Roles  for only display authorizations

Hi Experts,
Can any one suggest me how to creat the role only for display authorizations for basis.
Is any standard role like this? if it is please let me know.
Thanks & Regards.
Reddy V

n k wrote:>
> Hi,
>
> just give the tcodes required with the display activity, that is 03.
I consider that to be dangerous advice because it assumes that activities are checked in all transactions.

Similar Messages

  • How to create authorization role for just displaying query prefix Q and X.

    Hi Expert,
    I hope someone can help me on how to create authorization role for just displaying and executing  BEX  Queries prefix Q and X. I'm currently using SAP BI 7.1.
    Actually, I already created one role called : Z_FORINDO_ONLYDISPLAY_QX
    where I only put in the Authorization Component (in the Role Maintenance - Tcode 'pfcg'):
    -->Manually Business Information Warehouse
        --> Manually Business Explorer - Components
    Activity : Display, Execute, Enter, Include, Assign
    InfoArea : *
    InfoCube : *
    Name(ID) of a reporting component : *
    Type of a reporting component : Calculated key figure, Restricted key figure, Template structure
        --> Manually Business Explorer - Components
    Activity : Display, Execute
    InfoArea : *
    InfoCube : *
    Name(ID) of a reporting component : Q* , X*
    Type of a reporting component : Query
    But, the problem is I still can make changes on that queries (Q* and X*). Even, I still can run query with prefix Z. I use S_RS_RREPU Tamplete for Query Display and execution.
    Please assist. Very much appreciate your help. Thanks.
    Edited by: nadiyah salleh on Mar 18, 2008 11:22 AM

    Question close. This issue has been resolved.

  • WEB UI- only Display authorization for LEADS to users

    Hi Gurus,
    I have a requirement like i need to give only display authorizations for users to leads.
    I have created a new business role and assigned only search links. but in that search link we have Create New option. How i need to disable this.
    Users needs only display authorizations for Leads.
    Waiting for reply...
    Regards,
    Ajay.

    Hi Ajay,
    First of all, It is possible to disable the New button on the Search page without any code change. There is an SPRO setting which is to be done in order to achieve this.
    You might have created a new z navbar profile as you have created a new business role as per your business requirement.
    Lets take an example, you want to disable the New button on Contact Search Page. follow these steps:
    1.Go To T. code /ncrmc_ui_nblinks
    2. Select the Z navbar profile you have created for your business role
    3. Double Click on "Define Generic OP Mapping" in left hand side
    4. Select Object Type as BP_CONTACT and remove the Following entry
    BP_CONTACT     D Create     MD-BPCP-CR          MD-CONP-SR
    Please note the Obj. Action here D Create, if you remove this entry it means you are disabling the Create Action for this business role for object Contact.
    Hope this will help you.
    Regards
    Ajay

  • Only Display Authorizations User ID..

    Dear Experts,
    I want to create a User ID in SAP ECC 5.0 which have all SAP System authorizations, but only in Display mode...
    Meaning, the user can access all possible SAP T-codes but cannot create or modify anything... He has only Display rights...
    Can you please suggest me what to do?
    Thanks,
    Jignesh Mehta

    Hi Jignesh,
    there are already some threads here in this forum regarding display-only users/authorizations. One good entry point for your search is sap_all-display.
    Pleae make use of the search function!
    Thank you,
    b.rgds, Bernhard

  • Role for only creating Infopackages

    Hi,
    We would like to give authorizations  only for creating Infopackages in Quality system . I mean remaining things others only should have Display access..
    Please let me know the procedure for procedinng this
    Thanks in advance..

