Roles Authorizations Sap Bw BEx
Hi Guru
I need authorizations for creating a query, modifying an existing query , Executing and Displaying the Query result with the Bex Analyzer. This is for the Key User, but I want that the user don't access or view infocube navigate in the infoareas.
Thanks a Lot
Hi,
You can check your user's authorization by going to trxn: rsecadmin, then selecting "Analysis" tab and selecting "Execute As". Now enter the user name in the "Execution as User:" option and thenc heck the "With Log" check box.
Select trxn: RSRT, enter your Query name and try accessing your query.
After this you can check the log for the exact authorization the user has.
Hope this solves your issue.
Regards,
Balajee
Similar Messages
-
SAP BI : Roles & Authorizations
Hi,
I am working on roles & authorizations for SAP BI 7.0 How can I create authorization for a scenario mentioned below:
One user (userid ALAN) has two vendors under him viz V001 & V001A.
V001 has access to plant A001, A002 and
V001A has access to plant A002, A003, F002.
The data is created in SAP R3 and brought into SRM using criteria based on document type say ELEM. Even though V001 does not have access to plant A003, it can create documents of type ELEM. The business does not want this document to appear for V001.
The business needs documents to be displayed as follows, irrespective of documents existing in SAP R3:
Plants A001, A002 for V001 and
Plants A002, A003, F002 for V001A.
Please confirm if the following approach will work:
Create vendor - plant role
Role 1
Vendor = V001
Plants = A001, A002
Role 2
Vendor = V001A
Plants = A002, A003, F002
Assign User ALAN both roles Role 1 and Role 2.
Please suggest a solution as I have to deliver about 2000+ roles by end of week.
Thanks in advance.Hi,
Seems that you are looking for a merge of the authorization. Please take a look in the note 1000004 where you are going to see the explanation about the merging.
1000004 - Merging and optimizing analysis authorizations
This documentation should help you.
Regards,
Rafael -
How to determine role authorization of user in MAM?
Hi everyone,
I'm new to SAP and SAP MI, and I am currently implementing (or "enhancing") a MAM. I have the following question on user authorization:
In terms of role authorizations, does anyone know how I can determine what roles an authenticated user have from SAP? For example, if user A logs into the MI Client, and if this user accesses the MAM, is there a way for the MAM to know what kind of user roles he/she has? Is there a SyncBo that will give me such info? I checked the JavaDocs for the SyncBo's, but they have NO descriptions. The closest thing that I found was in MAM090 (Interface com.sap.mbs.mam.bo.MAM090). There are getter methods for getRoleGen(), getProfileResource(), and getPartnerRole(). Are any of these usable?
Are there any good documents that I can look at to determine what each SyncBo's does?
Many thanks!
JeffreyHi Jeffrey!
Here are the 3 different checks you have to look at"Users & Authorizations" for setting up your MAM Users.
(1) SAP Backend:
(1a) The SAP MAM User who synchronizes with the Backend from the MI Client should have all necessary authorizations for Plant Maintenance Components of the SAP System that are associated with your MAM Scenarios.Pl refer to the following SAP Authorization Objects I_ALM_ME ,I_AUART,I_BEGRP,I_BETRVORG,I_CCM_ACT ,I_CCM_STRC,I_ILOA,I_INGRP,I_IWERK,I_KOSTL ,I_QMEL,I_ROUT ,I_ROUT1,I_SOGEN,I_SWERK,I_TCODE ,I_VORG_MEL,I_VORG_MP ,I_VORG_ORD,I_WPS_MEB ,I_WPS_REV in your Backend System and have it assigned to the User Profile, based on your requirement.
(1b) Service User for setting up the MAM & MI Landscape: This user logon info has to be setup in the RFC Destination that is associated with your MAM25 SyncBOs, to logon to the Backend System and this user should have the basic authorizations required to establish the connection.
(2) MI Middleware: The SAP MAM User who synchronizes with the Backend from the MI Client should have the following Authorization Objects assigned to his/her profile. S_ME_SYNC, S_RFC, S_TCODE.
(3) MI Client: Refer to MI Security Guide.Pl note that the MI Client MAM User is same as the Middleware User and the Backend User.You should be taking care of this already.This is just a FYI.
Let me know, if you are looking for any other additional info.
Thank You
Gisk -
Check user role/authorization during Web report run-time?
Hello again,
I ran into a problem. I need to check <b>user's authorization during webtemplate execution (run-time)</b>. I want to have a possibility to allow in one web template extra functionality (through template menu) to key users. Normal users, who are running same report, should not have this extra menu visible.
Is it possible to check user authorizations or roles during web-template run-time?
Thank you!
VitaliyHi Harinam,
From my logic your are right.
