Open Authorization Objects in role after role Transport

Hi All,
I have transported a R/3 (ECC6, support) role from Dev to QA and Dev (Multiple clients). After transport, Role has authorization tab with status (green) but when i display authorization data i found one new open authorization object (yellow).
I already have generated profile before tranporting. Role is also okay in  Dev other clients (We have multiple clients in Dev) with status green and no open authorizations (yellow)
Any feedback/suggestions ?
Thanks in advance
Khasim.

This happens when PFUD runs at the same time as you are generating the role. Refer to this note: 355030 - Loss of authorizations after profile generation. Another remote reason could be if your source (DEV) and target (QA) systems use different characters sets. (Note #535554).
If it is the former case, re-transporting your role may just be the solution for you. Just re-generate the role in DEV and initiate a new transport.
Hope this helps.
Ashutosh

Similar Messages

  • Authorization Object And Roles For  Functional Consultant

    Dear Expert,
    What kind of respective Authorization Object And Roles would be provided to  Functional Consultant (FI,MM, SD, PM, PS, CO, HR )at the time of implementation ?
    Thanx in advance
    Pavel

    Thanks Juan,
    We now already have it here and in the NW IDM forum a few times as well...
    Cheers,
    Julius

  • Programmatically assigning Authorization Objects to roles

    Hi there,
    I have created an authorisation object with eight fields. The fields control which parts of my application are accessible to the user. (Each field is one category, each category has several subcategories).
    What I want to do is the following:
    There shall be a custom authorization dialog, wherein the system administrator can configure the access of the application for a specific user.
    In plain text: I want to develop an interface which makes it possible to assign authorisation objects with specific values to a user or to an already existing role.
    Is there any functionality, that allows me to perform this assignment and regenerate the users profile?
    I already discovered, that the table UST12 contains the connection between the authorization profile of a role and an authorization object, as well as the assigned values. Anyhow, just to write new values to that table has no affect to the authorization when calling "authority-check object" in an ABAP report.
    Does anyone know, whether there are standard functions in the ERP System, that support the changing of authorization objects and the regeneration of roles?
    Thank you very much,
    Gregor
    Edited by: Gregor Bender on Mar 11, 2008 8:41 AM

    >
    Gregor Bender wrote:
    > I already discovered, that the table UST12 contains the connection between the authorization profile of a role and an authorization object, as well as the assigned values.
    Nope, sorry, it's not the connection but only one of the many.... Roles and profiles are stored in quite a lot of different tables so manipulating one table directly will hardly ever get you the desired situation. It may even lead to problems due to inconsistencies.
    For mass regenerating profiles there's transaction SUPC.
    For manipulating the contents of roles/profiles have a look at scripting with SECATT or LSMW in combination with PFCG.
    If you want to write code to add objects to roles you have to look at least in tables AGR_1250, AG_1251 and AGR_1252. The UST* tables are updated when generating profiles and/or comparing users.

  • New Authorization Object within Role

    hi everybody,
    does anyone know how can i get New Authorization Objects for any Role for the new release that did not exist in the same Role from former release?
    tables AGR_1250 and AGR_1251 do not show if object is new for this role. they only show if object is new itself.
    thanks a lot,
    javier rubio

    pandu,
    se54 is not related with this topic.
    thank you very much for your answer, very hepful

  • Authorization Object for role creation for query display?

    Hi,
    Can Anybody here tell me what is the Authorization object that we use for role creation for query display?
    I want to assign a role to the newly designed query! that query does not have any role so far!
    Pls suggest me
    Thanks,
    Ravi

    Hi,
    I could make the authorization tab green by entering the authorization object!
    But user tab still remains red as it is not allowing me to enter my username in the user tab!
    in the user tab  i am unable to enter my user name?
    Any suggestions?
    Thanks,
    Ravi

  • Copying values of a singular authorization object between roles?