    I think you can do this using this authorization object...
    S_RS_ADMWB:
    Definition
    Using this authorization object, you can restrict the work done with certain objects in the Data Warehousing Workbench.
    Defined fields
    The object contains two fields:
    "Data Warehousing Workbench Object":
    You specify the Data Warehousing Workbench object that a user can edit.
    The following objects exist:
    <b>SourceSys</b> Source system
    <b>InfoObject</b> InfoObject
    <b>Monitor</b> Monitor
    <b>ApplComp</b> Application component
    <b>InfoArea</b> InfoArea
    <b>Workbench</b> Data Warehousing Workbench
    <b>Settings</b> Settings
    <b>MetaData</b> Metadata
    <i><b>InfoPackag</b></i> InfoPackage and InfoPackage group
    <b>RA_Setting</b> Reporting Agent setting
    <b>RA_Package</b> Reporting Agent package
    <b>DOC_META</b> Documents for metadata
    <b>DOC_MAST</b> Documents for master data
    <b>DOC_HIER</b> Documents for hierarchies
    <b>DOC_TRAN</b> Documents for transaction data
    <b>DOC_ADMIN</b> Administration of document storage
    <b>CONT_ADMIN</b> Administration of Content systems
    <b>CONT_ACT</b> Installation of Business Content
    <b>BR_SETTING</b> Broadcast settings (not including your own settings, which have one of the following distribution types: Broadcast E-Mail, Broadcast to Portal, Broadcast to Printer)
    <b>USE_DND</b> Drag and drop to InfoAreas and application components
    <b>CNG_RUN</b> Attribute change run
    <b>REMOD_RULE</b> Modeling Rule "Modeling Rule" for the remodeling tool
    IMG_BI BI-relevant activities in the IMG (Customizing)
    <b>OLAP_CACHE</b> OLAP cache objects
    <b>BIA_ZA</b> BI accelerator monitor checks and activities
    "Activity":
    Specifies whether you are permitted to display or maintain a subobject
    Display Source System (Activity = 03)
    Display InfoObject (Activity = 03)
    Display Monitor (Activity = 03)
    Display Reporting Agent Setting (Activity=03)
    Display Reporting Agent Package (Activity=03)
    Display Documents for Metadata (Activity=03)
    Display Documents for Master Data (Activity=03)
    Display Documents for Hierarchies (Activity=03)
    Display Documents for Transaction Data (Activity=03)
    Maintain Source System (Activity = 23)
    Maintain Application Component (Activity = 23)
    Maintain InfoArea (Activity = 23)
    Maintain InfoObject (Activity = 23)
    Maintain Settings (Activity = 23)
    Maintain InfoPackage (Group) (Activity = 23)
    Maintain Reporting Agent Setting (Activity=23)
    Maintain Reporting Agent Package (Activity=23)
    Maintain Documents for Metadata (Activity=23)
    Display Documents for Metadata (Activity=03)
    Maintain Documents for Master Data (Activity=23)
    Display Documents for Master Data (Activity=03)
    Maintain Documents for Hierarchies (Activity=23)
    Display Documents for Hierarchies (Activity=03)
    Maintain Documents for Transaction Data (Activity=23)
    Display Documents for Transaction Data (Activity=03)
    Manage Document Storage (Activity=23)
    Manage Content Systems (For example, Switch to Content System) (Activity=23)
    Install Business Content (Activity = 63)
    Caution:
    The "Install Business Content" activity is not active in the current release.
    (No authorization check is performed.)
    Display Broadcast Settings (Activity=03)
    Execute Broadcast Settings (Activity=16)
    Maintain Broadcast Settings (Activity=23)
    Execute Data Warehousing Workbench (Activity = 16)
    Update Metadata (Activity = 66)
    Drag and drop to InfoAreas and Application Components in the DW Workbench (Activity = 16)
    Start Attribute Change Run (Activity = 16)
    Display OLAP Cache Objects (Activity = 03)
    Delete OLAP Cache Objects (Activity = 06)
    Display BI Accelerator Monitor Check Results (Activity = 03)
    Execute BI Accelerator Monitor Actions (Activity = 16)
    Regards,
    rocks

  • Display Authorization for MASSD

    Hi,
    There is a requirement for giving a user only display authorizations for MASSD.
    I've tried various combinations of objects, however have been unsuccessful so far..
    Pls. help.
    Thanks,
    Saba.

    Hi Saba,
    the proposals (values maintained in SU24) should save time to role administrators.
    The developers maintain those values which make sense in their eyes. As example if they provide a transaction for creation of an item, they propably would maintain the activity 01, for a display transaction actvt=03 and so on. That will save time to admins, as they would not have to enter the values once more (compared to an empty field....). Of course, that proposals are still proposals only!
    For complex transactions it makes sense, to have a proposal of which authorization objects are necessary to be able to execute that transaction.
    Maybe you can remember the old procedure before pfcg had been invented - it was hard work first to identify all the objects checked with its values, then create the corresponding authorizations in SU03, then create the corr. profiles in SU02 and finally assign that profiles to users in SU01. That was really time consuming....
    So the invention of pfcg opened a very comfortable and quick possibility for that tasks with a high range of automatism. Of course this automatism can only be as good as the values which are behind it. So having accurate SU24 settings help a lot.
    So enjoy pfcg
    b.rgds, Bernhard

  • Cannot create profile for IMG display only access - Timeout

    Hello all,
    I have created a role for IMG display only role. It has hundreds of Org values and fields. I have made ACTVT=03 in change Authorization
    Everything is fine except when i click to create profile, the system does starts processing but its taking hell of a time. It times out since the system has time out after 9000s. Anyway 2 hrs for creating profile..phew!
    Is there a way I can create profile?
    Alternatively, Is there a simpler way to create role for IMG display only access?