The restriction is in two new roles (Requestor and Approver role).
But ->
If I assign my approver role the selection possiblities of the request types during the AR creation is restricted and the AR search function does not work.
If I assign my requestor role the restriction of the request type is not there, but the AR search function works again. :-(
If I assign the original approver role of sap I have the same behavoiur for the AR search.
Both new roles are a 1:1 copy of the SAP standard roles - > Exception, ristriction on request type 'Execption Approval' is not displ.
I have execute ST01 now. If I try to open the log, the system syst "No records that correspond to these search criteria".
But I have found something else.
The problem appears only if I search for Process ID "Access Request Approval Workflow".
If I select other Process ID such as "Control Assignment Approval Workflow" or "Fire Fighter Log Report Review Workflow", everything works fine.
Very strange!
BR
Melanie -
Role authorization for product selection
Hi All,
i have a requirement for which i need your help. Now my Account Manager can see all products while placing an order. I want to restrict his selection to only 5* and 6* products. That means when he will look for placing an order in the next time, he should only see 5* and 6* products not all products. Can you please tell me how to go about this role authorization.
your valuable inputs will be appreciated.
Regards,
SasmitaHi,
I feel Access Control Engine would be the most elegant and futuristic solution.
However, you need to review all the solutions suggested. Solution suggested by Shalini and Ashish are more practical. However, generally partner product range is used in case of Sold-to parties.
Please review all the solutions suggested and take decision based on circumstances at your client's end.
You can get more information about Access Control Engine at
http://help.sap.com/saphelp_crm40/helpdata/en/04/0177f9bb67ac4cafb84bb4d4c1d8fc/frameset.htm.
Also there are several guides and cookbooks on ACE at service market place.
Regards,
Deepak -
Implications of uploading roles from SAP 4.7 to SAP ECC 6.0 EHP 5?
HI Gurus,
Please tell what would be the cons for uploading the roles from SAP 4.7 to ECC6.0 EHP5.
Would there be issues in doing the same?
Regards,
SonuHi Sonu,
There me be changes in authorization object assignment for the roles. Some objects may be deleted and new objects may be addedd to the transactions.
Instead of uploading you can better get the list of transactions for every role and create them newly in ECC 6 EHP 5 system and maintain them according to the old roles.
Thanks,
Kranthi -
Role Authorization Vs ACL in cProjects
We do not want to use ACL (Authorization at the Project level) to grant authorization. We are looking for a way to have this authorization by roles. Not too sure if the minutest of details can be controlled by authorization objects.
Of the few requirements that we have, one goes as follows:
1. We need a role of "Resource Manager" to be able to view all projects. However, this role must not be able to edit the project structure. This is possible. However, another requirement that we have is that this role must have all "admin" level access at the "Resources" level. Which means, this role must be able to staff roles and assign tasks to roles and resources, but must have read-only access to the project structure.
Can this be done?
2. Another requirement is with regard to status management. We want a role to have the authorization to set only select statusses. We have a combination of standard and custom stasusses in the status profile that we are using. We look to control the access for roles by which one role can only set a few of these statusses.
Can this be done?
Thanks and Regards...Hi Peter,
We have exactly the same need, and unfortunately everything is not solved yet.
1/ In standard, there is no distinction between project and role authorizations. This means you need 'admin' auth at project level if you want to manage the roles. We created an OSS message for this, and SAP answer was to create a development request --> Until then, and if we get a positive answer, nothing can be done to separate project & role authorizations. So there is no solution today.
2/ For the statuses, we add to enhance class CL_DPR_STATUS_MANAGEMENT, methods GET_PERMITTED_USER_STATUS and/or GET_PERMITTED_ACTIVITIES. Thanks to this, we are now able to filter the status list that is populated in the screen.
Regards,
Matthias -
hi all,
am a BI consultant.
in my project CRM part there is a need for creating new users and for that roles & authorizations has to be assigned.
i want to do it.
in this business same role will be having diff autherizations as per the location.
example: mumbai Branch manager for mumbai
baroda BM for baroda,and few other cities.
how to assign the auth for this.
we need to restrict each one with their respective branches.
in this what is the role for a Basis consultant.
kindly give the road map for this problem. so that i will start learn.
jeevahi
for roles and authorisation please go through this link
https://www.sdn.sap.com/irj/sdn/go/portal/prtroot/docs/library/uuid/0062e975-48c2-2910-e49c-8d6ad796ba21
https://www.sdn.sap.com/irj/sdn/go/portal/prtroot/docs/library/uuid/0062e975-48c2-2910-e49c-8d6ad796ba21
it will surely help you
best regards
ashish -
Roles & Authorizations in FICO
Hi frends,
can anybody help me in preparing the Roles & Authorizations.What is the procedure and How can we prepare?what is the base?
