RSSM and Profile sap_all

Hi guys,
we have an abnormal behaviour of Custom Authorization Objects and sap_all in BW 3.5.
We created a new custom authorization object with RSSM (let's say ZGG_BUKRS) in order to design new Roles for End Users and it works.
The problem we have is with those users that have sap_all / sap_new profiles: it seems they need to be authorized with ZGG_BUKRS (new Custom AUthorization Object) in order to work properly. In fact they receive BRAIN 805 "No Authorization".
Did anybody of you experience such a problem?
Any idea about solutions?
Thanks in advance
GFV

Gianfranco Vallese  ,
Okay, then check the role where you used this authorization object... are the values for this object defined properly...
if you know the role name...take one user from this role...
go to RSSM1 give the user name and execute that perticular query... F3, you can see the logs where exactly it's strucked.
Cheer's
HVR.

Similar Messages

  • Compliance Calibrator Design - Roles and Profiles

    Hi guys,as you know SAP's authorization concept involves generation of Roles into Profile before it can be assigned to a User. In CC, i wonder why is there a need to segregate Roles and Profiles into 2 seperate functions. Isnt it already sufficient to analyse roles instead of profiles? Profile are names which is too technical which i feel should be omitted unless really necessary.
    Well, unless it is to cater for indirect assignment where profiles are granted to position/org unit etc... I will also be trying out whether there is a difference when you only batch analyse a Role and intentionally excluding the 'profile' whenever a new role is created. Will the system work fine when i do a role analysis?
    Cheers!

    I agree that profiles are old fashioned and should be phased out.  The system has to stop people from being able to maintain profiles directly and assign them directly before they do this though.  SAP_ALL etc can be converted and assigned as a role.  It would make the whole authorisation concept just that little bit easier.  We are talking about a German company though!
    Also, you don't need profiles for indirect assignment.  You can relate roles to the position using PFCG!  Click on the organisational management button on the user-tab, next to the user comparison button.
    Using profiles (ie, maintaining directly and assignment) is highly recommended against.

  • How to find the users who r assigned to profile sap_all through su01

    how to find the users who r assigned to profile sap_all through su01

    you can get into SUIM-->where used lists, check for users with profile SAP_ALL you can get a list of users who have
    it. and you can get into SUIM through SU01 from user information system link.
    you can execute RSUSR002 from SA38/SE38.
    RSUSR002  is the report which gets you the whereused list for profiles within roles, users.
    you can get it from transaction SECR ofcourse you are executing the same report.
    you can get from UST04 table and obviously USR04 also because sometimes you  miss some details from UST04 because of sync problems.

  • After BI 7.0 Upgrade, Authorization Roles and profiles are not visible

    Hi Gurus,
    We have an issue with authorization roles and profiles are not visible for all end users with new Bex Analyzer (BI 7.0) tool. But still they can see these roles with old Bex Analyzer ( Bex 3.5) tool.
    As a developer I have SAP_ALL acces and I can see all authorization roles in new BEx Analyzer (BI 7.0).
    I verified in SU01 for user access and every are assigned there roles and they are green.
    Do we need to add any new authorization object to fix this issue, please let me know
    Thanks and appreciate your help.
    Thanks
    Ganesh Reddy.
    Edited by: Ganesh Reddy on Oct 26, 2009 4:41 PM

    Hi Ganesh,
    check the behaviour, if you assign
    S_USER_AGR                          
       ACT_GROUP = "..name of the assigned role.."
       ACTVT = 03 (for "display")    
    b.rgds,
    Bernhard

  • After BI 7.0 Upgrade, Roles and profiles are not visible

    Hi Gurus,
                                  We have issue with the roles and profiles, all our users doesnt see any roles or profiles in Bex Analyzer, under there user access after BI 7.0 Upgrade. 
                                   When I go and check there profile in SU01 and I can see all roles are assigned but not able to see in the Bex Analyzer reporting tool.
                                   Do we need to do any configuration settings after BI 7.0 upgrade to visible roles. This problem with every user.
                                   Your help will be really appreciated.
    Thanks
    Ganesh Reddy.
    Edited by: Ganesh Reddy on Oct 22, 2009 5:19 PM

    Hi Mohan/Vijay,
                            Sorry for little bit late. I have all authorization roles access, and users dont have that access. Difference between our roles is I have SAP_ALL and SAP_NEW.
                            But when they login with old bex analyzer they can see all roles, but not with new bex analyzer.
                            Please some suggest me still I need to run SU25.
    Thanks
    Dayaker Reddy.
    Edited by: Ganesh Reddy on Oct 26, 2009 10:19 AM

  • BW Roles and profiles Tables

    I would like to download a list of all users and what roles and profiles each has.  I did it once before but now I can't remember the table names.  Can anyone help?