    How are you building your role?  It shouldn't be timing out - might be worth having a chat with your basis team.
    Alternatively, if you can save the role (but not generate it) you might be able to generate it in the background via transaction SUPC.  It's better to understand why you cany create it first though.

  • How would you create a read/display only applicaiton montior role for SRM

    Hello,
    I was hoping to get some insight on how to create a display/read only SRM Application monitor role.  This role would be used by our Service Desk to perform basic trouble shooting before escalating.  Currently in our system it is tied into a tab named SAP Administration and has the capability of doing more than read.  How do you create a read version of this to only display the application monitoring in read mode? We currently have an SRP role that has the followiing auths below.  Would a EPP portal role need to be created and if so how>  Thank you for any assistance.
       Manually   BBP Component                                                BBP
              Manually   SRM: General Access Authorizations in EBP                    BBP_FUNCT
               Manually   SRM: General Access Authorizations in EBP                    T-SD59003000
                 Function in SRM (for Authoriza MON_ALERTS                                                                  BBP_FUNCT
    - Todd

    Hello,
    I was hoping to get some insight on how to create a display/read only SRM Application monitor role.  This role would be used by our Service Desk to perform basic trouble shooting before escalating.  Currently in our system it is tied into a tab named SAP Administration and has the capability of doing more than read.  How do you create a read version of this to only display the application monitoring in read mode? We currently have an SRP role that has the followiing auths below.  Would a EPP portal role need to be created and if so how>  Thank you for any assistance.
       Manually   BBP Component                                                BBP
              Manually   SRM: General Access Authorizations in EBP                    BBP_FUNCT
               Manually   SRM: General Access Authorizations in EBP                    T-SD59003000
                 Function in SRM (for Authoriza MON_ALERTS                                                                  BBP_FUNCT
    - Todd

  • Restrict Authorization in SAP_ALL & SAP_NEW for SCC4 T-CODE only display

    hi,
    I want  to restrict 'Change' mode for SCC4 T-CODE to devuser having complete authorization with profiles SAP_ALL and SAP_NEW. Only 'Display' should be allowed for SCC4. For devuser no roles are assigned.
    For Other Users Roles are assigned with restriction in Authorization at "Basis: Administration-> Table Maintenance (via standard tools such as SM30)> Activity" for authorization object S_TABU_DIS only 'Display' is allowed.
    Abhijit.

    Jurjen Heeck wrote:>
    >... something else to make a part of SAP_ALL not work?
    2 ideas:
    - If the regeneration of SAP_ALL could check that the user running it does not have any SAP_ALL authorizations? Meaning, they would need to know exactly which non-SAP role authorizations (their technical names) have that authority in it. Many folks who only work with SAP_ALL don't know how to do that
    - If there were some way to isolate the program parts which are required to change SCC4 such that they can only be run with root priveleges, then you do not need to give your SAP system (with SAP_ALL) root access...?
    Disclaimer: Just ideas! Complete overkill!!
    => Does restricting the user's access sound like a much easier idea now?
    Cheers,
    Julius

  • Role for display Authorizations

    Hi All,
    We need to know if thre are any standard Roles available by which i can have all Display authorizations in Production system.
    Currently we have many Custom roles and this thisng is really messed up in our organization. So i have suggested to Standardized the role related issues and starting with MM, i would like to know if in production we can have access with all Disply rights for all relevant authorizations along with SPRO display. Can anyone suggest something on this?
    Also if we need to create some "Z" or "Y" role; please suggest how we can achieve it.
    thanks a lot in advance!
    Prashant

    Hi Prashanth,
    First identify all the transactions which you want to have to give display authorization.
    Go to PFCG--> Enter All transactions which everyou want to give authorization for display.
    Save.
    Go to Authorization tab check for objects vreated for relevant transactions and provide display as activity in those objects.
    With Regards,
    Vijaykumar P

  • Authorization Object for role creation for query display?

