Limited access group for some switches only

Hi ,
We have around 80 x cisco 3750 switches using AAA Windows Radius server and AD as authentication for IT users login.
How do we setup a limited access group which allow them to access some switches ONLY?
Any advice is very much appreciated.
Thanks
Qle

Well its Prod (you have a dashboard called testdashboard in Prod?) anyway - someone might have changed the presentation catalogue permissions on the dashboard. All it takes is for someone to remove 'Everyone' or change a Group permission and it could effect.
If they changed the Parent folder and cascaded the changes down this might cause this issue.
You have a folder called 'Shared' - check the groups that the people are in have 'Traverse' , 'Read' or higher. Also chek dashboard permissions themselves from Settings-Manage Interactive Dashboards - Check the Padlock icon.
Are you users getting allocated into the correct WEBGROUPS ? Is this assisngment done explicitly in the webcat or via an RPD Variable ? Have you checked NQQueryl.log to make sure any init blocks are completing successfully?
Either persmissions have changed or group memebership is not completing.
Good luck
Alastair

Similar Messages

  • OBIEE access denied for some users only

    Hi All,
    we are using OBIEE 10.1.3.4 version on windows envorinment .The users can access the OBIEE reports using 'PORTALPATH' session varible in RPD.For some of the users are got "access denied" while they are accessing for thir particular dashboard.Eariler these user got access this dashboard with out any errors.We dnt changed in our system anything from last three months.
    We have no idea why we are getting these error for particular users only.Its Prod issue we need to reslove these error ASAP.
    we are getting these error"acess denied for user to path/shared/shared/_test/testdashboard
    Error Codes:09XNZMXB"
    but last one year its working without any issues .From our side we dnt did any changes in production like RPD level,Catalog level and config file changes , we have no idea why suddenly we are getting these kind of error for some users only not for all users.
    Could u please advice me how to reslove this PROD issueASAP.
    Thanks,

    Well its Prod (you have a dashboard called testdashboard in Prod?) anyway - someone might have changed the presentation catalogue permissions on the dashboard. All it takes is for someone to remove 'Everyone' or change a Group permission and it could effect.
    If they changed the Parent folder and cascaded the changes down this might cause this issue.
    You have a folder called 'Shared' - check the groups that the people are in have 'Traverse' , 'Read' or higher. Also chek dashboard permissions themselves from Settings-Manage Interactive Dashboards - Check the Padlock icon.
    Are you users getting allocated into the correct WEBGROUPS ? Is this assisngment done explicitly in the webcat or via an RPD Variable ? Have you checked NQQueryl.log to make sure any init blocks are completing successfully?
    Either persmissions have changed or group memebership is not completing.
    Good luck
    Alastair

  • Access Connections Ethernet Location Switching only saves one port at a time

    Like many other people, I cannot get automatic location switching between two Ethernet networks to work properly.
    I have two stored network locations;  one for home and one for work.  Both of these are set up as Best Available Network with both Ethernet and Wireless.
    Under Tools - Location Switching, both networks are listed, and "Include Ethernet connections in automatic switching and prompt me to save Ethernet ports"  is checked.    However, in the details column, the current location has 1 saved port(s), and the other has 0 saved ports.    The saved port is always the one most recently connected.  
    If I go to Edit Saved Ports, only one location is listed, with the correct IP address and MAC address for the router.   If I connect at the other location, only that location is listed, again with the correct IP address and MAC address.
    The router IP addresses are different (work is 192.168.0.1, and home is 192.168.1.254), and obviously the MAC addresses are different, so it should be possible for Access Connections to distinguish them.  Unfortunately the only "editing" that is possible is to delete the saved port.  I would be happy to add a saved port manually, but that is not an option.  In addtion, despite the "...prompt me to save Ethernet ports" being checked, I have never received a prompt.  Even if I delete the saved port, it resaves automatically next time without any prompt.
    I have also tried setting up both locations as Ethernet only, but have exactly the same problem.
    My T520 was supplied with Access Connections 5.85 preinstalled.  I tried upgrading to 5.97 in the hope that it had been fixed in the meantime.  Unfortunately it has not.
    Access Connections is still marginally useful to me for automatic switching between Wireless and Ethernet, and for a simple manual switch of settings such as default printer, home page, and file sharing.  However, it would be very useful for the home and work locations to be autodetected and switched.  
    From the number of unresolved questions on this board on the same topic, it appears that this is a long standing deficiency with Access Connections.  Is there any chance of this being fixed?

