ESS: SAP_EMPLOYEE_ERP role

Hi All,
I set up ESS for ECC 5.0 system. I configured JCo destinations using User ID and Password (This UID and PWD has SAP_ALL role assigned in the ECC System). All the configuration is complete.
Now, when i try to access the ESS iviews from the portal i'm geting an error saying " you are not authorized to this service..."
As i know that SAP_ALL will include all the roles and authorizations.
My question is, do we need to assign the role SAP_EMPLOYEE_ERP even if we have SAP_ALL role assigned to the user?.
Thanks in advance
Karthik

Achim,
Thanks for your reply.
I dont have authorizations for transactions that u mentioned. I was given SAP_EMPLOYEE_ERP role. but still the problem remains.
Problem:
  You dont have the authorization to start service sap.com/essarpdata/Per_Personal_AR.  
com.sap.pcuigp.xssfpm.java.FPMRuntimeException: You dont have the authorization to start service sap.com/essarpdata/Per_Personal_AR.
The help says,
Create copies of the composite role SAP_EMPLOYEE_ERP and all the single roles contained in it. Work with the copies only.
Choose the authorization object S_SERVICE (check on start of external services) and enter the required services in the Program, Transaction, or Function Module Name field.
The service names must follow the naming convention <vendor>/<dc>/<Application>.
Example: sap.com/ess~us/Per_Address_US
What i understood is that we need to add all country specific services to the object S_SERVICE (Eg: sap.com/ess~us/Per_Address_US). is it correct?
Achim, if u've already done this, can u please elaborate this in detail

Similar Messages

  • Custom ESS/MSS ROLE under ADMININTRATION workset  - How to approach?

    HI
    Dear
    ESS/MSS Experts,
    We have a requirement with our client for a custom development ESS/MSS ROLE under ADMININTRATION workset for the functionality.
    ADMINISTRATION(workset)
    This workset provides administrative information regarding an employee. The services available under this workset are:
    INBOX(service)under--->This service will show the SAP inbox for an employee. The details shown on the screen are,
    u2022     Inbox
    u2022     Outbox private
    u2022     Shared
    u2022     Resubmission
    u2022     Trash
    how can i implement in portal...
    I am New From  Portal consultant so kindly please help me its very much helpful.
    Regards,
    Rafi Shaik

    inbox you meant UWL ie universal worklist
    first note that SAP provides standard roles and you can copy it to z role and modify it accordingly and remove the roles
    as per required/
    For ESS, the standard composite role is SAP_EMPLOYEE_ERP. You can make a Z copy of this role and customize it per your needs.
    http://help.sap.com/erp2005_ehp_04/helpdata/EN/a4/93554056bd1f24e10000000a1550b0/frameset.htm
    There is no standard role provided for MSS applications. You will need to build one as per your needs.
    See SAP Note 844639 for more details.
    http://help.sap.com/erp2005_ehp_04/helpdata/EN/a4/93554056bd1f24e10000000a1550b0/frameset.htm
    https://www.sdn.sap.com/irj/scn/wiki?path=/display/bpx/uwl+faq

  • ESS & MSS Role

    Hi Experts
    How to map ESS & MSS roles to ECC 6.0 Roles in EP.
    Say for example in ECC 6.0 we have a user A and User B.
    User A have some addtional attributes and User B does not have it
    How to map this two users in EP.
    Thanks
    Daya.
    Edited by: daya damu on May 27, 2008 8:27 PM

    Hi Daya,
    You will have to do the user mapping,
    It can be done in two ways,
    1. Go to user administration and once you enter user A, you will have an option of "User mapping".
    2. When you are logged onto the portal, click, personalize option and choose "User Mapping".
    User mapping is basically done when the portal users and ECC users are different.
    Let me know if you need any further clarification on the same.
    Cheers,
    Sandeep Tudumu