    Hi,
    Roles:
    SAP_BW_DEVELOPER
    Profile:
    SAP_ALL
    S_BW_D____
    S_BW_D____1
    Authorizations are
    S_Rs_Admwb_a
    S_rs_adw_a
    S_rs_exp_a
    S_rs_wb_all
    Links for user roles:
    http://help.sap.com/saphelp_nw2004s/helpdata/en/52/6714b6439b11d1896f0000e8322d00/content.htm
    http://help.sap.com/saphelp_nw2004s/helpdata/en/42/271d24d86211d2961a0000e82de14a/content.htm
    http://help.sap.com/saphelp_nw2004s/helpdata/en/e4/15e48efd6c11d296430000e82de14a/frameset.htm
    http://help.sap.com/saphelp_erp2005vp/helpdata/en/d3/559a4271c80a31e10000000a1550b0/frameset.htm
    http://help.sap.com/saphelp_erp2005vp/helpdata/en/4e/52b74065448431e10000000a1550b0/frameset.htm
    For profiles and authorisations:
    http://help.sap.com/saphelp_nw2004s/helpdata/en/52/67151e439b11d1896f0000e8322d00/frameset.htm
    http://help.sap.com/saphelp_erp2005vp/helpdata/en/20/efcbfed8a511d397110000e82de14a/frameset.htm
    Also chk this link..
    http://www.bwexpertonline.com/archive/Volume_04_(2006)/Issue_10_(Nov_and_Dec)/V4I10A2.cfm?session=
    screenshots..
    https://www.sdn.sap.com/irj/servlet/prt/portal/prtroot/docs/library/uuid/1b439590-0201-0010-ea8e-cba686f21f06
    Hope this helps,
    regards
    CSM reddy

  • How to create a role using profile SAP_ALL

    I want to create a role which has the same authorizations as SAP_ALL except several tcodes.Because SAP_ALL is not a role ,I can't do it by the way of copying role. how should I do?

    Hopefully you do not believe that this is sufficient ...
    If you've left the S_DEVELOP authorizations users that are assigned to that role still can perform any action - simply because they can develop own coding or modify existing coding ... (respectively: using the debugger to bypass AUTHORITY-CHECKs).
    Please keep in mind: the role concept is driven by the business scenario perspective (e.g. role "purchaser", "HR staff", "user administrator", etc.). All the technical details are derived ("hidden" as detail). Your approach is performing the opposite: using a technical vehicle and wrapping a role around it.
    Furthermore: you have chosen a very special "authorization profile" (SAP_ALL). In real life there is no employee that is entitled to do "everything". Even the CIO is not entitled to perform any action (e.g. he should not be authorized to perform just any technical operation - e.g. database reorganization). Just because it is not his "role" (in the company).
    => there is no "SAP_ALL" role in real life

  • I have moved to uk from ireland and bought new iphone, set up using my existing Apple ID account and profile but won't let me buy install or update apps??

    I have moved to uk from ireland and bought new iphone, set up using my existing Apple ID account and profile but won't let me buy install or update apps??
    Can anyone advise me on what I need to do?
    My existing account is linked to ireland as my bank account details are there, does this make a difference?
    Please help!

    Until you get a UK bank account and credit card, buy and redeem UK iTunes gift cards for use in the iTunes and Mac App Stores. But you need to switch your region/country to the UK store in your account information, as you can't use UK iTunes gift cards in the Irish stores, the gift cards are country specific.

  • PSE 11 - MacOX 10.7.5  -MORE-Printer and Profiles Not Working Correctly

    Changed Profiles after printing many prints..     this time the first print was dark/black muddy as on my previous discussion...  follow up prints fine....
    see early discussion about 12 hours ago

    I will suggest you to re verify that the Profile of your image and Profile of printer are same.
    PSE11 prints an image in two different scenario:-
    1. When Color Handling is governed by Photoshop Elements  and  2. When Color handling is governed by Printer
    I will explain you these two scenario in detail.
    1. Open your image in PSE11.
    2. Go to Image > Mode and note down the image mode.
    3. Now launch Print dialog.
    4. Click "More Options" button present on Print dialog.
    5. Now select Color Management tab.\
    6. Here you can find Image Space , this should be same as you noted down in 2nd step.
    7. From here you can control Color Handling options.
        a) From "Color Handling" drop down you can select either "Printer Manages Color" or "Photoshop Elements Manages Color".
        b) If you select Printer Manages color then you can see the profile of your printer in Printer Profile, that you cannot change.
        c) But if you will select "Photoshop Elements Manages Color" then you can change the Printer Profile.
       Now in both cases, for best result, make sure that that Image Space and Printer Profile is same.
       Also if you are using Photoshop Elements Manages Color then please turn off the Color Management of printer from your Printer Preferences option.
    If your Printer Profile is known to you then you can also change the Image mode from Image > Mode menu.
    For best result of printing it is necessary that both Image and Printer profile are same.
    Hope it will help you in your problem.
    Cheers !!!

