New role creation for display

Hi,
We want to create a role such that the users can see only the pricing but not the costing, for sales quotations and orders, for a particular distribution channel?
Regards,
Ajit

Hi Ajit,
If you wish to create a new Role, Use T. Code: PFCG.
Once created assign the same role in to User's Profile Via T. Code: SU01.
Here itself, in Authorization you may add T. Codes (for Display) and also define/ restrict User's view/ access to Sales Area data (i.e. Distribution Channel).
Better to take help from Basis-Administrator as its purely Basis-job.
Best Regards,
Amit.

Similar Messages

  • Authorization Object for role creation for query display?

    Hi,
    Can Anybody here tell me what is the Authorization object that we use for role creation for query display?
    I want to assign a role to the newly designed query! that query does not have any role so far!
    Pls suggest me
    Thanks,
    Ravi

    Hi,
    I could make the authorization tab green by entering the authorization object!
    But user tab still remains red as it is not allowing me to enter my username in the user tab!
    in the user tab  i am unable to enter my user name?
    Any suggestions?
    Thanks,
    Ravi

  • Request Number is not generated for BRM "new" role creation

    Hello Gurus,
    I have configured BRM in SAP GRC AC 10, along with the workflow .
    I have selected the following methodology
    Define Role --> Maintain Auth >Analyze & Access Risk>Request Approval>Generate Roles>Maintain Test Cases
    Role name : Y_TEST_BRM_FUNCTIONALITY
    So i do the following steps and assign
    1) Role approver as Mr. ABC & Alternate approver as Mr. QRS
    2) Assign the Required transactions and do the RAR i.e i am done till step 3 of methodology
    When i click "Initiate Approval request"
    The approval triggers , and goes to the 1st stage as configured in MSMP
    1) Power User Approval .
    Here the Power User : EFG , open his workflow and see the request as
    Role approval required for role Y_TEST_BRM_FUNCTIONALITY
    The approver approves the request and then the request all together vanishes.
    Unfortunately i am not able to search the request for that role from NWBC -->Search request by
    Process Id : Role Approver Workflow
    It gives blank !!
    Hence neither i am able to find the request no able to do any debugging of it using
    GRFNMW_DBGMONITOR_WD
    Please note that the Request Id is created for any request in CUP.
    Is it that i have to create a number range for BRM request ??
    If so will you please let me know the object

    Hello All,
    I was wrong in posting the cause of problem.
    Please note no "Request number" is generated for Role creation Request.
    The problem was i was unable to search the Role Request approval status from "Search Request" via  Process Id
    It got resolved via SAP note 1643539 : UAM: Search Request not returning result for some Process Id.
    My Issues is Resolved.
    Thank You.
    Regards,
    Victor

  • Need Documents on New Role Creation in SAP

    Hi All,
    i am new to SAP Security and i would like to grow in this field,
    Can any one send me the links for the documents on creation of new roles, objects, Authorizations, transactions etc.
    Thanking you in Advance,
    Savitha.

    Hi,
    I guess you should look on Google for ADM940 and ADM950,
    Its a very detailed book for what ou want.
    Indeed to help you out, Its a very very simple task. But when you read this book keep in mind that there are 3 kinds of roles, Single roles, Derived roles and composite roles.
    Just to give you a heads up :
    Single role :  Role which has Authorization and data is restricted via company code and filed level values
    Derived role : these are derived from Single roles or you can say master role. Difference between single role and derived role is that you can derive say 10 roles from single role however company code can be manage in derived roles.
    So generally how it works is one create a master role which has all the required authorization. Now you don't want people in australia sould approve orders for Texas, US.
    Now there are hundred of companies department accross the glob. you don't want to end up creating hundreds of roles. so you create one master role and then you create derive role from that master role which is most of the time master role replica (keep in mind most of the time but not always so you have to be very carefull) now in derived role all you have to maintain is company codes.
    all the authorizations for all the objects and fields come from master role.
    I hope i am making sense.
    Composite role : its a collection of single and derived roles. Keep in mind you can not put composite role into composite role.
    That was just a heads up you need to read ADM940 and ADM950.