    I found from another bulletin board that ethernet location switching seemed to work OK with Access Connections 3.82, but stopped working with releases after that, and from my experience still does not work with 5.97
    http://www.thinkpads.com/forum/viewtopic.php?f=18&t=38514
    Two questions:
    1. Does anyone know if Access Connections 3.82 works with Windows 7?
    2. If so, where could I get a copy?  The oldest version on the Lenovo website appears to be 5.50
    I will refrain from commenting on the necessity of going back to such an old version to recover basic functionality for this utility......

  • Keyboard malfunction for some keys only

    I'm using an HP G61-410EL laptop model for more than 1 year but suddenly the keyboard not functioning for some keys for B,N,Alt Gr,@..can anybody please advise me what to do?is it a hardware problem or a software problem for my keyboard??
    thanks,
    jay

    Dear Customer,
    Welcome and Thank you for posting your query on HP Support Forum
    It looks like you are having issues with the Keyboard on your Notebook.
    We will surely assist you with this.
    Troubleshooting: 
    Step 01. Click on the Start Button and go to Control Panel
    Step 02. Open the Device Manager and expand the Keyboard from the list
    Step 03. Right click on Standard PS/2 Keyboard and click on Uninstall
    Note: This driver will get installed again automatically on your Notebook
    Step 04. Please turn OFF the Notebook
    Step 05. Un-plug the Power/AC Adapter and also remove the Battery too
    Step 06. Press and Hold the Power Button of the Notebook for a full minute
    Step 07. Now let's re-insert the battery back in and plug back the Power/AC Adapter
    Step 08. Start the Notebook and keep tapping F10 Key during the startup to access the BIOS
    Step 09. Once you get to the BIOS, Please press F9 or F5 Key[Model specific] to load setup defaults for the BIOS
    Step 10. Use the arrow keys to say "YES" and hit enter
    Step 11. Now let's press Esc/Escape Key. Save Changes and Exit - Yes
    Step 11. Now please wait till the Unit loads the Windows Operating system
    If the issue still persists please check and verify if an External Keyboard works fine with your Notebook
    Note: Please click on the below shown link to find more troubleshooting steps
    http://h10025.www1.hp.com/ewfrf/wc/document?docname=c03738933&tmp_task=solveCategory&cc=us&dlc=en&lc...
    Hope this helps, for any further queries reply to the post and feel free to join us again
    **Click the KUDOS star on left to say Thanks**
    Make it easier for other people to find solutions by marking a Reply 'Accept as Solution' if it solves your problem.
    Thank You,
    K N R K
    Although I am an HP employee, I am speaking for myself and not for HP

  • CISCO 3750X stacking for 5 switches , only 4 switches are coming in stack

    Dear All,
    I have 5 cisco 3750X switches ,but only 4 switches coming up 5 switches i am unable to see .
    Connection for the switch :Please find the attached snapshot for the stack data connection .
    Also find the snapshot for the stack power connection .
    Please provide your assistance and support to overcome this issue .

