FM to create role derived from other role

Hi,
I have to create roles derived from other roles. i need FM which can create roles derived from other roles. can anybody help me.
Thanks in advance.

Try BAPI_BUPA_ROLE_ADD_2
Refer: http://abap.wikiprog.com/wiki/BAPI_BUPA_ROLE_ADD_2

Similar Messages

  • ERP Mass Role generating from master role.

    Hello
    In our ERP system we have several master roles and lots of roles derived from those masters. My question is when I add a transaction or even change one authorization object I have to manually generate all of those sub roles.
    How can I do "copy from master role" then regenerate and then compare users more easily? Editing hundreds of roles takes lots of time.
    I know PFCG has option Mass Compare and Mass Generate but they are not working for those sub roles.
    Thanks

    Hi,
    Please go through help.sap.com or google to search and understand the process of creation/generation of master-derived roles:-)
    If you have master -derived role created in system, you do not need to generate each individual roles. Just go to change mode of Master role in Authorization tab and beside "Generate" button at the top, you also see an icon "Generate derived role" (CTRLSHIFTF4 is the shortcut key) which can be used to adjust-derive all derived roles inheriting all characteristics of the master role into the derived roles (except the organizational values in case they are separately maintained in the derived roles)
    Thanks
    Sandipan
    Edited by: Sandipan Choudhury on Mar 18, 2011 2:53 PM

  • Can not open JPEG files and can not create JPEG files from other software

    Can not open JPEG files and can not create JPEG files from other software (For example from Solidworks).
    When I try to right click on a JPEG, a notice window appears written: "Windows Explorer has stopped working - Windows is
    checking for a solution to the problem" and then the notice box disapears, the desktop appears and I can continue working.
    From the other side - If I try to save as JPEG a screen of Solidworks (like a view of a part) the Solidworks falls but the JPEG
    is created (I can see its name in the directory I created it).
    I can open the JPEGS with the Paint software if I want but not with the Windows Photo Viewer.
    I have the feeling that the Windows Photo Viewer disapeared from my computer - just a feeling.
    I will appreciate your assistance.
    Avi T. 2014

    Hi,
    Did Windows Photo Viewer option appear when you right click the JPEG file and select open with?
    I would like suggest you use Clean Boot to troubleshoot if there is third-party software conflict:
    How to perform a clean boot in Windows
    http://support.microsoft.com/kb/929135
    Karen Hu
    TechNet Community Support

  • "Create Simple document" from other objects

    Scenario: Creating a document using option "Create Simple document" from other objects
    I have created a document type and defined the object link for Functional Location with option "create simple document"
    When clicking on create icon on the additional data tab on IL02 screen, The system asks for the document type and then the file to be uploaded.
    The document type that i have defined has the Description filed as mandatory field and hence i am not able to create the document.
    However, for the Document type when i set the description field as not mandatory the system creates DIR. But this DIR has no description.
    Please let me know if there is a BADI, using which i could set the Functional location name as the description OR if there is some enhancement by which the user is asked to enter the description when creating the document.
    Warm Regards,
    Vivek Mohankumar

    Hi Vivek,
    After my tests I would like to inform you that this is                  
    the standard system behavior as the document description field is       
    maintained as mandatory in transaction DC10. Please note that for the   
    simple creation of documents this should not be set as a mandatory      
    field.                                                                               
    The creation mode can be defined in transaction DC10 for each object    
    under 'Define object links'.                                                                               
    Please note that the value "1" for the creation of documents is used    
    to enable a user to simple attache a word file to an object             
    without going to the transaction CV01n. Therefore the system behaviour  
    is different then creating a document by CV01n and attaching a          
    file to it. With simple creation mode there should not be any           
    mandatory fields as the user cannot enter anything during the creation  
    process.                                                                               
    However, you can change the behaviour how the document is created by    
    MM02 transaction if you change the customizing in transaction DC10      
    like this:                                                                               
    If you maintain the value "2" for creation of documents, the user is    
    put to transaction CV01n and then the description can be entered. So    
    maybe this would solve the issue.  
    Regarding a useful BADI I can only recommned you to test BADI DOCUMENT_OBJ1,
    DOCUMENT_OBJ2 or DOCUMENT_MAIN01 for fill the description field.
    I hope this information could be useful for you and help to avoid the   
    mentioned error message.                                                                               
    Best regards,
    Christoph