  • Role Creation for CMS

    Hi Steve,
    We use ant scripts to create domain and assign roles. But some how the scripts for role is incomplete.
    Can you let me know, where the roles like 'Anonymous' and others should be specified in newly created domain. I mean where do we assign roles and privileges inside domain folders?
    Cheers,
    Lakshmi

    Hi
    > i need to create a ROLE only for  Plant Maintenence (only Plant maintenence  authorization).......
    Search the roles for this module & make copy of this roles to zroles.After the zrole was created assign this new roles to that user.
    Search the role by writing plant,maint & check which are related to plant maintenence & copy that role.
    Again check all the transaction which are going to use in the module PM.Create a new role & assign this transaction in this role.this is another way to create the user with authorization only for PM.
    For more details about PM modules transaction check the following link
    http://www.sap-img.com/sap-pm.htm

  • Role creation for Plant maintenence

    Hi Folks ,
    i need to create a ROLE only for  Plant Maintenence (only Plant maintenence  authorization).......
    regards
    sathish

    Hi
    > i need to create a ROLE only for  Plant Maintenence (only Plant maintenence  authorization).......
    Search the roles for this module & make copy of this roles to zroles.After the zrole was created assign this new roles to that user.
    Search the role by writing plant,maint & check which are related to plant maintenence & copy that role.
    Again check all the transaction which are going to use in the module PM.Create a new role & assign this transaction in this role.this is another way to create the user with authorization only for PM.
    For more details about PM modules transaction check the following link
    http://www.sap-img.com/sap-pm.htm

  • New Role creation

    Hi All,
       I created new Role and assigned users to that role . I added HTML page to the particular role and when I go click that link it is saying that java authentication problem. I am unable to see the applets what ever I created for the web page. Is there any thing to add in xMII for the particular role and if add the same HTML page to the Everyone role its working fine.
    Thanks
    Muvva

    Hi Muvva ..
    May be you can try the following ...
    instead of providing the direct html, you can provide the user with the logon credentials which redirect the page to the desired html page, as follows...
    http://Server:50000/logon/logonServlet?redirectURL=XMII/....../YourPage.html
    Regards,
    Ajay.

  • Block New Data Creation For Customize HR Infotype

    Hi Expert,
    I'm creating a customized HR infotype. This infotype only allow user to Display and Modify current entered record from other program. So, here i need to Block / Not Allow User to Create New Data from PA30. Therefore if user Click The Create (F5), system will prompt message "Data Creation Not Allowed For IT9906" such this example [Block Data Creation Infotype|http://4.bp.blogspot.com/-HCbPhXP-CYU/TgxLU7t86UI/AAAAAAAABrs/d46uN9XrIHk/s1600/BlockDataCreation+Infotype.bmp] what  i'm Searching. tq.

    Hi , i found the answer. need to add code at PBO at screen 2000. add this such code:
    if psyst-ioper eq insert.
        message i532(0u) with text-001.
        leave to transaction 'PA30'.
      endif.

  • New address creation for already existing customer in Oracle

    Hi,
    We are working on customer conversion and loading all the data into customer interface tables so that we can run the customer interface to move the data into oracle tables.
    We need to create another address as per client’s requirement to already existing customer in oracle which has active primary bill_to address.
    Can we do this by using customer interface tables or use the API’s for it.
    Any pointers regarding this will be highly appreciated.
    Thank and Regards,
    Rekha Palagani.

    i have heared form someone that i should copy some text (from files) or some files which resides in bin folder (i don't know the exact path) in the sql console to access existing tables. is that ture?Not sure what that means... to access existing tables, or to create new ones you have to use Sql commands (or some graphic stuff).
    What about reading some documentation ?
    System user is a DBA, and can possibly read any tables, but most probably is not the owner of emp table. To know it you can do
    SQL> select owner from dba_tables where table_name='EMP';
    then connect to that user, or, as system user, do
    SQL> select * from <owner>.emp;

  • Role Creation for FSCM

    I have a developer/functional person who continually requests FI/FSCM transactions such as OBXI. Since he is supposed to be authorized for everything except HR transactions, I initially copied all of the SAP standard menu to this role and removed HR (thinking that this included all but HR and Z transactions). However, all of the transactions that he asks for donu2019t exist in any previous roles, SAP roles, or the SAP menu but the transactions definitely exist.
    My question: how, or where, is it possible to have all of these transactions that donu2019t exist in any SAP roles, the SAP menu, or SUIM? I would like to add all of these FI transactions in one transport.