    Dear Marvin,
    Thanks for your reply.
    is my connection provided in attachment for data stack are ok .
    i login to Switch # 5 through console 
    following is the result :--
    switch: ?
               ? -- Present list of available commands
             arp -- Show arp table or arp-resolve an address
            boot -- Load and boot an executable image
             cat -- Concatenate (type) file(s)
            copy -- Copy a file
          delete -- Delete file(s)
             dir -- List files in directories
      flash_init -- Initialize flash filesystem(s)
          format -- Format a filesystem
            fsck -- Check filesystem consistency
            help -- Present list of available commands
          memory -- Present memory heap utilization information
        mgmt_clr -- clear management port statistics
       mgmt_init -- initialize management port
       mgmt_show -- show management port statistics
           mkdir -- Create dir(s)
            more -- Concatenate (display) file(s)
            ping -- Send ICMP ECHO_REQUEST packets to a network host
          rename -- Rename a file
           reset -- Reset the system
           rmdir -- Delete empty dir(s)
             set -- Set or display environment variables
          set_bs -- Set attributes on a boot sector filesystem
       set_param -- Set system parameters in flash
           sleep -- Pause (sleep) for a specified number of seconds
            type -- Concatenate (type) file(s)
           unset -- Unset one or more environment variables
         version -- Display boot loader version
    switch: version
    C3750E Boot Loader (C3750X-HBOOT-M) Version 12.2(58r)SE, RELEASE SOFTWARE (fc1)
    Compiled Tue 26-Apr-11 06:59 by abhakat
    switch: boot
    Loading "flash:/c3750e-universalk9-mz.122-58.SE2/c3750e-universalk9-mz.122-58.SE2.bin"...flash:/c3750e-universalk9-mz.122-58.SE2/c3750e-universalk9-mz.122-58.SE2.bin: no such file or directory
    Error loading "flash:/c3750e-universalk9-mz.122-58.SE2/c3750e-universalk9-mz.122-58.SE2.bin"
    Interrupt within 5 seconds to abort boot process.
    Boot process failed...
    switch:
    All other 4 switches i can see in stack but not these switches and also the status light for this switches is blinking green  please provide your assistance .

  • Snow Leopard Finder's Get Info fails to show Owner and Group for some files or folders which reside on a Shared Volume, hosted by G5 Server w/ OS 10.4 - why?

    Frustrations with file permissions abound, as certain co workers are unable to manually determine their level of permission or who to ask to make changes to files and folders belonging to others. Users of Snow Leopard desktop OS get unhelpful feedback via Finder's Get Info, seeing only the permissions listed for "Everyone" and a statement that "You have custom access".  The custom message exists, presumably, because ACL's are employed on the shared volume in an attempt to give managerial control over these volumes to specific users, even if all users can create files and folders on those volumes.
    Shared volumes are partitions of an external RAID which are set up as sharepoints on a G5 tower running Server 10.4.  Other persons in the office, using machines that are running desktop OS 10.5, can correctly see the assigned Owner and Group permissions (although the "custom access" still shows).  This at least lets the 10.5 user know who created a given file or folder, so that they can resolve permissions-restricted issues if they come up (i.e. User A wants to delete file X, but as it was created by User B, A must contact B and have them delete it.  In 10.6 it appears that A cannot determine who B is).
    I know that ACL's are functioning (enabled on the drive) since we have been making use of ACL-granted write privileges for quite a while (and the custom access seems to be evidence too).
    An error I encountered, pertaining to this, is that I used a 10.6 machine to create a working folder, then generated and saved several files in this location.  Expected permissions thus would be Owner = me (i.e. the user I was logged in as), R/W, Group = staff, R only, Everyone = R only.  However, immediately the permissions shown in Finder / Get Info consisted only of Everyone = R only, with no entry for Owner or Group.  Moreover, clicking + to add either an Owner or a Group resulted in error message that I had entered an invalid user or group, even though I typed in correct info (such as trying to add "staff" as a group).

    Frustrations with file permissions abound, as certain co workers are unable to manually determine their level of permission or who to ask to make changes to files and folders belonging to others. Users of Snow Leopard desktop OS get unhelpful feedback via Finder's Get Info, seeing only the permissions listed for "Everyone" and a statement that "You have custom access".  The custom message exists, presumably, because ACL's are employed on the shared volume in an attempt to give managerial control over these volumes to specific users, even if all users can create files and folders on those volumes.
    Shared volumes are partitions of an external RAID which are set up as sharepoints on a G5 tower running Server 10.4.  Other persons in the office, using machines that are running desktop OS 10.5, can correctly see the assigned Owner and Group permissions (although the "custom access" still shows).  This at least lets the 10.5 user know who created a given file or folder, so that they can resolve permissions-restricted issues if they come up (i.e. User A wants to delete file X, but as it was created by User B, A must contact B and have them delete it.  In 10.6 it appears that A cannot determine who B is).
    I know that ACL's are functioning (enabled on the drive) since we have been making use of ACL-granted write privileges for quite a while (and the custom access seems to be evidence too).
    An error I encountered, pertaining to this, is that I used a 10.6 machine to create a working folder, then generated and saved several files in this location.  Expected permissions thus would be Owner = me (i.e. the user I was logged in as), R/W, Group = staff, R only, Everyone = R only.  However, immediately the permissions shown in Finder / Get Info consisted only of Everyone = R only, with no entry for Owner or Group.  Moreover, clicking + to add either an Owner or a Group resulted in error message that I had entered an invalid user or group, even though I typed in correct info (such as trying to add "staff" as a group).