    Suppose I have an authorization object assigned to a role and its fields hold a large amount of data (say S_TCODE with a lot of transaction codes specified via ranges). Suppose further that I want to have this same object with this same data in another role. The other objects of the two roles are different and I'd rather not type the large amount of data into the authorization object again.
    Is there a way to copy/paste just one authorization object between two roles?
    I know how to make a copy of an authorization object and its values within the same role, but I haven't found a way to copy between roles.
    ursa

    Hi Ursa,
    I havent come across any export object kinda thing...
    This may help you in practical situation...
    Let us consider your particular requirement related to s_tcode.
    for that go to suim -
    transactions -> executable for role .
    Give the role name get the list of transaction codes.
    Download into excel file. then copy from there and paste into your new role menu or in s_tcode object.
    Mostly we dont get that much list for other objects.
    One more thing you can do.
    click on display tab beside the object in your source role, you get the list window.
    type ctrl + Y and then copy the 7-8 lines and paste it in the object of new role.
    Cheers.
    Shamish
    Message was edited by:
            Shamish Lele

  • Object automatically changed after file transport

    Hi Friends,
    I have transported  a mapping object from quality to production. In quality the target structure occurance is set to 1..1 to generate one idoc.
    After transport into production the occurance of the target structure in mapping has changed to 1..unbounded(instead of 1..1) automatically.
    I wonder how it happened.I have even cross checked the transport id of quality object and production object which is exacly the same.
    Please help with the possible reason!!!
    Regards,
    Suresh.

    Hi
    Seems to version conflict , are u able to see extra tab "Conflict"
    u can see list of Objects which have a version conflict.
    Actual habit is transporting from QA --> PROD
    but was it followed , i think there might be a change made in Prod envi , before transporting to Prod from QA.
    Rgds
    srini

  • Error in Transport of Authorization Object

    Hi,
    I have created a authorization object in my development and transported it to testing. In the transport log I can see that it was succesfully imported but I am not able to see the Authorization object in SU21 of testing system but I tried to see that Authorization object through SUIM and able to see that object.
    I tried to create a sample role and assign this authorization object manually to that role but not able to do that.
    Can any one help me in this issue.

    Hi Martin,
    Thanks for the reply
    Yes I forgot to transport Authorization class. I have done that now and able to access the Authorization object.
    Can you please let me know the complete process whether we have to transport only Authorization class...
    Then the Authorization object will be transported on its own..
    Thanks in advance

  • BW Role Transport

    Hi,
      BW Version-3.5
      I created 20 Different roles that will grant access to the different cost center hierarchies..
    for that i created  a authorization object in RSSM.
    Now how can i transport this to Production
    1) Do i need to transport the authorizatiuon object i created in RSSM
    I tried by selecting the role and grouping 'In data Flow befor' when i draged from left partion to right in transport connection screen
    i can't see any authorization object under role only role is avaliable to raise a request
    Can you please give me detailed approach transporting roles ....espicially hierarch
    Thanks

    Hi,
    Authorization objects have to move separately before the Role's moved to a different systeme.
    You can include the Authorization object in the RSSM object directory entry by giving the package name.
    Hope that would help !
    Raju

  • How to find a autorization object and roles for paricuu00F6llar documetytpe(DMS

    Hello,
    I have a question,Its urgent ..#
    For a particular document type (for example PPN)..
    How to find a authorization object and roles...Please let me know.
    In the DIS which autority object and roles they use it for this.
    <b><REMOVED BY MODERATOR></b>
    Regards
    preethi
    Message was edited by:
            Alvaro Tejada Galindo

    This issue seems to be resolved since jDeveloper/ADF 11.1.1.3.
    Am I true?

  • How to find a autorization object and roles for paricuöllar documetytpe(DMS

    Hello,
    I have a question,Its urgent ..#
    For a particular document type (for example PPN)..
    How to find a authorization object and roles...Please let me know.
    In the DIS which autority object and roles they use it for this.
    Reward with full points
    Regards
    preethi

    This issue seems to be resolved since jDeveloper/ADF 11.1.1.3.
    Am I true?

  • Issue with authorization objects

    Hi,
    We are running on ECC 6 . There is an issue while adding t-codes to a role.
    When we add a transaction code in the Menu tab, for eg, a Z transaction code, it throws up a whole lot of open authorization objects under the authorization tab (open authorizations under FI, MM, so on). The open values proposed are all the default values in SU24. This happens even if we use the 'Read old status and merge with the new'. Our check indicator maintenance for all t-codes seem to be fine. Pls advise.
    Cheers!!