  • Under ess wdAbap role

    hi frnds,
                  we already installed the ess/mss ehp5 components in portal 7.01 ehp2. We have seen only overview,appraisal document , processes & forms iviews & pages under ess wdABAP role. I dont get any another iviews under this role. What about another iviews ?we want to implement the standard ess/mss applications to our client.    r there any another components installation required?  plz suggest me. our back end is Ecc 6.0 EHP5.
    waiting for ur valuable replies
    Thanks & Regards
    veeranji

    thank u siddhardh for your promt reply.
    can you provide any document how to add services to HR MENU.  and coming to portal r there any changes in configuring ess/mss? Previously we are activating JCO's  and assign roles to users.  But now we don't get jco's also after installing ess 1.50 components. I think no neccesity to activate the JCo's? If i am wrong, what should i do ?  suggest me.
    Thanks & regards
    veeranji

  • ESS Composite Role Adjustment

    Hi Experts,
    I have been trying to modify the Composite role SAP_EMPLOYEE_ERP for some functionality on portal. In tx OOAC, P_PERNR switch is activated (changed to 1) before this. First of all, I do not know whether the switch should be activated for ESS. But activation worked for me, and was able to get rid of one error. I followed this document for activating <a href="http://help.sap.com/saphelp_erp2005/helpdata/en/94/b8b83b5b831f3be10000000a114084/frameset.htm">P-PERNR</a>.
    I followed the guide lines in the help link, and made some changes in the
    <b>HR Master Data – Personal number Check</b> in the role Z_SAP_ESSUSER_ERP. I added the following profile:
    <b>Authorization Level: W (write access)
    INFOTYPE: 167 (Health plans)
    Interpretation of Assigned Authorization: E (excludes the right access)
    Subtype: BMER</b>
    I feel that should do trick: the user should not edit the Health Plan BMER on portal. Is it the right approach? It should overwrite the standard profile
    <b>Authorization Level: *
    INFOTYPE: 0002, 0005, .............., <b><i>0167</i></b>, 0168, 0169, ......
    Interpretation of Assigned Authorization: I
    Subtype: *</b>
    Any suggestions will be greatly appreciated.
    Thanks!

    Christopher,
    Ok.
    I managed to achieve the requirement. I am keeping the thread here as I do not know how to move threads.
    This is what I did.
    1. Authorization Level: W (write access)
    INFOTYPE: 167 (Health plans)
    Interpretation of Assigned Authorization: E (excludes the right access)
    Subtype: BMER
    2. Authorization Level: *
    INFOTYPE: 0002, 0005, .............., 0167, 0168, 0169, ......
    Interpretation of Assigned Authorization: I
    Subtype: *
    Profile 2 is overwriting the profile 1. What i did was in profile 2
    I removed the 0167 under INFOTYPE. made the profile 1 as follows.
    <b>Final </b>
    <b>1. Authorization Level:R (read access)
    INFOTYPE: 167 (Health plans)
    Interpretation of Assigned Authorization: I (incldue )
    Subtype: BMER
    </b>
    I did the trick. The user is able to view the benefit plan not edit. the system throws a message "you are not authorized to do this" if he tries to edit. However it is one way of restricting the user. might be not elegant. but quick.<i></i>

  • ESS- User Roles

    Hi Experts
    I am using ECC 6.0 and ESS 7, for SAP Gui (R/3) also we are using Portal, means as per the user roles assigned in R/3, user is able to view different services of R/3 in portal with ESS.
    For ESS I am using all the three standard roles of ESS i.e.
    SAP_ESSUSER
    SAP_ESSUSER_ERP05
    SAP_ESSUSER_ERP
    but when I had assigned all these roles to a user and accessing the ESS I am facing the following error:
    com.sap.tc.webdynpro.services.exceptions.WDRuntimeException: ComponentUsage(FPMConfigurationUsage): Active component must exist when getting interface controller. (Hint: Have you forgotten to create it with createComponent()? Should the lifecycle control of the component usage be "createOnDemand"?
    Plz help me in this regard
    Thanks in advance
    Sheetal Gupta

    Hi Sheetal,
    try to give....only one role..i.e SAP_EMPLOYEE_ERP or SAP_ALL  and check it..
    it could also may be poss thatt user is locked in backend....
    u also need to assign ESSUSER group to user..
    regards
    Jigar Oza

  • Best Practice for ESS/ MSS role customization

    Hi ,
    I would want to know the best practice for role customization for ESS / MSS business package . For eg if my company does not want to use someof the workset like working time , travel etc , what is the best practice for this scenario .
    anEEZ

    Hi Aneez,
    This is the link for complete best practices on NetWeaver
    http://help.sap.com/bp_epv260/EP_EN/index.htm
    Browse the Busines scenarios, you will find what you are looking for.
    Now, these ones is specific for ESS and MSS
    http://help.sap.com/bp_epv260/EP_EN/html/EP/N26_ESS.htm
    http://help.sap.com/bp_epv260/EP_EN/html/EP/N27_MSS.htm
    Hope this helps,
    Kumar
    P.S Reward Points for useful answers.

