Real role and ideal role comparison

Hello, ladies and gentlemen,
I would like to write an experimental program that would help me understand how some weird and big roles, I have here, were created. I feel that some parts of the roles come from the SU24 suggestions and some were obviously changed/ added manually.
Here is what I would like to compare
a) the ideal role, if it would be generated only (no manual changes) based on the SU24 suggestions for the "objects" listed in the role menu
The premise here is that I can generate a reasonable and usable role based on the SU24 entries only. If you think this is crazy, let me know, but also let/ help me build the report so I can learn myself:))
b) a real role - the one that exists in the system
I can get a list of the auth objects that are parts of the role easily (tab AGR_1251).
I can also get a list of SU24 suggestions for various objects I can use in the role menu.
The last step to be able to build the comparison is that I don`t know how to connect role menu entries with the role. Or better: I can easily get a list of transactions used in the menu. That`s fine. But I can also add a function module into the menu (for example) but see this one as a SERVICE in tables only, without the additional details (FM name would be nice).
So I am not able to use this "SERVICE" to go to USOBX_C and get the SU24 suggestions for the function module.
Can anybody suggest a way, how can I get a whole list of objects used in a role menu, not only the transactions?
Thanks,
Otto

Hi,
N means that you just added all transactions and additional stuff to user's menu in PFCG and you open authorizations for that role for the first time. So it takes all values from SU24 but you still need to enter values for all fields which don't have any proposed value in SU24. So it's really hard to tell what ideal role looks like. D means that it reads current authorizations for that role. So you can compare results. So you can have some extra authorizations in second results. These are manually added objects. You can have some extra authorizations in the first result. These should be deleted authorizations. Your problem will be with merged authorizations (it's impossible to split them).
BTW PRGN_ACTIVITY_PROF_INTERN_READ is used by SUPRN_AUTH_DATA_IN)_EXP_MODE and this FM is basically really similar to FM SUPRN_PROFILE_GENERATOR which is used in PFCG.
Cheers

Similar Messages

  • GRC 5.3 | ERM | Disabled Role Comparison Field

    When executing a role comparison in ERM, the only way to select the role is to use the magnifier next to the field, search and select the role. As we have thousands of roles, this is not userfriendly.
    Is is possible to enable the field for role name in the role comparison "section" so that can be searched on roles using wildcards.
    Thx.

    Hello Kraell 
    Considering that this feature is not available as of now but if you still have dire need for the same, you may contact SAP if they can treat this as an enhancement request (for which you might be charged a bit) and deliver this feature to you.
    Regards,
    Hersh.
    http://www.linkedin.com/in/hersh13

  • Role Comparison Cross System - alternatives to RSUSR050

    Hello Experts,
    Would there be an alternative for Cross system role comparison outside of using RSUSR050 ?
    We have a variety of landscapes and are on different basis levels...SAP notes have corrected all but one
    which is older release level- business not ready to upgrade this one
    I have dabbled with SCMP tcode but results are not clear or complete. I was using table AGR_1250 and 1251
    Any thoughts appreciated ..
    Dan.

    Thanks Bernhard,
    i guess i need a little instruction on how to use this tcode (if that's the best method). When i compare  2 roles that are different
    SCMP notes they are the same ? but i notice there is a field that selects Role id - only allows one numeric input. Can't seem to
    get an entire display of the auth objects. I did this by entering our RFC dest and table name AGR_1251.
    Any other alternatives.   The SUIM (RSUSR050) works fine functionally and we have RFC dest but because of the differing Basis levels on this particular destination server- the results are erroneous and incomplete.  Thanks !

  • Mass Roles Comparison in ECC System

    Hi Forum,
    I am know working on Role-Redesign project, which involves about 4000 roles.
    We have to eliminate the roles, which have same transactions and activities.
    SUIM provides only single role comparison....
    Is there any possibility to compare set (range of) of roles with a set (range of) of role in ALL-COMBINATIONS. 
    Regards.
    Sathish Ram.

    Hi Surya,
    There is one way. Download the roles in excel files. I would suggest not more than 80-100 roles in one go. Then for each file convert the various columns into one column using concatenate function. Now for a given set of roles you will 2 files one for each of the involved systems. Now create a third files in which you collate the date from both the original source files and then do a column comparision. It is tedious but in given circumstances the shortest way. I think it will take less time then do role comparision on one to one basis. Take help from an MS excel expert.
    Regards.
    Ruchit.

  • Real Instruments and Master Track icons dessapeared

    This is when i open garage band
    This happen when i start to used. The Real Istruments and Master Track icons desappeared. What is this happening and how can I fix it?

    THis can either mean, that the GarageBand application needs reinstalling or that you have corrupted settings and preferences files in your user account. To find out if something in your user account needs fixing, try to launch GarageBand from a different user account.  You could try to log off and sign  into the Guest account or create a second account for testing using the System Preferences "Users&Groups" pane.
    If GarageBand works well using a different account, try HangTime's "oddball probs" fix and trash the GarageBand preferences file - move com.apple.garageband.plist from the Preferences folder in your user library to the Desktop.  See the FAQ:
    http://www.bulletsandbones.com/GB/GBFAQ.html#oddballprobs
    (Let the page FULLY load. The link to your answer is at the top of your screen)
    But if it even does not work from a different account, trash GarageBand and reinstall it.
    Regards
    Léonie

  • I need to host a Shared PDF on SharePoint. If it is on SharePoint can only one person comment at a time? I know documents have to be checked out when using SharePoint. I need multiple users to be able to comment in real time and see comments in real time.