  • How to Avoid Grouping for some conditions?

    Hi,
    I am facing a problem in Sales_commission Report. In this report I am grouping data Based upon first by
    salesman and then by customer. And also some sorting conditions. I designed all grouping by using report wizard.
    The problem is: If sort_by Parameter =customer then only need to group data based customer.
    Else ie if sort_by= 'order_no' or 'Inv_no' then no need of grouping the data by customer. Display data
    as per sorting condition.
    Is there any solution for this problem?

    Hi,
    I am facing a problem in Sales_commission Report. In this report I am grouping data Based upon first by
    salesman and then by customer. And also some sorting conditions. I designed all grouping by using report wizard.
    The problem is: If sort_by Parameter =customer then only need to group data based customer.
    Else ie if sort_by= 'order_no' or 'Inv_no' then no need of grouping the data by customer. Display data
    as per sorting condition.
    Is there any solution for this problem?There is no way to remove the grouping based on customer, so sorting based on customer will be retained.
    Way to hide the customer group fields in the customer repeating frame is by using format triggers based on sort_by_parameter,
    and place the customer fields in the last group repeating frame also and show or hide this fields depending on sort_by_parameter.
    Hope this helps.
    Best Regards
    Arif Khadas

  • Using access groups for documents

    Hi, there!
    I have groups of users with different access rights. Also I would like to setup documents groups which should be different for show to different groups of users as matrix.
    For example:
    1) General Policy is a group A, which means shown to anybody who has an access to corp portal.
    2) SOP ID123 is a group C, which means shown to selected tiny groups of users
    3) Confidential attachment to specification belongs to a group D, which granted access to 3 users only, including to CFO
    Can I use such matrix approach or it is difficult to implement?
    Or as an idea - more simple way just to create different libraries and manage access on this level?

    Hello Alex,
    I think the best solution is to create separate libraries, to separate permission.
    But if you want to have the documentation in the same library, you can take another approach. Try to create a folder, or a document set, to separate the documents. Then assign permission to each folder/docset as needed.
    finally, you can create a view to display all documents without folders. this way you can have the same view for all users, but users will only see what they have access.

  • Tollerence group for open item only

    hii all
    can any one tell me, if I want to make tollerece group fo employees and also want to specify the tollerence limit for amount posted per document only. not want specify tollerence limit for open item account (customer/vendor). is it possible? i have done blank in "amount per open item account" but the system not allow to post any vendor/ customer invoice. is it possible to solve

    Hi,
    It is possible to control the users or employees for a certain amount,by configuring  as shown as following Path
    FA-G/L Accounting-Business Transactions-Open item clearing-Clearing Differences-Define for Employee and the
    G/L acconts.
    MAy i hopeful, ths will hep p
    Regards,
    Kanike

  • Texts not going through for some people only

    Hello,
    The problem I'm having is that my niece(iphone5), 2 nephews(iphone4), one nephews girlfriend(iphone4), my sister and her fiance(iphone4) all have verizon as the provider for there service and since day 1 when my nephew bought the iphone4 all the texts I've sent him never went through. Here's the funny thing....everyone else gets them except him and I don't get his either. I have a blackberry 9310 with boostmobile so I decided to send him a message but to the default verizon phone email address so I sent one to [email protected] and another to [email protected] he only received the one I sent to the vzwpix address but when he replied I never got it. I asked him to send it to boost's default sms address ([email protected]) and finally I got it, for the first 3 weeks it worked but I had to keep the first text he sent me and just reply to it (I know a big never ending reply) anyway.... all of a sudden without any warning we ended up not getting anything all over again but everyone else is fine. I have to text his girlfriend to tell him whatever I need to tell him and they live together and share the same plan soooooo..........HEEELLPPPP!! Has anyone out there had this type of issue? also, its been a good 8 months of this and yes I reset his phone, I reset my phone, I upgraded his and mine with the latest everything and still no luck.  