Regards
Sap Guru
[email protected]Fist you decide based on your organosation, how many roles you want, ex: user , officer, manager.
even if you want create like AR users, AP usera, like that also.
Once rolls ready assgin your employees to your rolls.
For Each roll you decide which type of transaction you want give access.
wHAT ARE ALL TRANSACTION CODE YOU GIVE ACCESS TO ROLL , THAT T.CODES ONLY WORKED FOR THAT EMPLOYEES based on the Roll CREATED.
CHANDRA. -
Import SAP BW roles to SAP BO withour prefix
Hello,
we are re-using our SAP BW authorizations roles for folder authorizations in SAP BO.
Therefore we import roles from SAP BW source system and add these roles to different BO-Groups. Folder authorizations are maintained for these BO Groups.
Import of roles works - but all imported roles / Groups start with a prefix "<SYS-ID>~<CLNT>@"
So if we promote groups/authorizations to qa and prod system we have to add BW roles in each system.
E.g.
DEV-System:
DEV~001@BW_ROLE --> added to BO Group "BW"
Promotion to QA-System:
BO Group contains Role DEV~001@BW_ROLE and QA~002@BW_ROLE has to be added.
How to avoid this?
There is a similar issue with user which has been resolved by maintaing registry setting.
HKLM\SOFTWARE\SAP BusinessObjects\Suite XI 4.0\Enterprise\Auth Plugins\secSAPR3\SimpleUsernameFormat
Thanks and best regards,
Christian
P.S. we are using BI 4.1Hello Ingo,
A small clarification w.r.to security maintenance in BO w.r.to SAP report execution...
If I have roles created/maintained in SAP to restrict the access in terms of what data is available for an end user, and if these roles have been imported into BO and have been assigned to different groups as per the user grouping roles in SAP.
And later, if additional access in terms of data has been assigned to the SAP role....does the group on BO has to be changed as the data access provided is only on SAP side.
As my understanding is the groups on the BO side are only to dictate what level of access does the user have for BO tools in terms of changing/creating/deleting BO reports and not what kind of data is accessed in SAP.
Can you please confirm the same.
Thanks
Dharma. -
Roles not displayed in BEx Analyzer for NW2004s
We are evaluating a technical upgrade only from BW 3.5 to Netweaver2004s. Under this plan, the 3.5 security will not be migrated to 7.0. We are using SAPGui Frontend 6.40 for BI. The existing BW 3.5 roles are not display in the Role Menu of SAP NetWeaver BEx.
Any ideas on this?
IsbellGot the following response from SAP and this resolved the issue
please add the parameter
DELETE_DOUBLE_TCODES with PATH = 'NO'
into the table: ssm_cust (via tx: se16)
The settings in SSM_CUST defines a compress mechanism for the user menu
known as "Redundancy avoidance" and described in notes 357877 and 357693
Redundancy avoidance deletes easy access menu entries for doubled
transaction codes whenever SSM_CUST contains
1. an entry CONDENSE_MENU with PATH = 'YES' and
2. either an entry DELETE_DOUBLE_TCODE with PATH = 'YES' or no entry
DELETE_DOUBLE_TCODES, at all.
If you don't want doubled transaction codes to be deleted, then simply
add an entry DELETE_DOUBLE_TCODES with PATH = 'NO' into table SSM_CUST.
Suresh -
Necessary Roles/authorizations required to Userid for workflow assignment.
Hi all,
Am working on a Custom workflow assignment.
This is the first time, customer is working on workflows in this system.
Henceforth, we need to do basic setup/configuration, before starting actual work.
I want to know, what all Roles/authorizations are required for my userid throughout the assignment.
Currently, we have got,
EXX_BC_SAP_ALL_RESTRICTED :: All authorization without basis
SAP_BC_BMT_WFM_ADMIN::Administrator for Business Workflow
SAP_BC_BMT_WFM_DEVELOPER::Developer for Business Workflow
SAP_SWFMOD_ADMIN::Workflow Modeler Administrator
Are these sufficient or do we need any other roles?
With above authorizations, i am unable to access below mentioned t-codes,
SWNCONFIG Extended notifications for business workflow
SWU3 Automatic Workflow Customizing
SWWCOND_INSERT Schedule background job for work item deadline monitoring
SWWCLEAR_INSERT Schedule background job for clearing tasks
Pls let me know the role, i need to get for above t-codes.
Kindly go thru your SU01 t-code & let me know what all roles are used in your workflow system.
cheers.
santosh.Hi,
I recommend you to have roles related to SWLD tcode (SAP menu Workflow). The basis must know what are the exact names.
