005/helpdata/en/43/688055b88f297ee10000000a422035/content.htm
    For 4.7 SAP R/3 http://help.sap.com/saphelp_47x200/helpdata/en/12/9d78d6d8f74043a32e82be87e433b7/content.htm
    Release Notes on SAP Web Application Server 6.30
    http://help.sap.com/saphelp_47x200/helpdata/en/2b/64fc3e9d3b6927e10000000a114084/content.htm
    http://solutionbrowser.erp.sap.fmpmedia.com/
    Check these links
    https://www.sdn.sap.com/irj/sdn/go/portal/prtroot/docs/library/uuid/790e690c-0901-0010-7894-de8b3d91d78e
    http://help.sap.com/saphelp_nw04/helpdata/en/94/c65839bec58b27e10000000a114084/frameset.htm
    http://help.sap.com/saphelp_nw04/helpdata/en/a8/b9623c44696069e10000000a11405a/frameset.htm
    http://help.sap.com/saphelp_nw04s/helpdata/en/c1/1253164e665b4fa635af38b66dc166/frameset.htm
    http://help.sap.com/saphelp_nw04/helpdata/en/f5/a9673e42613f7ce10000000a114084/frameset.htm
    http://help.sap.com/saphelp_nw04s/helpdata/en/dc/6b7f2f43d711d1893e0000e8323c4f/frameset.htm
    Reward points for useful Answers
    Regards
    Anji

  • When Tcode and Object added to the particular role

    Dear Gurus,
    My question is that, how we can able to know that who (user ID) / when this tcode or object (with particular activities) has added to this particular roles/profiles.
    Regards,
    Sanjay

    Hi Sanjay,
    Goto SUIM->Change Documents->For Profile and select the profile of the role for which you would like to see the changes.
    After running the report, you will see the Objects added/removed. Click on each Object & it will show all the details, as in: who did, at what date, time, values entries etc
    Similarly, you can see the same for Roles also, if you want to see for Transaction codes

  • SAP EP 7.0 Error in accessing Import function of CustomizedTranport role.

    Hi All,
    I have a business requirement of Creating Transport role which should access only Transport Navigational Tab in EP 7.0.
    For that, I have created a role and added Standard System admin role as role to role and i hide the Navigational tabs except Tranport Tab (by changing Properties of ''Invisible in Navigational areas of System Admin role'')
    I have assigned this role to a user. and i have also given read/write permission to folders and in security zones. Export is working o.k and when i click on browse tab in import it is showing-->>
    "Unexpected error. Check the log files for details."
    I have checked logfiles and i didn't find any thing.
    Any ideas??
    Your early response would be highly appreciated.
    Thanks in advance,
    Khasim.

    SAP has resolved this problem.

  • Where has the just added function gone?

    Where has the "just added" function gone in the store

    You can drag & drop as before, or turn on the menu bar with ctrl-b.
    tt2

  • What's the function of "Team Role" in Team configuration

    Hi All,
    What's the function of "Team Role" in Team configuration.
    For example, go to Account Detail page, click "Add Users" button in Account Team section, there's a dropdown list named "Team Role".
    In help document, it says:
    To explain the role the linked record plays in relation to the main record, select an option from the Team Role drop-down list.
    But I don’t understand, can anyone explain this for me?
    Thanks in advance!

    Hello Bruce,
    Team Roles are the access you define to a user you associate to a record. Lets say there are 3 user's A,B and C. If you want to associate All threeto an Account but each should have different access to that account. like A can have Edit, B Edit and delete and C only read only access. so for each user your associating you can control the access exclusively
    ---Shyam (CRMIT)

  • Error in reconcilation Function - Job "Reconcile roles and privileges"

    SAP NW 7.0 SP2 Patch 3
    Roles contain Privileges
    Help file says: "If you are using roles and privileges, you will need to perform a reconciliation of the roles/privileges assigned to the users in the identity store after the roles are modified. "
    Job imported as described.
    When I let the job run on the ID-Store, for each entry, the following error message occurs:
    runFunctionsInString($FUNCTION.reconcile( MSKEY )$$) got exception
    org.mozilla.javascript.NotAFunctionException: reconcile( MSKEY )
    ...where MSKEY is, of course, the MSKEY of the entry.
    If I let run the job with the Windows-Dispatcher and as a VB-script, it produces no error; however, in the output file, there are a lot of Messages like
    "!ERROR: Invalid use of Null"
    Only some entries (of Type MX_PERSON) show the "Priviliege added: (...)" output. But the job does not add the Privileges assigend to the role, as it should.
    So, I would suggest that one redefines the SQL-Query of the Job so that it runs only on MX_PERSONS. But then, still, in my case, it does nothing.
    Has anyone better experiences with the Job?
    Edited by: Thomas P. Felder on Sep 25, 2008 10:32 AM

    The job when imported by default uses java runtime engine but the script is written in vbscript syntax so you have to change the engine or the script syntax.
    When you did your select statement did you use SELECT DISTINCT.  That will also cause errors.  I do not narrow the entry type to MX_PERSON.
    I'm installing the patch now;  I will see if I get any errors.