        Thanks for following up, ProRay298. Does your friend also have an iPhone? If so, please have her check her blocked contacts by going to Settings>Phone>Blocked and make sure you are not listed. Is it possible that she shares her Apple ID with another iPhone? Please also try disabling your iMessage by going to Settings>Messages and switching iMessage to off. Keep us posted.
    AndreaS_VZW
    Follow us on Twitter @VZWSupport

  • How do I Get Album Art for Some Tracks Only?

    I feel really stupid for asking this but I have tried to find out how to do it to no avail!
    I only want to get the album art for actual albums but whenever I click on "Get Album Artwork" it goes through my whole library!
    I have tried by highlighting the songs and then clicking get album artwork... did not work.
    I have tried only selecting the songs I wanted [using checkbox thingy] and then clicking get album artwork... did not work.
    I feel there is a really simple and obvious way to do this but cannot for the life of me figure out how.
    Regards,
    Michael

    HAHAHAHAHA!
    Thank you! I tried that and did not see it at all!
    *feels v. sheepish*

  • Release Of Forecast From DP To SNP (For Some Locations, Only Baseline)

    Dear All,
    Generally, we follow the following procedure....In the month begining, we generate the baseline forecast for all the locations (we are having around 20 branches). Then we used to open the DP planning book for a couple of days to our branch persons so that they are able to feed their correction. After which we release the final forecast i.e. Baseline Forecast +/- Branch correction to SNP for further proceesing.
    This month, we opened the planning book (as usual). Branches did  the branch correction. But on final checking, we found that around 4 -  5 branches have done corrections / updations very vagely i.e. roughly. So, we wants to ignore their branch correction.
    My query be that is it possible that while releasing the Forecast from DP to SNP... can we release baseline forecast for selective five branches and for the rest of the branches, we wants to release final forecast key figure i.e. Baseline +/- Branch correction.
    Kindly advise further.
    With Best Regards,
    Sanjeev Chugh
    17-NOV-2010 (AN)

    Sanjeev
    You have not mentioned at what level you are doing the forecasting. If forecasting is done at material- branch level then what you are asking can be achieved easily. All you have to do is go to /n/sapapo/mc90 ( or create a release profile) and for the branches for which you want to release baseline forecast , you have to specify the baseline forecast keyfigure in the input and specify the material branches in the i/p criteria. For adjusted forecast you have to use another variant and specify the adjusted forecast key figure and the corresponding material branches.
    Iam not sure how your requirement can be achieved in case you are forecasting @ material level.
    Thanks
    Aparna

  • StoreFront : Payment and Shipping group relationships are missing for some orders

    Hi Team,
    In our application, we are able to see relationship between payment and shipping group for some orders. But we are not able to find these relationships for some orders.
    We are verifying in "dcspp_payship_rel" table. We are wondering why this behavior is happening for some orders.
    Could you please suggest to move further ?
    Regards,
    Babji...

    Hello.
    First of all you must ensure that you are properly using transactions when you create/update the orders.
    There are best practices to update the orders in ATG that must be followed to avoid loss of information.
    Like this steps below:
    Acquire a write lock using the ATG lock manager.
    Start the transaction.
    Synchronized on the Order object.
    Update the Order.
    End the synchronization.
    End the transaction.
    Release the lock.
    Here are some links that should help you understand the steps to be followed to make a correct update of an order:
    https://atgoasis.wordpress.com/2014/08/28/best-practices-for-updating-an-order-in-atg-commerce-applications/
    http://www.digitalsanctuary.com/tech-blog/java/atg/design-pattern-for-updating-an-atg-order.html
    http://sumangalavijay.blogspot.com.br/2011/10/atg-update-order.html
    Oracle ATG Web Commerce - Managing Transactions in Oracle ATG Web Commerce
    Hope it helps you! =)