  • Creating single role by copying profiles from other roles

    HI ,
    I am creating a single role from 4 roles. Ihave copied the authorizations of 4 roles and added into the new role. This is done by copying the profiles.
    Problems Faced :-->
    1. )In table AGR_TCODES i am not able to see the Tcodes for this new single role present in  the new role, whereas if i goto object S_TCODE i am able to see tcodes and have that access.
    2.) Some of the objects are not copied into this new role. Even from the roles whose all other objects are copied into this role.
    Can anybody help me on this and also if someone knows what other problems can be faced by doing this.
    <removed_by_moderator>
    Thanks,
    Rajesh
    Edited by: Julius Bussche on Oct 15, 2008 3:55 PM

    Hi Rajesh,
    If you have created a role by copying authorizations, then it is possible to get the t-codes provided your role contains the auth.obj S_TCODE which you might have copied manually from one or two among the 4 roles.
    If S_TCODE exists in your role then you can find out the t-codes belonging to this role through SUIM->Transactions->Executable for Roles-> Insert your role name
    or
    Go to SE16-> Table AGR_1251->
    In the field AGR_NAME, give the role name
    In the field OBJECT, enter S_TCODE and then
    Execute.
    Q.My second question THere is one role created by some user I am checking it in AGR_Tcodes and SUIM ....I am finding that the no. of Tcodes in both cases donot match....Can anybody tell where i can look for this and what is the possible reason.
    Possible reasons for this could be that some of the t-codes have been entered into the role manually and not through the menu in PFCG and as mentioned earlie that AGR_TCODES only shows the transactions that exists in the menu of the role.
    It could also be that the manually entered t-codes contains wildcards specifying a range of values.
    The best option would be to find it out from the AGR_1251 table.
    Hope this helps !
    Thanks,
    Saby..

  • Org data in Derived role differ from Parent role

    Hi there
    I need some help please, I am in the process of creating various parent / derived roles and have found that when I update the parent role (org data) and I do a generate do a derived role update the values in the org data is not correctly pulled through to the derived roles.
    e.g.
    In the parent role for Org data "Purchase Org" the previous value was "/" so that it could be specified in the derived roles should they require the split on this field, however the business has decided that they do not require a restriction on this field so I went back to the parent role and changed the value to "*", so I generated the parent role, updated the derived roles, but when I go to any of my derived roles that field value is still blank, it did not pull through the value * .
    We are currently on
    SAP_ABA  701           0005    SAPKA70105
    SAP_BASIS  701        0005     SAPKB70105
    I have created the derived roles with the parent role as the derived from role, it does pull through the values but just does not update it once I do make changes.
    Your help / suggestions would really be appreciated as I need to create MANY roles.
    Regards
    Sonja

    Hi Sonja,
    obviously there is a misunderstanding of how the derivation works....
    > Thanks guys for the feedback, but surely I do not only need to maintain the ORG data in the derived roles individually, if I have got an Org field that should be the same for all the derived roles I must be able to update the Parent role with this value which then upon generate, and generate / activate the derived roles must update the derived roles.
    -->no.
    Only the first time of derivation, if the field content in the derived roles are initial...
    help.sap.com:
    quote
    The organization level data is only copied the first time the authorization data is adjusted for the derived role. If data is maintained for the organizational levels in the derived role, and if you have maintained the organizational levels using the dialog box, the data is not overwritten by another conciliation (See SAP Note 314513).
    unquote
    The whole stuff:  http://help.sap.com/saphelp_nw70ehp2/helpdata/en/1c/c38028816c11d396bc0000e82de14a/frameset.htm
    otherwise the maintained org.fieldvalues would get overwritten by the value of the master role every time. And that is exactly, what has to be avoided!
    b.rgds, Bernhard

  • What's manageddisabledrole different from other role?

