S_tcode

Hi All,
The long text box in the role says the t-codes are added to this role on -
date. But the t-codes are not present in the object S_tcode.
Did i miss the opening credits or is it all that the role designer did not add them as per the description?
Thanx

How do you know they are not in S_TCODE? Have you checked in PFCG? Are you sure they are not using ranges? Sometime if you are searching on SUIM "" or ranges do not appear. EG searching for SU01 but the role contains SU.
May be a good idea to check in PFCG or table agr_tcodes to find out what is in the roles.
Thanks,
Sam

Similar Messages

  • Open field in object S_TCODE

    I've deleted a tcode from a role in menu tab. Now when I look at the object S_TCODE in the role it has an open(blank) field. I cannot delete this blank field from the object as S_TCODE shows up only in display mode though you enter the role in change mode. Further I do not see this blank field in the menu tab assuming that the blank field might got transfered from the menu. Please suggest how to remove the blank field from the object?
    Thank you,
    Partha.

    Hi,
    I had some similar issues already. The yellow status of S_TCODE came from a blank entry in the menu. If the menu is big, its hard to find that entry, which has to be removed from  the roles menu. As a workaround to identify that 'blank' entry check table agr_hier for that role. Select Reporttype=TR and Report=  (means leave the field empty and set as operator '='.
    In the field Parent_ID you can identify now the node under which this entry is located and with the OBJECT_ID you can find the text in table AGR_HIERT (with that text you can use the search function in pfcg to find that entry(ies).
    Then simpyl delete these entries from the menu and merge the authorizations. S_TCODE shall be 'green' afterwards.
    b.rgds, Bernhard

  • S_TCode Full Authorization in all Roles

    Hello,
    We have created roles as per the role matrix given by the client. All are absolutely working fine but when i see the report at user level the transaction codes assigned to user we can see almost 100000 T-Codes authorization. I analyzed and found that S_TCODE authorization object consists of value as " * " so that is the reason i am finding all the T_codes authorization.
    How this has happpened? We have not given these value in any of the Role.
    Regards,
    Narasimha Kumar

    > How this has happpened? We have not given these value in any of the Role.
    If you didn't do it manually then it must have been a (very strange) proposal value coming from SU24. Have a look in table USOBT_C, filtered on object S_TCODE. If there's a star in the low or high column, the 'name'  column tells you which transactions' proposal you need to fix in SU24. After that re-read the authorizations for roles containing this transaction.

  • S_Tcode not populating in simulation

    Hello-
    When running a simulation in CC 5.2, and using permission level analysis, you have to manually add s_tcode in the object table. 
    Steps:
    Insert a role, press simulation, add an action, click on the objects button; s_tcode is not populated.  When it is not added, it is not causing any conflicts, which is incorrect.  In an older version of CC 4.0, before a support pack was installed, this problem was evident.  Is it a product-level issue with CC 5.2?  If so, how do you work-around it?
    This is an urgent issue, since we have to run simulations almost everyday, as we have not implemented Risk Terminator.  Thanks!...
    Noah
    Edited by: Noah Phillip on Feb 26, 2008 7:51 PM

    Ibrahim-
    Yes, I understand, but not inserting s_tcode in the object manually produces wrong results after executing the simulation.  Inserting s_tcode manually produces the correct results. 
    The same issue was evident in CC 4.0, until SAP produced a patch for it.  I am wondering if they overlooked this patch while developing CC 5.2...
    Noah

  • S_Tcode authorisation object Inactive

    After adding T-code in the role in  Development,generated the profile and transported it to Regression system but when it was transported to Production , the S_TCODE became inactive and the transaction related to the particular role were not accessible.
    Do anybody suggest me ,why this was happened.
    Is it happened due to transporting the changes in production during working hours or reason is some technical.............
    Thanks
    Manoj

    Hi Manoj,
    Check if the associated profile has this object in it. (S_TCODE) for that tcode.
    Even if someone has changed the role in QAS, and assuming the same transport request has been imported in production after i dont know what QA( if S_TCODE is inactive , how did it pass QA?, how did the tester execute the tcode?) , the role will have this object in production, unless changed and generated here too!
    Do let us know how the profile looks like with the time stamps
    Thank you
    Abhishek

  • S_TCODE in CRM Roles

    Hi all,
    I am relatively new to CRM and have the following question regarding design of CRM security roles.
    We have a marketing manager who needs to log on directly to the CRM production system to execute a transaction. I have used the CRMD_UI_ROLE_PREPARE programme to create the PFCG role from the business role and this all works ok.
    Now they need to be able to execute the transaction so I am wondering:
    Is it good design to add s_tcode to the role with all the UIU* components?
    Should transaction roles be kept seperate?
    Is S_Tcode the only object used for this or are there further considerations for CRM?
    Thanks.

    Richard,
    Since you are relatively new to CRM I suggest you obtain and look through the Security Guide for your version of CRM. From there you might have more specific questions regarding your CRM role design. Its a great start.
    https://websmp208.sap-ag.de/~form/sapnet?_SHORTKEY=01100035870000401180
    Thanks,
    Matt

  • S_TCODE object is not coming in role after adding profile of another role.

    Dear Gurus,
    I have added profile of a existed role to a newly created role in pfcg (edit->insert authorisation-> from profile), but I can't see the S_TCODE object of that role of the added profile.
    For some roles, it appears, but for some, it don't come.
    Please let me know the reason behind this, so that I can go forward.
    Regards,
    Nilutpal.