    I need to host a Shared PDF on SharePoint 2010. If it is on SharePoint can only one person comment at a time? I know documents have to be checked out when using SharePoint. I need multiple users to be able to comment in real time and see comments in real time. Is this possible?

    try here:
    http://www.bbb.org
    File a complaint with them. Verizon will call you to fix the blunder.
    But remember it is always up to the customer to insure what they are getting and what it costs. Don't trust the word of a sales person who makes their living on getting that sale. Lies, deceit or false promises will be and have been used by sales people for thousands of years.
    Good Luck

  • Please read my question carefully, this is, I think, a question for the experts. It's not the usual name change question.   When I setup my new MacBook Pro, something slipped by me and my computer was named First-Lasts-MacBook-Pro (using my real first and

    Please read my question carefully, this is, I think, a question for the experts. It's not the usual name change question.
    When I setup my new MacBook Pro, something slipped by me and my computer was named First-Lasts-MacBook-Pro (using my real first and last name).
    I changed the computer name in Preferences/Sharing to a new name and Preferences/Accounts to just be Mike. I can right click on my account name, choose advanced, and see that everything looks right.
    However, If I do a scan of my network with my iPhone using the free version of IP Scanner, it lists my computer as First-Lasts-MacBook-Pro! And it lists the user as First-Last.
    So even though another Mac just sees my new computer name, and my home folder is Mike, somewhere in the system the original setup with my full name is still stored. And it's available on a network scan. So my full name might show up at a coffee shop.
    Can I fully change the name without doing a complete re-install of Lion and all my apps?

    One thought... you said the iPhone displayed your computer's old name? I think that you must have used the iPhone with this computer before you changed the name. So no one else's iPhone should display your full name unless that iPhone had previously connected to your Mac. For example, I did this exact same change, and I use the Keynote Remote app to connect with my MacBook Pro. It would no longer link with my MacBook Pro under the old name, and I found that I had to unlink and then create a new link under the new name. So the answer to your question is, there is nothing you need to do on the Mac, but rather the phone, and no other phone will display your full name.

  • Is there a way to hide apps from the app store? I don't want my kids to see those "free" apps that nag you to spend real money and download their other apps! I can hide them from "purchased apps", but they still show up when browsing for new apps!

    Is there a way to hide apps from the app store?
    I don't want my kids to see those "free" apps that nag you to spend real money and download their other apps!
    I can hide them from "purchased apps", but  they still show up when browsing for new apps!
    Is there a way to hide them so that my kids will never see them when looking for new apps?

    Not other than parental oversight. On the computer you can implement Parental Controls on a separate user account that they would use. You can then block certain websites. But you cannot do that on the iPad.
    You could change your iTunes account such that they cannot access it in order to buy or download apps.

  • I record multiple tracks (3-5) from real instruments and vocals. I want to send these files to a collaborator to add more tracks to, but Garageband wants to mix these down (which I don't want). How can I send the multiple tracks files to my friend?

    I record multiple tracks of real instruments and vocals wth Garage Band. I want to share the file with a collaborator so he can add another instrument or two. I have not found a way to do this without the process mixing down the tracks. I don't want them mixed down like when I send them to Itunes. Also I can't seem to just attach a file directly to an email for sending purposes. I thought I saw a method to do this with software instruments, but how do you do it with real instruments? I've tried every process on the "export" list to try to accomplish this, without success. Thanks for any breakthrough advice on this!

    As isteveus said - for large projects uploading to a server would be best.
    Also I can't seem to just attach a file directly to an email for sending purposes.
    But for completeness's sake , you cou can mail a project, if you ctrl-click the project and use "Compress xxx.band". This will compress the project and create a zip file, that you can mail (if it is not too large). But ask your friend for the maximal file size allowed as a mail attachment.
    But whichever method you use to share your project, be sure you include all loops and instruments, if your friend does not have the same JamPacks installed. You can bundle the loops into the project by saving it as an archive. "File > Save as" and check the "Archive Project" option.
    If this option should be disabled, you can force it to become active by editing your project slightly. It is only available, if the project needs saving.
    Regards
    Léonie

  • Read data in real time and save as an excel file

    Hi,
    I want to write a LabVIEW progarmme which able to read data in real time and save it as an excel file from Varian Vacuum muli-gauge.
    It is using RS232 port.
    Can anyone give me some examples or point me in the right direction?
    I am a beginner of LabVIEW. Hope anyone can help me.
    Thank you very much!!
    Joanne