  • R/3 Security roles versus ESS Security Roles?

    Hello Experts,
    I am not a security person, but we are in the process of testing ESS and having some conflicts with a users GUI (r/3) role versus the ESS role!  For example, a user will not have access to Bank Information (Infotype 9) in the GUI, but will need access to edit this Infotype through ESS on their own record.
    Our problem is how do we set the roles up under this scenario? If this cannot be done, how do other companies handled this scenario?
    Any direction will be highly appreciated.
    ECC 6.0
    EP 7.0
    ESS 1.0
    Thanks for your time,
    Mike

    Hi Mike,
    My suggestion would be to make use of P_PERNR in your ESS role only - and not P_ORGIN or P_ORGINCON.
    We added all the info types that the ESS users are supposed to maintain or view in P_PERNR.
    We did eventually need to add display and matchcode search for info types 0000 - 0002 so that the ESS users could make use of the Who's Who functionality in order to search for emloyees across the organisation.
    Without info type 0009 in a P_ORGIN or P_ORGINCON auth object, the users will not be able to maintain in PA30.
    Hope this helps.
    Regards
    Lucille

  • ESS Customized Role - iView appearing twice

    Hi Experts!!
    We have created a new ESS role which has a customized Travel & Expenses workset (page and iview also cust). When we assigned this new role to a user, we see that when clicked on Travel & Expenses it is showing the page with two iview (it is assigned so - Travel & Expenses and My Alerts) with all subareas. Now I enter into My Trips under Travel & Expenses and from there Exit. Now it is showing only Travel & Expenses (but not My Trips) and that too twice...one below the other.
    I have checked configuration in R/3. it seems fine. Can somebody suggest me where it went wrong? Am I missing something?
    Your help is highly appreciable. Thanks a lot.

    Assigning to several groups should not affect in anyway, as far as i know.
    However, the issue is resolved. In SPRO, under Resources, we have a checkbox PCD Page Static. This was unchecked. Just on trial and error basis, I checked it and tested and surprisingly this worked. As I was not sure about the significance of this check box, I never bothered about this. I will try to go through the significance of the same.
    Thanks to all.

  • ESS / MSS Roles

    Dear Gurus,
    Iam basically a HR Technical, now moved into functional role.
    I need to know how to set one as ESS user or MSS user.
    This  will be of which part of implementation, will that be the intial stage of realisation?
    Please help me with some examples how to create a ess user
    I know the relationship will be made at Communication Infotype (105)
    my mail id is:  [email protected]
    Thanks in Advance
    Sera
    Message was edited by:
            Sera

    Hi Sera,
    To assign Personnel number in R/3 to your portal user:
    1) Your portal user is mapped to your R/3 user.
    2) Login in R/3 system using your user and password,
    3) Goto PA30 and enter pernr you want to assign to your user,
    4) Create a record for infotype 105 and subtype 0001 and enter your user name there.
    5) save the changes.
    This assigned pernr to your user will be ESS / MSS user when you log in to portal.
    Hope this helps !!
    Regards,
    Ruchi

  • Automation of assignment of ESS & MSS roles

    We are implementing ESS and MSS as part of our global HR implementation. What i am thinking of is to look for methods to automate the assignment of ESS role once the HR master record is created for an employee and MSS role once the chief relationship is established for the corresponding org unit.
    Does anyone out in the field had done anything similar? If so,could you please share your experiences/lessons learned etc??
    Thanks
    Sarada Ganti