    Hi,
    Can Anybody here tell me what is the Authorization object that we use for role creation for query display?
    I want to assign a role to the newly designed query! that query does not have any role so far!
    Pls suggest me
    Thanks,
    Ravi

    Hi,
    I could make the authorization tab green by entering the authorization object!
    But user tab still remains red as it is not allowing me to enter my username in the user tab!
    in the user tab  i am unable to enter my user name?
    Any suggestions?
    Thanks,
    Ravi

  • Authorization roles for display access to PD transactions

    Hi all,
    There is a requirement to create a new security role to allow display access to PD transactions :
    > Organisational and Staffing Display PPOSE,
    > Display Position PO13D,
    > Display Organisational Unit P010D
    With this role, display access needs to be restricted to view organisation units and positions within the line of business where the position with this security role sits, eg position is within Direct Sales and Service 55001641 therefore they can only view organisational structures that report through to this top org unit.
    Any inputs regarding this would be appreciated.
    Regards,
    Manasee

    Try with  object 'S_ENQUE' and ID 'S_ENQ_ACT'...
    Hope it helps!
    Bye,
    Roberto

  • Authorizations to restrict Query Designer with Only Display option

    Hello,
    I have looked all most all possible ways in internet to find out a suggestion/solution for the below. But Invain.
    I would like to know the Transactions, authorization objects and profiles  that are responsible to restrict users not to change and copy queries from QD.
    I need only display option for queries.
    Also,please confirm shall we restrict the same from Transaction SCC4.
    Thanks In Advance.

    Hi there,
    Since you're talking about a QD system, you should lock it in transaction SCC4.
    In case you need to change things in QD without opening the system in SCC4, you can go to transaction rsa1->transport connection and click on Object Changeability. In there you can define what paricular options are "opened for changes" even with SCC4 in close mode.
    Also, for roles having that objects, you should use the authorization object S_RS_COMP and S_RS_COMP1 with Activity with value 02 - Display
    Diogo.

  • How to make accounts display only via authorizations?

    Has anyone setup CRM 2007 to get the account page to be display only? We don't want to allow certain users to manage accounts directly in CRM and would like to lock this down via authorization objects. We can't seem to figure out what authorization objects are needed to lock it down appropriately. Thanks in advance.

    Hi James,
    We've had a similar requirement. We used sap note 1260695.
    Using this BAdI you can customize that depending on the BP role, some areas (e.g. marketing attributes) are
    editable, and others (e.g. address data) are only displayed.
    As an alternative, you can use note:
    Note 1259940 - Authority check for accounts depending on roles
    Hope this helps.
    Regards,
    Wim Olieman

  • Display authorization for plan data

    Dear All,
    I have to split users into two categories as reviewers and planners.
    I have created two roles from rsecadmin. For plan users it is working perfectly but for the reviewers system gives an authorization issue.
    Plan users auth:
    0TCAACTVT - ACTIVITY : 02
    Reviwers auth:
    0TCAACTVT - ACTIVITY : 03
    Is there any possibility to do it but copying queries as not input enabled?
    Thank you very much.
    Alkan

    Dear,
    That ROLE will be SAP_ALL_DISPLAY
    "what is to be done"
    just assign the role to the display user via SU01
    Hope this help!
    Also refer this ,
    DISPLAY ONLY AUTHORIZATION
    Regards,
    R.Brahmankar

Maybe you are looking for

  • Updated iPod touch 5th generation to IOS7, but it fails to activate.

    In order to update my iPod, I had to restore it prior to the update. It finished updating and took me through the set-up. After connecting to my wifi, it leads me to a screen with the message: "Your iPod touch could not be activated because the activ

  • How do I connect shuffle the home theater system

    How do I connect ipod shuffle to home theater system?

  • Problems with TDP for Oracle

    Hello, I'm having problems setting up TDP for Oracle. When I run a backup, I get the following error stack from RMAN: RMAN-00571: =========================================================== RMAN-00569: =============== ERROR MESSAGE STACK FOLLOWS ====

  • Running Crystal Reports in background mode

    Ist there any way to run Crystal Reports against R/3 (ECC) in background mode instead of as a dialog user? We're having timeout issues since the dialog timeout is set to 30 minutes. We have several reports that run quite a bit longer than that. Updat

  • Slideshow Using Multi-State Objects

    Hi, I created a slideshow in an Indesign document using multi-state objects. The slideshow has foward and backward buttons to navigate the slideshow. The slideshow works fine in Indesign but when I export the document as an intereactive pdf, the slid