These are some roles:
SAP_BC_BMT_WFM_ADMIN --> Administrator for Business Workflow
SAP_BC_BMT_WFM_CONTROLLER --> Process Controller for Business Workflow
SAP_BC_BMT_WFM_DEVELOPER --> Developer for Business Workflow
SAP_BC_BMT_WFM_GP_ADMIN --> Role for Guided Procedure Business Workflow Administrators
SAP_BC_BMT_WFM_GP_SERVICE_USER -->Service User for Guided Procedures Business Workflow API
SAP_BC_BMT_WFM_PROCESS --> Business Workflow Implementation Team
SAP_BC_BMT_WFM_UWL_ADMIN --> UWL: Administrator for Workflow Functionality
SAP_BC_BMT_WFM_UWL_END_USER --> UWL: End User for Workflow Functionality
SAP_SWFMOD_ADMIN --> Workflow Modeler Administrator
SAP_SWFMOD_TRANSPORT --> Access to transport manager
SAP_SWFMOD_USER --> Workflow Modeler Administrator
SAP_WF_ADMINISTRATION --> Business Workflow: Work for administrator
SAP_WF_CONTROLLER --> Business Workflow:Work for process controller
SAP_WF_EVERYONE --> Business Workflow: Work for Everyone
SAP_WF_IMPLEMENTATION --> Business Workflow: Work for Implementation Team
Regards, -
Preparation of Roles & Authorizations
Dear Guru's
Can you plz help me in preparation of Roles & Authorizations...plz provide me the step by step procedure for this.
Will assign the ponts
Regards
Sap GuruHi,
Roles and authorisation are created by Basis Person.
We as functional consultant creates the same in Excel sheet and provide the same to Basis team.
1. Identify the user along with there roles.
2. For executing the roles, the person needs the authorisation i.e. T.Codes
3. Create a Role and under that attach T.Codes. Then the role is attached to the
user(s).
4. In each T.Code, you have can restrict by certain objects which will differ
organisation to organisation.
Hope this is of some help, if yes, please assign points.
Regards,
Harish -
How can we remove the commas from the Formula value in SAP BW BEx query
Hi All,
How can we remove the commas from the Formula value in SAP BW BEx query
We are using the formula replacing with characteristic.The characteristic value needs to be display as number with out commas.
Regards
Venkat.Do you want to remove the commas when you run the query on Bex Web or in RSRT?
Regards -
SAP BW Bex 7.3 Queries not working with Enterprise Portal (EP) 7.3 ABAP Stack
Dear Portal Gurus,
we want to integrate SAP BW Bex Queries 7.3 into an Enterprise Portal 7.3 EP ABAP Stack only installation.
1) We have Done SSO between EP And BI System
2) System Object is Created
3) When we trying to create Iview of BEX 7.3 report, its executing that report on BI server, we don't have java stack on BI System
4) We have updated the required table in Bi system for executing the report on EP
5) RFC is OK, System Object Test is OK, Report is working independently from Business Explorer, but not working from EP
There no irj services available on BI system, as it is only ABAP stack.
Can anybody help us in achieving our requirement
Thanks in advance
Michael WeckerHi Michael,
To integrate portal with BI you need to perform BI Portal integration steps.
Refer to a document link below for guidance purpose.
http://www.sdn.sap.com/irj/scn/go/portal/prtroot/docs/library/uuid/b0a5216a-349c-2a10-9baf-9d4797349f6a?overridelayout=t…
Ensure that you have performed all these relevant steps.
Hope this helps.
Regards,
Deepak Kori
Maybe you are looking for
-
I had my laptop for about two years now and it has worked great with the exception of it overheating. Now I am starting to have a number of issues: 1. Blue screen memory dump while playing games. It said something about Kendal hardware. I did researc
-
Why are my colours in Illustrator so dull??
I'm hoping somebody can help me with this as it's driving me nuts I'm working on digitalising my girlfriends artwork which needs to be very bright for the effect of her work to be seen but for the life of me, i can't get the right colours out of Il
-
Where is the "General Options" menu?
Hi, I'm a new Blackberry user and I just purchased a Pearl 8110. I noticed that when I place a call, my number comes up as "Private" or "Unknown" to the person receiving the call. I looked it up in the manual and it said to go to the "General Options
-
I wonder if you can help me... Does anyone know of a utility that will place the rating, play count and last time played information from the iTunes library into the ID3 tag of a music file? Does anyone know why this information is only stored in the
-
Nokia 6303i Firmware 7.10 Update
hello, i have a nokia 6303i with the firmware 6.61. now i want to update the firmware to 7.10. and i want to do it over my cellphone. when i go to options and search for new software then my cellphone says no new software available. but there is a ne