    You have not mentioned the method of role assignment, ie direct/indirect so I assume you are using both.
    You can automate the role provisioning without any problems for ess roles  directly assigned to the ess user in SU01 - this is because the steps involved are easier to script.
    Problems arise when automating the role provisioning for mss users that are indirectly assigned to their mss role through the position.  The steps for administering indirect role assignments are not so straight forward and involve the running of RHRPROFL0 which needs to be maintained with key parameters to link the mss role to the position that the new manager is assigned to.
    In the end we decided not to use indirect assignments because of this reason.  The various scenarios was too difficult to script for the provisioning tool Tivoli (ITIM)
    Hope this helps.
    Regards
    Charmaine

  • ESS UI5 role import problem on Portal

    Dear Gurus,
    I have tried to import pfcg role for ess ui5(SAP_EMPLOYEE_ESS_UI5_1) into portal, it is not importing and not giving any errors as well.
    other than ESS all are importing into Portal.
    My Portal Version is NW7.4 and ECC 6.0 EHP7 HR Renewal FP 04.
    could any one please suggest why this is happening. In Sandbox and development is working where as QA is getting problem.
    Thanks in advance .
    Regards,
    cbr.

    Hi,
    Have you checked the gateway error log, transaction - /IWFND/ERROR_LOG as this should identify what is missing  (under the menu option 'Error Log > Global Configuration you may want to change the error log level to 'Full' otherwise some detail is hidden).
    Have you activated the TASKPROCESSING Odata service?
    This thread may help UI5 Approval - Missing OData Service TASKPROCESSING
    I am also having issues with the Approvals lane when I lauch the tasks that I have just raised a thread for.
    Regards
    Jon

  • Customizing SAP ESS Portal Role

    Hi,
    I need to customize the ESS portal screens.  For example, I need to view "Employee Search" tab but not the "Working Time" tab.  Is advisable to modify the ESS Worksets provided by SAP directly and remove the workesets, pages that I do not need? 
    The approach I took was to create a new role and workset and include the SAP pages I needed.  However, this gives me problems when I acess the iviews.  For example, when I click on the "Who's Who" link, nothing happens.
    Can anyone help?
    Thanks.

    Sudhir,
    You mentioned to "change the Role location of each resource in backend ESS configuration".  Which resources do I change. 
    For e.g.,  I created an "Employee Self-Service" role and an "Employee Self-Service" workset.  Now in my "Employee Self-Service" workset, I referenced SAP's "Employee Search" workset.  What do I need to change?
    Thanks,
    Basant
    > You need to copy standard role and then put
    > iviews/pages in concerned order/page.
    > moreover you ned to change Role location of each
    > resource in backend ESS configuration.
    >
    > Well removal of certain tabs can be achieved using
    > service/Subareas config in ESS. Please check IMG ESS
    > config node for more details.
    >
    > Hope this helps.
    > Regards,
    > Sudhir

  • ESS/MSS Role : Employee Search

    Do I have to give * in IT0001 and IT0002...etc for Auth objects in ECC for Employee Search in ESS/MSS to work ?
    Kindly help.....

    hi
    you need not give * , but for search helps you have to provide M along with the other auth options.
    Regards
    sameer

  • ESS missing roles

    Hi,
    I have deployed the following packages:
    - ESS14_0-10002965.sca
    - PCUIGP014_0-20000568.sca
    - MSS14_0-10002964.sca
    I´ve deployed them with SDM with no problems.
    After the deployment I went to the portal and starting looking for the roles and they are not there so I went to webdynpro console to see if the jco were there to be created and they were there and the packages too.
    If I log into the SDM i can find in the repository the packages and it do not let me install it again because it shows that i have it already installed.
    Any idea about this? How do I find the XSS roles?
    Thanks,
    Edu
    Message was edited by:
            Eduardo Fagundes

    Hi James,
    My e-mail is [email protected]
    While i´m waiting the docs, i´ll try the steps you described.
    But i think this is not the problem because the roles there i´m talking about is the portal roles and one doc that i have says to me that after i deploy with SDM i should be able to see the files in the portal content -> Content Provided by SAP -> End user, and there is no package there only "Standard Portal Users".
    Any idea?
    Thanks in advance!
    Edu

Maybe you are looking for