    > The default values (SU24 values) are once again populated if they were not maintained during the earlier maintenance.
    They are populated again if they were deleted during the earlier maintenance or are in a changed status of the original authorization where new values in SU24 are proposing something different.
    That is why you should never delete standard or maintained authorizations and try to avoid the copy & change strategy by maintaining SU24 to meet your needs.
    It shounds like SU24 is not as "fine" as you have stated before hand.
    Cheers,
    Julius

  • Authorization object for "add approver" in contracts

    Hello, Experts,
      I am looking for authorization object for adding approver in contracts.
    But without adding authorization for changing contracts.
      Regards,
        Rami Kleiman - HP

    1. you can try to restrict  the authorization object ( Manager Role-- /SAPSRM/MANAGER) for contracts to display ( remove the change).
    2. you can also change the personalization object key "BBP_WFL_SECURITY" to None ( but i, think this will affect all the objects like shopping carts purchase orders etc..)
    Thanks
    velu

  • Authorization object per systems

    HI,
    1. There is different authorization  object in different systems (like R3 BW CRM) .
    2. When we get  R3 system we get out of the box authorization object  and roles like for admin ...
    or we have to build it?
    Regards

    The Netweaver "Basis" AS ABAP for example has it's objects, regardless of which components are installed. E.g. S_DEVELOP, S_DATASET, S_RFC, etc etc etc. See the BC* classes.
    The application components also have their own objects (assigned to the packages of those components).
    SAP does provide some roles as templates and profiles to get you started if you have nothing else (E.g. the SAP* roles and SAP_ALL profile), as well as portal roles for which you need to build the backend authorization for, as well as nothing other than the SU24 check proposals from which you need to building your own role from scratch depending on your business process design (choice of transaction).
    In some cases, absolutely nothing is delivered except the coding. Those are the real buggers.
    Cheers,
    Julius

  • Role -- Object--- activity compare after upgrading from 4.6c to ECC 6.0

    Hello,
    Our team has recently upgrade the SAP system from 4.6 c to ECC6.0 , after successfully upgradation when i check the customized role some of the Objects and some of the profiles are in INACTIVE status.
    So my question is what we have to do for cross check the authorizations with my older authorization and what are the ways to do that.
    I have older 4.6C quality system to which i have to compare the newely upgraded ECC 6.0 roles.
    will give full point for fast and proper reply.
    thanks in advance.
    Regards,

    Hi,
    After the upgrade, you will have to do the security upgrade.
    Please follow these steps.
    1. Go To SU25
    2. Run step 2A to 2D.
    3. In step 2C, you shall get the list of all the affected roles.
    Click on first role. It will take you to authorizations of that role. Click on the "New" tab there to find the new objects added to the role after the upgrade.
    Note: You can open the same role in the unupgraded system to check.
    4. Provide the access to the required authorization objects.
    5. Disable the unwanted authorization objects.
    6. Generate the profile.
    7. Follow the same steps for all the affected roles listed.
    Please note that you will have a list of new objects added.You need to maintain them inorder to avoid any access issues.
    8. After step 2C, complete 2D.
    Regards,
    Imran

Maybe you are looking for

  • Not able to update single file in a non ejb Module related jar

    Hey all, I have depoyed my j2ee application <b>.ear</b> on NW webAS .        This application apart from having all the ejb Modules related jar, <b>also has a jar which has all my properties files</b> being accessed by my application. Very often is i

  • ITunes only plays one song at a time ... help please

    All of my songs are checked, but iTunes only plays one song at a time. I can't figure out why. Any suggestions? It just started doing this.

  • My Airport Express Disconnect From the Cable Every Few Minutes

    Hello, I have had an Airport Express for 3 years and it sometimes disconnects after a few minutes. Actually, it more looks like that the Airport crashes: the "PC Link" light on the cable modem goes off, the Airport lights go off and I cannot find my

  • SOAP Adapter details

    hi all, i am doing R/3>PI1>PI2-->File scenario.(i am working at PI2) here i am importing the XSD's into PI2 through External definitions,for this what SOAP Adapter details i need to provide to PI1. another interface File>PI2>PI1-->R/3 for this scenar

  • STO - Cross Company

    Hi All Please explain the Process and configuration for Cross Company STO Regards Jagadish