  • Add user in ACS with limited access

    Dear
    I have low experiance with cisco ACS
    So kindly i need help to add user to The ACS which has limited access to my network Switches ( As Show only not to change configuration )
    Also how to take backup for the ACS Database
    Thanks,

    Hi,
    Search about command authorization in the AAA section, you'll get ample information about it, i.e., on how to configure network devices so that you can allow certain users on ACS to have limited and certain user to have full access.
    About taking a backup, that is pretty simple.
    System Configuration > ACS Backup > Backup Now.
    And you have a latest backup from ACS.
    Regards,
    Prem

  • Object level checking for some of the basis tcodes(internal audit)

    Hi masters,
    in our company every month we check access controls for some of basis tcodes,i am giving it below,is the selection for Tcode and object level values combinations are correct or is there any modifications please notify.
    Tcodes     Imp Auth Objects     Auth fields     Auth  values
    SCC1     S_CLNT_IMP     Actvt     21,60
         S_TABU_CLI     CLIIDMAINT     X
    SCC4     S_TABU_CLI     CLIIDMAINT     X
         S_TABU_DIS     Authorization Group     *
              Actvt     01,02
    SCC5     S_CLNT_IMP     Actvt     21,60
         S_TABU_CLI     CLIIDMAINT     X
    SCC7     S_TRANSPRT     Request type     *
              Actvt     43,60,75
         S_CLNT_IMP     Actvt     21,60
    SCC8     S_DATASET     PROGRAM     *
              Actvt     06,34,A7
         S_TRANSPRT     Request type     *
              Actvt     43,60,75
    SCC9     S_TABU_CLI     CLIIDMAINT     X
         S_CLNT_IMP     Actvt     21,60
    SCCL     S_TABU_CLI     CLIIDMAINT     X
         S_CLNT_IMP     Actvt     21,60
    SCU0     S_TABU_DIS     Authorization Group     SS
              Actvt     01,02
         S_TABU_RFC     Actvt     3
    OBR1               
    SM01     S_ADMI_FCD          TLCK
    SM04     S_ADMI_FCD          PADM
    SM12     S_ENQUE     S_ENQ_ACT     DPFU,DLOU
    SM13     S_ADMI_FCD          UADM,UMON
    SM50     S_ADMI_FCD          PADM
    SM54     S_ADMI_FCD          NADM
    SM55     S_ADMI_FCD          NADM
    SM56               
    SM59     S_ADMI_FCD          NADM
                   RFCA
    SMLT     S_LANG_ADM     Actvt     02,16,61
              Table     *
    SPAD     S_SPO_DEV     SPODEVICE     *
    SP01     S_SPO_DEV     SPODEVICE     *
         S_ADMI_FCD          SP01,SP0R
    ST01     S_ADMI_FCD          ST0M,ST0R
    ST05     S_ADMI_FCD          ST0M,ST0R
    RZ04     S_RZL_ADM     Actvt     1
    RZ06     S_RZL_ADM     Actvt     1
    RZ10     S_RZL_ADM     Actvt     1
    RZ21     S_RZL_ADM     Actvt     1
         S_BTCH_JOB     JOBGROUP     *
              JOBACTION     DELE,RELE
    SM49     S_LOG_COM     Command     *
              Opsystem     *
              Host     *
         S_RZL_ADM     Actvt     1
    SM69     S_RZL_ADM     Actvt     1
    SM63     S_RZL_ADM     Actvt     1
    SMLG     S_RZL_ADM     Actvt     1
    SE16     S_TABU_DIS     Authorization Group     *
              Actvt     01,02
    SM30     S_TABU_DIS     Authorization Group     *
              Actvt     01,02
    SM31     S_TABU_DIS     Authorization Group     *
              Actvt     01,02
    SPRO     S_PROJECT     PROJECT_ID     *
              APPL_COMP     *
              PROJ_CONF     *
              Actvt     02,06
         S_DOKU_AUT     DOKU_ACT     MAINTAIN
              DOKU_DEVCL     *
              DOKU_MODE     *
    SPRO_ADMIN     S_PROJECTS     APPL_COMP     *
              PRCLASS     *
              Actvt     01,70
         S_PROJECT     PROJECT_ID     *
              APPL_COMP     *
              PROJ_CONF     *
              Actvt     02,06
    PFCG     S_USER_AGR     ACT_GROUP     *
              Actvt     01,02
         S_USER_PRO     Actvt     01,02
              PROFILE     *
    SM19     S_ADMI_FCD          AUDA,AUDD
    SU01     S_USER_AGR          *
                   01,02
         S_USER_GRP     Class     *
              Actvt     01,02
    SU02     S_USER_PRO     Profile     *
              Actvt     01,02
    SU03     S_USER_AUT     OBJECT     *
              AUTH     *
              Actvt     01,02
         S_USER_PRO     Profile     *
              Actvt     01,02
    SU05               
    SU10     S_USER_GRP     Class     *
              Actvt     01,02
    SU12     S_USER_GRP     Class     *
              Actvt     01,02
    SU20     S_DEVELOP     DevClass     *
              ObjectType     SUSO