    Thanks for your reply.
    I just use MAX to verify that the rs232 port is operational.
    However, there is an error (please refer to the attachment).
    One possible reason is in MAX I am trying to do the default command *idn? ...but it doesn't work.
    I read the vacuum multi-gauge manual but I don't know which command should I use...
    I attached the manual and can you tell me which command should I use?
    Or can you tell me other possible reason for this error code?
    Thank you very much. 
    Joan
    Attachments:
    Varian Multi-Gauge Controller.pdf ‏2747 KB
    error1.JPG ‏111 KB

  • Question on How to Use LI and NP Data Comparison Report

    Hi,
    We are trying to figure out how to make the Transaction Code PC00_M42_LLPD (LI and NP Data Comparison Report) work. What file type (.xls, .txt, etc) should be used?  Anyone who is familiar with the transaction, please help.
    Best Regards,
    Bry

    Somewhere in the Oracle 8.0 documentation it is stated that one
    enviroment per each thread is required if I want to ensure
    complete concurrency of different threads accessing databases.
    But isn't this a waste of resources since only Handle Alloc &
    Free functions use Enviroment handle, hence they should be
    mutexed for access from concurrent threads.
    But the most time-consuming functions are ServerAttach &
    SessionBegin which shouldn't be mutexed since they have each
    their own Server/Session handle.
    So my question is if a single OCI Enviroment is enough for the
    most demanding tasks or should I create one enviroment per
    thread?
    Most folks are happy with a single environment. The mutex on the
    env handle is only taken when the OCI library is allocating some
    memory for internal operations.
    Tomislav.

  • BI content required for Real Estate and Plan Maintenence

    hi;
    I have BW 7.0 server with BI_CONT addon and support package level is 6 ie SAPKIBIIP6.
    now we need the business content for real estate and plan maintenence. i have read documents which contains the business content , but i couldnt find the particular one am searching for ie..real estate and plan maintenence....
    should i update the patch?
    regards
    seethy
    Edited by: Seethy Meerasahib on Jun 18, 2008 1:57 PM

    hi
    its already  available in the InfoProvider..
    Real estate comes under= Financial management and controlling
    Plant maintanece = Defence force and public security..
    regards
    seethy

  • [ACE] Real servers and VIP in the same VLAN

    Hello.
    I´m facing an issue because the real servers and the VIP address are in the same VLAN, when a request comes from an external client to the VIP (crossing an ASA firewall) , the ACK gets back using the IP of one of the real servers instead of the VIP so this traffic is blocked by our WAN firewall probably due the inspection rules.
    My question is if there is some way make the VIP the address who ACK´s that requests? Creating a new VLAN would be complicated because there are other services already running on those real servers.
    Thanks a lot,
    Miquel

    Hi Miquel,
    Please do source nat on ACE so that return traffic gets sent to ACE and not FW. Pasting an example for you.
         ==========================================================================
         One-Armed Load Balancing with VIP, Servers, & NAT Pool on the Same Subnet
         ==========================================================================
    login timeout 0
    access-list ANYONE line 10 extended permit ip any any
    rserver host SERVER_01
      ip address 192.168.1.11
      inservice
    rserver host SERVER_02
      ip address 192.168.1.12
      inservice
    rserver host SERVER_03
      ip address 192.168.1.13
      inservice
    serverfarm host REAL_SERVERS
      rserver SERVER_01
        inservice
      rserver SERVER_02
        inservice
      rserver SERVER_03
        inservice
    class-map match-all VIP-30
      2 match virtual-address 192.168.1.30 tcp eq www
    class-map type management match-any REMOTE_ACCESS
      description remote-access-traffic-match
      2 match protocol telnet any
      3 match protocol ssh any
      4 match protocol icmp any
    policy-map type management first-match REMOTE_MGT
      class REMOTE_ACCESS
        permit
    policy-map type loadbalance first-match SLB_LOGIC
      class class-default
        serverfarm REAL_SERVERS
    policy-map multi-match CLIENT_VIPS
      class VIP-30
        loadbalance vip inservice
        loadbalance policy SLB_LOGIC
        loadbalance vip icmp-reply active
        nat dynamic 1 vlan 451
    interface vlan 451
      description Servers vlan
      ip address 192.168.1.2 255.255.255.0
      access-group input ANYONE
      service-policy input CLIENT_VIPS
      nat-pool 1 192.168.1.10 192.168.1.10 netmask 255.255.255.0 pat
      no shutdown
    ip route 0.0.0.0 0.0.0.0 192.168.1.1
    Let me know if you have any question.
    Regards,
    Kanwal

  • My iPad 2 won't charge unless I push the cord in real tight and hold it there. Right now I have 3% battery left! HELP PLEASE!

    My iPad 2 won't charge unless I push the cord in real tight and hold it there. Right now I have 3% battery left! HELP PLEASE! Oh my gosh.

    This sounds to me like a hardware issue. Take it to an Apple Store or Apple authorized repair service.

  • I think my spouse is using apps like YouMail and many more to throw me off her real location and different things of that nature. How do I tell if I'm miss informed?o

    I think my spouse is using apps like YouMail and many more to throw me off her real location and different things of that nature. How do I tell if I'm miss informed?o

    I suggest you talk to your spouse: honest communication is the only approach when this kind of question bothers your mind. There's no way that anyone here can tell you anything useful.

Maybe you are looking for