  • How to remove Seperator from check-in and profile check in pages

    How to remove Seperator from check-in and profile check in pages
    The seperator is included on the checkin pages, which is present in the std_page with name "std_namevalue_separator", this is called by td_document_checkin_fields and std_document_file_fields.
    Defination of include:
    <@dynamichtml std_namevalue_separator@>
    <$if not isUploadFieldScript$>
    <tr>
         <td width="<$captionFieldWidth$>"><hr /></td>
         <td width="<$captionEntryWidth$>"><hr /></td>
    </tr>
    <$endif$>
    <@end@>
    I have to remove the following include from some of the profile check in page.
    Please suggest if anyone have some idea, how to proceed.
    Thanks,
    Sumit

    791848 wrote:I have to remove the following include from some of the profile check in page.The key here is that you want to do this in some profiles, not all profiles or globally, if I'm reading this right.
    Without writing a component, you can put this code in the "side effects" box in the desired profile(s). This code removes the horizontal rule, and inserts a non breaking space in its place.
    <$setResourceInclude("std_namevalue_separator","<$if not isUploadFieldScript$>
    <tr>
    <td width=\"<$captionFieldWidth$>\"> </td>
    <td width=\"<$captionEntryWidth$>\"> </td>
    </tr>
    <$endif$>")$>YMMV. The non-breaking space may get stripped out in the forum.

  • How can I add the status and profile picture features on an account that was created before iOS 5?

    How can I add the status and profile picture features on an account that was created before iOS 5?

    Have you looked at the previous discussions listed on the right side of this page under the heading "More Like This"?

  • Use of RSSM and authorisation processing type

    I create a authorisation object for customer using RSSM. At the report level, I want to create a variable on the "customer".
    If I create a User Entry/default value processing type  for the characteristic variable on "Customer", how will the system handle data restriction checks for different roles for "Customer".
    Or to make my question better,
    Are authorisation objects created in RSSM useful for only Variables with "Authorisation" processing type.
    Thanks
    Simmi

    hi Simmi,
    no, it's useful in infocube level, in rssm we mark which infocube(s), all queries to the infocube will have authorization check. processing type authorization will display report with restriction to all values given to the user.
    to restrict user by e.g customer, you need to maintain in role (transaction PFCG), choose created authorization object (RSSM), and assign value, and assign the role to your user.
    e.g role ZCUST, user A given cust1, user B given cust2 and so on.
    hope this helps.

  • Tables of user and profile

    I need the information on the tables user and profiles, for the information of the SOX of the company, as they are the names?

    Hi Mauricio Ariza ,
      Check these tables, these will be helpful
    Table Name                     Short text
    USH02                          Change history for logon data
    USH04                          Change history for authorizations
    USH10                          Change history for authorization profiles
    USH12                          Change history for authorization values
    Regards,
    S.Manu

  • Security roles and profiles

    Hello,
    Could you please provide information on "security roles and profiles "
    I would appreciate.
    Regards,
    Alex

    Roles give you authorization to specific area of the system. Use TC pfcg and you will see different setting for a role.
    In specific Role -> Authorization -> click on Display Authorization Data.
    Here all specific InfoArea, Cube, ODS, Reporting componets: display, execute and other security rules are defined.
    User Section: defines who has access to this role.
    Multiple authorization are combined to create an Authorization Profile. You defined a profile at TC su01 and under profile section.
    Hope that helps.
    thanks.
    Wond

  • $PROFILES$.FILENAME, $PROFILES$.PRINTER and $PROFILES$.CONC_COPIES

    Hello All,
    I am developing BI Publisher reports. One of my requests is to auto print the generated output(PDF) file.
    When I asked the client to use normal printing functionality from concurrent manager, they said it requires user level profile option setup and it will affect all other reports.
    When I googled it, I found the following profile options used as arguments while creation driver,
    $PROFILES$.FILENAME, $PROFILES$.PRINTER and $PROFILES$.CONC_COPIES
    When these values will be initialized. Can we initialize and reset the values at run time.
    Does this will affect other reports.
    Regards,
    Kannan B

    Hi,
    Not sure on your full requirements, but you can set the printer name on the concurrent program, force the print to 1 copy, and I would guess you don't need the file name.
    Regards,
    Gareth

Maybe you are looking for

  • Scheduling webi report error

    Hi Guys, How u all? Guys I need help from your side, While refreshing Webi report in 3.1, getting error: A database error occured. The database error text is: Failed to execute MDX query. Reason: Inconsistent input parameter (parameter: <unknown>, va

  • How do i export a PDF to PowerPoint

    I need to export a pdf  PowerPoint to powerpoint. How do I do this so I can edit the powerpoint.

  • Production Rule in AME

    Whats the use of Production Rule in AME? Where is it used typically? AG

  • Installing Flash Pro error: Media_db

    Hi, While installing Flash Pro from Creative Cloud, I encountered an error "Camera Profiles Installer 8.0.0.13 {539AEF15-3A2B-4A31-A587-7E90F7D9C700}' information not found in Media_db". What could be the cause? Regards.

  • Safari slow or won't load pages since recent Safari update.

    Safari is slow to load or will not finish loading pages since installing latest Safai update.  I have to constantly use the refresh button to finish loading pages.  Other browsers work fine.  Contacted Apple support, went into safe mode and verified