              ObjectName     *
              P_Group     *
              Actvt     01,02
    SU21     S_DEVELOP     DevClass     *
              ObjectType     SUSO
              ObjectName     *
              P_Group     *
              Actvt     01,02
    SU22     S_DEVELOP     DevClass     *
              ObjectType     SUST
              ObjectName     *
              P_Group     *
              Actvt     01,02
    CMOD     S_DEVELOP     DevClass     *
              ObjectType     CMOD
              ObjectName     *
              P_Group     *
              Actvt     01,02
    SA38     S_PROGRAM     P_Action     SUBMIT,BTCSUBMIT
              P_Group     *
    SD11     S_DEVELOP     DevClass     T,Y,Z*
              ObjectType     UDMO,UENO
              ObjectName     *
              P_Group     *
              Actvt     01,02
    SE11     S_DEVELOP     DevClass     T,Y,Z*
              ObjectType     DOMA,DTEL.ENQU
              ObjectName     *
              P_Group     *
              Actvt     01,02
    SE12     S_DEVELOP     DevClass     T,Y,Z*
              ObjectType     DOMA,DTEL.ENQU
              ObjectName     *
              P_Group     *
              Actvt     01,02
    SE13               
    SE14     S_DEVELOP     DevClass     T,Y,Z*
              ObjectType     INDX.MCID,TABL
              ObjectName     *
              P_Group     *
              Actvt     01,02
    SE15     S_DEVELOP     DevClass     *
              ObjectType     *
              ObjectName     *
              P_Group     *
              Actvt     3
    SE37               
    SE38     S_DEVELOP     DevClass     T,Y,Z*
              ObjectType     FUGR,PROG
              ObjectName     *
              P_Group     *
              Actvt     01,02
    SE93     S_DEVELOP     DevClass     T,Y,Z*
              ObjectType     TRAN
              ObjectName     *
              P_Group     *
              Actvt     01,02
    SE41     S_DEVELOP     DevClass     *
              ObjectType     *
              ObjectName     *
              P_Group     *
              Actvt     01,02
    SE43     S_DEVELOP     DevClass     *
              ObjectType     *
              ObjectName     *
              P_Group     *
              Actvt     3
    SE43N     S_DEVELOP     DevClass      '
              ObjectType      '
              ObjectName      '
              P_Group      '
              Actvt     01,02
    SE51     S_DEVELOP     DevClass     T,Y,Z*
              ObjectType     FUGR,PROG,DYNP
              ObjectName     *
              P_Group     *
              Actvt     01,02
    SE80     S_DEVELOP     DevClass     T,Y,Z*
              ObjectType     *
              ObjectName     *
              P_Group     *
              Actvt     01,02
    SE81     S_DEVELOP     DevClass     *
              ObjectType     *
              ObjectName     *
              P_Group     *
              Actvt     01,02
    SE82     S_DEVELOP     DevClass     Y,Z
              ObjectType     APPLTREE
              ObjectName     *
              P_Group     *
              Actvt     01,02
    SE91               
    SE92               
    SE92N               
    SNRO     S_NUMBER     NROBJ     *
              Actvt     02,17,11
    SQ00     S_QUERY     Actvt     02,23
    SQ01     S_QUERY     Actvt     02,23
    SQ02     S_QUERY     Actvt     02,23
    SQ03     S_QUERY     Actvt     23
    SQVI               
    SM35     S_BDC_MONI     BDCAKTI     ABTC,AONL,DELE
    SM35P     S_BDC_MONI     BDCAKTI     ANAL
    SM36     S_BTCH_ADM     BTCADMIN     Y
    SM37     S_BTCH_JOB     Jobaction     PROT,SHOW
              Jobgroup     *
    SM39               
    SM62               
    SM64     S_BTCH_ADM     BTCADMIN     Y
    SE01     S_CTS_ADMI     CTS_ADMFCT     EPS1,EPS2,PROJ
         S_TRANSPRT     Actvt     *
              Ttype     *
    SE06     S_C_FUNCT     PROGRAM     SAPLSTRF,SAPLSTRI
              CFUNCNAME     SYSTEM
              ACTVT     16
         S_TRANSPRT     Actvt     43,60,65
              Ttype     *
    SE09     S_TRANSPRT     Actvt     43,60,65
              Ttype     *
         S_CTS_ADMI     CTS_ADMFCT     EPS1,EPS2,PROJ
    SE10     S_TRANSPRT     Actvt     43,60,65
              Ttype     *
         S_CTS_ADMI     CTS_ADMFCT     *
    SPAM     S_CTS_ADMI     CTS_ADMFCT     IMPA,IMPS
         S_TRANSPRT     Actvt     43,60,65
              Ttype     PATC,PIEC
    STMS     S_CTS_ADMI     CTS_ADMFCT     *
         S_RFC     Actvt     16
              RFC_NAME     EPSF,STPA
              RFC_TYPE     FUGR
    Edited by: rameshbabu muddana on Mar 2, 2009 10:56 AM