    Hi,
    isn't OBXI a config transaction and is only accessible menuwise via SPRO?
    Not all transactions are available in the SAP standard menu. There are many transactions that only are bound to report and or configuration activites that does not fit into the standard menu.
    Config activities are included into SAP roles by ranges. in this case most likely OB*.
    Regards Fredrik

  • Reg:new request creation for alredy created request

    hai,
    one program is created under more than one request number , Now i want to create one request number for all those modification.
    all requests are released.
    is it poosible to create new request for all released request.
    regards,
    Chaitanya

    hi,
    once if you save any changes under one request it will automatically take all modifications of program under new request, no questions of wethe that request save all changes or not.
    or create new copy program and save this new program under new request - in this way u can make all changes under one request.
    Rewards if is useful
    Regards,
    Vijay

  • New user creation for accessing BPM work list

    Hi,
    I have installed AIA in my system and by default it allows me to login to the BPM worklist using AIAIntegrationAdmin user. All the error notifications are also sent to this user.
    If I want to send error notifications to other users and provide them access to BPM worklist, how should i go about it?
    Pointers to this would be great help.

    hi,
    As mentioned i have created a user (named TestUser) in enterprise manager and given him the roles of ascontrol_monitor and ascontrol_appadmin. I have made an entry of this user in users-properties.xml. Still i am not able to login into worklist with this user credentials.
    Please find the user definition I added in users-properties.xml file:
    <userObject>
    <name>TestUser</name>
    <description>Demo User</description>
    <email>[email protected]</email>
    <title>Load Agent 5</title>
    <firstName>Test</firstName>
    <lastName>User</lastName>
    <manager>jstein</manager>
    <timeZone>America/Los_Angeles</timeZone>
    <languagePreference>en-US</languagePreference>
    <notificationPreferences>Mail</notificationPreferences>
    </userObject>
    PLease let me know if i have to make changes at any other places.

  • Role creation for CATS

    Hi all,
    How can i create roles and authorisations fo CATS.I need to know how can i find out what are all roles required to manage CATS?
    Give me inputs of source where i can find out some roles?
    Regards,
    Hema

    Hi Hema,
    The roles and authorizations depends on the work that a particular user is doing.
    My suggestion :-
    Have a discussion with your super user and find out what are all the tcodes that user is using.
    Keep that tcodes in mind create one role to user and assign it.
    There might be a specific tcodes to approver also.
    Thanks
    K. Bhaskar

  • Role creation for web report

    Hello All,
    Can any one provide step by step solution to assign web report to role.
    Thanks & Regards,
    Suneel

    Role Menu/Bookmarking/Web Reporting in NW2004s
    Hope it Helps
    Chetan
    @CP..

  • GRC AC Request Role Creation

    Hello all,
    I noticed that by default GRC AC doesn´t have a Request Type for Role Creation. Normally how this is done? I mean, if someone realizes that a new role is necessary, how can this person report the need for a new role creation? What are my option here?
    Regards,
    SAP Legend

    Hi SAP Legend,
    You can not request a new role to be created via an Access Request workflow. You still need a business governance strategy where someone has to raise a request outside of the GRC system for the new roles through the right channels deemed fit in your company to get the new role made. Maybe you have a support ticketing system in place or some SAP security department you can raise the formal requests to.
    The BRM Role creation/maintenance workflow runs separately from the Access Request workflow. Further more, the definition and creation process of roles via GRC should only involve and be used by Business Process Owners/Role Owners and the Authorisation security team only, i.e. not general end users.
    A role build methodology will have to be set up and then the underlying approval workflows (based in MSMP technology also, like the AR workflow).
    Once the role has been built (either via back end PFCG) or via GRC using the BRM methodology and approval flows, the role will be available to the end user to request via AR.
    Hope that helps.

Maybe you are looking for

  • How to empty cache in Safari 6?

    In Safari 6, the "empty cache" command is missing from the Safari menu. Does anyone know how to empty the cache in Safari 6?

  • Workspace not working properly with planning

    Hi, When we try to access the planning application through workspace all menu's are coming as jumbled up. We are using IE 9 and distributed environment where workspace and planning are in different server. Please find below error from workspace.log f

  • What is the "Other" category under storage and how can i delete items from this?

    My disc is almost full.  "About this Mac" says that I have 47 GB of "Other."  What is this Other and how can I delete items from this?

  • Execute a dos command

    I am trying to execute a dos command thru sap and specific the delete command. i tried in 2 ways (i read it to the forum) but i can't do it. a)            DATA : FILE(100),                PARAM(50),                COMM(30).                COMM = 'DEL

  • How to manage multiUsers in weblogic5.1

    Hi all,           We have multi user situation in database.           To start up the application server, there would be dummy connection.           Based on the dummy connection, all entities would be deployed (weblogic           5.1).           Sce