    I tried to understand what exactly the manageddisabledrole is different from other custom role? Maybe some ACL controls this role? How does the users got disabled by being a member of this role?
    So if i don't like the manageddisabledrole, can i create a new role and make it function just like manageddisabledrole?
    Anyone here gives me an insight to this? I cannot find any docs that explains about this.
    Thanks

    Thanks for your reply, but I'm still confuse. I still
    have few more questions to be clarify.
    1. By definition, CoS allows you to share attributes
    between entries. In this case, the
    nsAccountInactivation_cos shares the nsaccountlock
    attribute between entries. Is this correct?Correct.
    2. If so, where do I find the template entry? If it
    works right, the template entry must have the
    atttribute nsaccountlock with the value = true in it.
    How do I locate this template entry in the
    directory?CoS and Role definition and template entries usually have objectclass ldapSubentry - this is a special objectclass used to create administrative entries (like operational attributes, only entries). In order to do a search to find these entries, you must include the filter (objectclass=ldapSubentry) in your search request. So, if you wanted to find these definitions under your suffix, do a search like this:
    ldapsearch -s one -b dc=yoursuffix,dc=com -D "cn=directory manager" -w password "objectclass=ldapSubentry"
    The CoS template entry is as specified in the CoS definition entry:
              cn="cn=nsDisabledRole,<your suffix>",cn=nsAccountInactivationTmp,<your suffix>"
    3. How does this nsAccountInactivation_cos CoS
    related with the nsManagedDisabledRole role? I don't
    see any relationship between these two. Maybe I
    still don't understand well about Cos and Role.They are not easy to understand, but then, many powerful features are not easy to understand at first.
    >
    Thanks alot

  • How to delete a role from other role.....

    Hi All,
    I have a query like....
    I have created one new role ATH:MDC:INV3 and added two existing roles to that new role on DEV system ie Added ATH:MDC:INV2 + ATH:PUR:PMG0
    So,now i need to remove only one role ie ATH:PUR:PMG0 from ATH:MDC:INV3.
    All the 3 roles are single roles.
    Is there any way to remove/delete that role or do we need to do manually by deleting one by one authorisation,which is time taking process....
    Please give me if there could be any better way to approach....
    Thanks & Regards,
    Swapna.D
    Edited by: swapna devi on Feb 1, 2008 3:53 AM

    Doug,
    You gave me an idea. What if you create a new folder on the desktop. Select the roll above #20, which you said will also select #20, and move that roll to the desktop folder? Will roll #20 move with the one above it? If so, then you could go back to iPhoto, drag them both to the trash, delete trash (will it delete with the roll above it?), Import to Library the pictures where you put them on the desktop.
    Caution, you would probably lose some of the info from the roll you delete and re-import, like their dates, etc. So I wonder... can you select, say, half the photos in that roll and Create New Roll? Will the remaining roll still be linked to #20? If so, can you do it again and again until the linked roll only contains 1 picture? Then move it to desktop, trash in iPhoto, and re-import?
    What happens if you play with it like that?

  • Why Oracle removed "Create View" privilege from "Resource" role?

    Seems like a silly question, but does anyone know why?

    >
    Hm.. deprciated and replaced by what? I know they trimmed CONNECT a lot but only create view seemed missing from RESOURCE.
    >
    Replaced by NOTHING. They didn't just 'trim' CONNECT; it only has the CREATE SESSION privilege now.
    The only published info I've seen are these two notes in the Oracle is this from the Database Security Guide.
    http://docs.oracle.com/cd/B28359_01/network.111/b28531/authorization.htm
    >
    Note:
    Each installation should create its own roles and assign only those privileges that are needed, thus retaining detailed control of the privileges in use. This process also removes any need to adjust existing roles, privileges, or procedures whenever Oracle Database changes or removes roles that Oracle Database defines. For example, the CONNECT role now has only one privilege: CREATE SESSION. Both CONNECT and RESOURCE roles will be deprecated in future Oracle Database releases.
    Note:
    Customers should discontinue using the CONNECT and RESOURCE roles, as they will be deprecated in future Oracle Database releases. The CONNECT role presently retains only the CREATE SESSION privilege.