  • ERM 5.3 (SP12) Derived Role Update Problem

    Hello Experts,
    I have a question.
    We have a master role/derived role set up in the back-end system. We are trying to update a master role and its derive roles in ERM via PFGC sync.
    Our problem:
    We can add a transaction to a master role no problem in ERM via PFCG sync (adding a transaction code in the back-end and sync to ERM) However, we are unable to update the transaction for derived roles (nothing happens for derived roles in ERM).
    If I am correct, we don't have to add a transaction to each derived role manually, and we should be able to update derived roles automatically once we update a transaction in a master role.
    Please just note that we successfully imported all the master/derived roles from our back-end system, and we are not try to create a derived role in ERM at this time. All we want right now is to update a master role and its derived roles in ERM via PFCG sync.
    If you can, please advice.
    HM

    Go to the TXT file , cut the last line from the AGR_1252 (rtable and insert it to the top of the lines ( AGR_1252) , and reimport it will work I had the same problem in my previous implementation.
    try for one parent & child role
    This is a known problem with SAP they will rectify it in SP12/SP13 or so

  • Adding T-code to Role Area Menu which doesn't exist in box

    Hello,
    We are using a SAP system called QIM which has "jumplink" functionality, which is a web based linked (NWBC) which will launch you into a ERP system transaction when clicked. For example, in QIM we will display a outbound delivery, and if we click on the link it launches VL03N from the ERP system and displays as  web UI.
    In PFCG under area menu, this transaction code appears under the menu, but VL03N doesn't actually existing in the system... The issue is we created a custom object for inbound delivery and we need ot add it under this area, but when we attempt to add a transaction code under the Role Area, the system says the t-code doesn't exist... Even when we try this with an existing t-code showing in the menu (Vl03N) it says it doesnt exist. Same if we look at the authorization object S_TCODE. These t-codes exist in here, but when you try to readd them they system says it doesn't exist.
    Please find the attachments with some screen shots... Any idea how we can do this?

    You can create a role menu as remote enabled remote menu.
    The authority checks will happen on the remote side, also against objects which don't exist in the calling system as the music is on the other side.
    On the RFC client system side, you only need the parameter transaction to start the remote transaction in the remote system.
    See the documentation on SYST function module ABAP4_CALL_TRANSACTION.
    This is however a rather antiquated technology... it is more popular to use a SAP Portal or webdynpro applications for this sort of thing (the user does not notice the difference) or later versions of such integration such as Fiori UIs or imbedded links within the Business Client.
    I don't want to lean out the window too far, but the buggy phase of these new things is approaching an end and they are usable if you are on newer releases. Then you can pool the menu and use APIs for navigation and no more irritating S_TCODE checks.
    Cheers,
    Julius

  • S_TCODE object is not coming in role after adding profile of another role.

    Dear Gurus,
    I have added profile of a existed role to a newly created role in pfcg (edit->insert authorisation-> from profile), but I can't see the S_TCODE object of that role of the added profile.
    For some roles, it appears, but for some, it don't come.
    Please let me know the reason behind this, so that I can go forward.
    Regards,
    Nilutpal.

    Hi,
    S_TCODE will be added in your authorization profile when you add some T-Codes in Menu Tab of that role in PFCG.
    This may be the case for your role.  In this case it will not be copied with profile. It will be added only if you add the T-Code in Menu Tab.
    The other case is if you directly insert it in bthe authorization objects. In this case it will be copied with profile.
    Please revert.
    Regards,
    Jaya

  • DC not functioning with FSMO roles

    hello every body,
    I have 0 DC and 01 ADC lets say that DC and ADC. both were replicating AD and working properly. few days ago the motherboard of my DC failed and we replaced with new one. and obviously NIC card was attached with M.Board which also changed. when i boot up
    my DC, i see its not functioning as domain controller as i saw in server manager all FSMO roles are with red cross. i assign the ip address which it hold previous i.e 192.168.0.1. but still FSMO roles are disabled. While my only ADC is working properly with
    following errors and warning in AD DS roles. 
    Warning on ADC:
    The remote server which is the owner of a FSMO role is not responding.  This server has not replicated with the FSMO role owner recently. 
    Error on ADC:
    Log Name:      Directory Service
    Source:        Microsoft-Windows-ActiveDirectory_DomainService
    Date:          12/15/2014 11:18:07 AM
    Event ID:      1863
    Task Category: Replication
    Level:         Error
    Keywords:      Classic
    User:          ANONYMOUS LOGON
    Computer:      KHI-ADC.jehanpakistan.com
    Description:
    This is the replication status for the following directory partition on this directory server. 
    Directory partition:
    DC=ForestDnsZones,DC=jehanpakistan,DC=com 
    This directory server has not received replication information from a number of directory servers within the configured latency interval. 
    Latency Interval (Hours): 
    24 
    Number of directory servers in all sites:

    Number of directory servers in this site:

    The latency interval can be modified with the following registry key. 
    Registry Key: 
    HKLM\System\CurrentControlSet\Services\NTDS\Parameters\Replicator latency error interval (hours) 
    To identify the directory servers by name, use the dcdiag.exe tool. 
    You can also use the support tool repadmin.exe to display the replication latencies of the directory servers.   The command is "repadmin /showvector /latency <partition-dn>".
    My DC is working properly as a System.
    should i have to do something with my NIC or AD DS roles or i have to transfer FSMOs to ADC. or sieze fsmo roles of DC on ADC.
    please help.

    Is your DC (role holder) a DNS Server as well? I assume it is, if so open the server role properties and ensure the DNS server role shows the IP in the interface if it does not you may need to uninstall/ re-install the DNS server role (assuming it is a 2008
    R2 DC or above... Also did you look at your NIC settings? Did you re-establish the exact same NIC configuration as before?
    When the motherboard gets replaced and new NICS are introduced I normally look at the NIC settings and DNS Server roles... That is the Microsoft side of things. On the LAN/ WAN side of things if your network team has port security enabled on the switches
    the port may be locked down due to the new MAC Address.

Maybe you are looking for