    hi,thanks for reply "you should not care about the transaction start s_tcode at all - only check the object required"
    It has made manditory policy to check for users and roles every month with given criteria of Tcode and object,now i have been given the task to check the combination of Tcode and object value combination are correct or not,please validate the combinations and suggest,we are using ECC 5.0,i had gone through wild card use (#) when we check in SUIM,i am getting confused that when i give # followed by value, data i am getting different from without #.please provide an example for SE16 with S_TABU_DIS
    how to check?
    i am checking in this way
    S_TCODE       SE16
    S_TABU_DIS
    Activity                   
    Value  01or 02
    Authorization Group
    Value  #&NC&

Maybe you are looking for

  • How can I wipe my hard drive and restore to factory settings without the use of the original OS CD?

    I have a 2010 MacBook and I need to wipe the hard drive and restore to factory settings. The problem is that even though I have the original disc, the CD drive has stopped functioning and will reject any disc put into it. Therefore, is there another

  • Installed snow leopard and now all red colors look rusty orange.

    All I did was install snow leopard on my mac pro and now all reds will shift to orange on one display and pink on my other. I've been using the exact same setup with just leopard and didn't have this problem so I am assuming it has definitely somethi

  • How to include non-joining records from level one in the lowest level?

    As an example the dimension has three levels with data coming from three source tables. The relationships between these tables are zero to many. As a result of this e.g. there are records at the first level that do not join to the second table for le

  • Download NWDS 7.0.11

    Hi, Where could I download NetWeaver Developer Studio 7.011 ? I already search in market place and sdn, in market place I found a sar file, but I need an exe file because I don't have access as admin in SAP server. In Sdn is a trial version for Linux

  • SAP Installation - 3 SAP systems on 1 host

    Hello, I already have Solution Manager system and Enterprise Portal system installed on a host. Can I install another dual stack(ABAP+Java) on the same host? Thanks, Gautam.