  • Creating a property with list values derived from other hierarchy

    Hello Friends,
    Thanks in advance for any help in this regard.
    1)     Can we have a property with list values populated automatically from other hierarchy.
    2)     Can we select multiple items from the list box. Does property allows multiple values.
    The example is like this. There are 2 hierarchies.
    Customer
         Customer 1
         Child Customer
    Industry
         Hightech
         Computers
         TVs
    Manufacturing
         Auto
         Steel
         Healthcare
         Pharma
         HealthInsurance
    The requirement is to add Industry hierarchy as property of Customer Hierarchy and select each customer is what type of Industry they belong as a property value.
    Thanks

    Use property data type ListGroup for multiselect.
    To select values from another hierarchy you can use Node or MultiNode, or an Asscociated Node property, of which there are several types. I'm not fond of the property editors for Node data types and will often just use a string and validate the user input by defaultin prefixes and such with a derived property that is checked by a query based validation. Make sense?

  • How to create an ImageIcon from other ImageIcon's part?

    I have an ImageIcon instance and want to create an other one from the specified part of the initial icon.
    How can this be done??
    Thanks. Boris.

    If I were you, I would create a BufferedImage and paint the ImageIcon into it. You have the choice of either :
    - in the paint method itself, modify the clip bounds so as to make it only paint the desired region
    - or paint the image completely and then use BufferedImage's getSubimage method
    Either way, you'll get a BufferedImage that you can use to create your target ImageIcon

  • How to set a sub-role invisible from the role

    Hi guys,
    Our roles are as following:
    Role1
    App1
    App2
    SubRole1
    SubApp1
    SubApp2
    We've assigned SubRole1 to Role1, but we don't want it is shown under Role1, how to set it?
    Many Thanks and Best Regards,
    Xiaoming Yang

    Hi,
    If you do not need these applications/iViews in the navigation hierarchy, then you do not have to do any fancy tricks.
    If all Role1 users should get subRole1 iViews, then just have one role and make those iViews invisible.
    If you want to be able to assign the iViews in subrole1, just create a second role with no entry point (it does not need to be a subrole) and set the permissions so there is no end user permission, and then assign it to users.
    Hope that helps.
    Daniel

  • Creating an ImageIcon from others ImageIcon

    Hi,
    I want to write a method that create an ImageIcon object from two ImageIcon objects passed.
    ImageIcon createImageIcon(ImageIcon img1, ImageIcon img2) {
    ImageIcon img;
    return img;
    The returned ImageIcon displays as the two img1 and img2 placed side by side.
    Thanks very much,
    Charly

    Thanks to camickr and stevops,
    this is my working method (mainly the camickr code).
         public static ImageIcon createImageIcon(ImageIcon icon1, ImageIcon icon2) {
              int width = Math.max(icon1.getIconWidth(), icon2.getIconWidth());
              BufferedImage image = new BufferedImage(width, icon1.getIconHeight() + icon2.getIconHeight(), BufferedImage.TYPE_INT_RGB);
              Graphics g = image.createGraphics();
    //          g.drawImage(icon1.getImage(), 0, 0, icon1.getIconWidth(), icon1.getIconHeight(), null);
    //          g.drawImage(icon2.getImage(), 0, icon1.getIconHeight(), icon2.getIconWidth(), icon2.getIconHeight(), null);
              icon1.paintIcon(null, g, 0, 0);
              icon2.paintIcon(null, g, 0, icon1.getIconHeight());
              g.dispose();
              return new ImageIcon(image);
         }Bye

  • How to create view/table from other user's view/table

    Hi all
    I'm using Oracle database 10g.
    I create table/view on user XXX, how to I create table/view on user YYY from user XXX.
    Thankyou,
    Thiensu2810

    user8248216 wrote:
    Hi all
    I'm using Oracle database 10g.
    I create table/view on user XXX, how to I create table/view on user YYY from user XXX.
    Thankyou,
    Thiensu2810grant select on xxx.table_name to yyy;
    create table/view table/view_name as select * from xxx.table_name;

  • Assigning Admin role or any other role to Unity Connection user

    How do I assign a role to a user. I`ve given them the admin role as an example but can not log in . What is the GUI log on details I should use Alisa, Extension etc but no luck. The password I`m also using is the VM PIN I use to listen
    thanks

    Chris,
    I`ve sorted it now, I was looking for as separate ssection for PIN and password , I  didn`t realise that they are under the same heading but separated by the drop down menu - Web and VM application
    thanks for your help

Maybe you are looking for