    Hi,
    S_TCODE will be added in your authorization profile when you add some T-Codes in Menu Tab of that role in PFCG.
    This may be the case for your role.  In this case it will not be copied with profile. It will be added only if you add the T-Code in Menu Tab.
    The other case is if you directly insert it in bthe authorization objects. In this case it will be copied with profile.
    Please revert.
    Regards,
    Jaya

  • Tcode in S_TCODE Object Error

    Hi Experts,
    When we are searcing for "Y" Tcode in Menu Tab in "XXX" Role in PFCG,It was not there in menu Tab.
    But it was there in S_TCODE Object.S_TCODE Object is maintained one.It was not added manually.
    Ex:When I am searcing for SM59 in menu tab,it was not showing any output.But when I given RFC(in find) it displaying all tcodes with RFC name(including SM59 which was not shown when I searched as SM59 ).But it is showing as Service in the place of tcode.
    But SM59 was there in S_TCODE Object & it was showing in SUIM & SE16 dump.
    Kindly help to solve the above issue.
    Regards,
    Karthika

    I've just noticed you mentioned 'Service' below in your original posting?
    "But it is showing as Service in the place of tcode"
    (Haven't worked out how to do a quote on here yet   so I apologise for the crude entry
    Is this on the menu tab that you are seeing the transaction called service please? If so then this would have been added via the authorisation default button instead of the insert transaction button. This can be used to 'hide' a transaction from view of the user (a bit flakey but a final resort sometimes!)
    The transaction will have a hand holding a green card icon next to it instead of the usual three-D box.
    Table AGR_BUFFI holds this info and not AGR_TCODES or AGR_1251 - are you using SUIM or SE16(N) to search?
    Standard SUIM will return the 'SM59' fine but SE16(N) won't.
    See you have solved it but I'm not clear what happened yet so I'll keep digging 0;0
    Edited by: David Berry on Sep 20, 2010 7:49 PM

  • Report S_BCE_68001398 and Object s_tcode

    Hi Guys
    When running report S_BCE_68001398 with tcode suim i.e
    Tcode suim >>> Users>>> Users by complex selection criteria .. By transaction authorizations and Insert a tcode. I get a list of tcodes that are being used by users.
    When I do the same thign from another point i.e Tcode Suim>>Roles >>> By transaction assignment (rsusr070) .. Insert tcode that i am working with..I get a list of roles that supposedly should have the tcode inside it.
    The list seems to be different.
    The reason for this is that it looks as  when the role was created they did not add the tcode in the i.e tcode pfcg >>> under the menu tab but rather went into the authorization tab and added the object s_tcode and add the transaction.
    Is there a way to pick these roles up from the  User information system when runnign reports on where a specific code is being used.
    Hope this makes sense
    Thanks

    Moods,
    Yes there is a difference in the way the reports check the tcodes.  One just looks at the tcodes in the menu (AGR_TCODES table) and the other looks at the S_TCODE object within the role.
    To find all the transactions at the S_TCODE object level in the SUIM reports run a report by complex selection criteria (either users or roles) then fill in the authorization object S_TCODE and hit enter or "entry values" then enter the tcode in the field.  Execute...
    Cheers,
    Ben

  • Facing probolem in s_tcode

    hi,
    after running su53 i am getting missing authorization of in object s_tcode and when i am trying to insert the same tcode it is showing, tcode does not exists.
    please let me know why i am not able to add that tcode even though it is there in missing authorization.
    regards,
    Tarun Chandel,
    SAP Basis Security Consultant
    <telephone_number_removed_by_moderator>
    Edited by: Julius Bussche on Aug 28, 2008 9:40 AM

    >
    Sneha Kulkarni wrote:
    > Try this method :-
    >
    > You can add missing tcode manually in S_TCODE authorization objects in authorization tab of the role.
    >
    > Hope this will work !!
    > Thanks,
    > Sneha
    Do not do this!
    Why do you think that in later releases SAP has locked S_TCODE from manual updating (unless you manually insert another instance of S_TCODE object)?
    We need to find the root of the problem before deciding what to do.  It may be that this additional t-code be added into SU24 for the original transaction or alternatively configuring SE97 depending on the situation....there are plenty of option depending on the actual cause.

  • Standard S_TCODE object showing Yellow trafic light

    Hi All,
    Recently I have noticed standard s_tcode object is showing Yellow traffic light (Not fully maintained) in one of the role in ECC6 system. I have tried to maintain by clicking on change button which usually doing with other objects and got succeeded to do modifications.
    I have downloaded that role and uploaded in to another ECC6 system and observed that s_tocde is in green color and not allowed me to modify it as usual.
    As per my knowledge standard s_tocde object is not modifiable but we can modify manually inserted s_tcode object.
    Please advice.
    Regards,
    Sri Vandan.

    Hi,
    What happens if you delete the role in your original system and re-upload and generate?
    I have tried that one also but getting same problem.
    propably the SU24 entries have been changed (for field S_TCODE) since the last mergeing of authorization data....
    Bernhard, can you please elaborate on this.
    Regards,
    Sri Vandan.

  • TCD field in display mode in S_TCODE

    Hello,
    I have a requirement to remove t-codes from TCD field under S_TCODE object in the role itself and NOT from the role menu.However when I go to PFCG>Change>Auth.Data Tab>Change auth.data>, the field TCD is DISPLAY only and hence removal of t-codes cannot be done.
    Why is this and what would be the workaround.
    Thanks.
    Mani

    Thanks Debmalya.
    The issue is - why the change is possible for certain roles and only for this role, Would not a PFCG Change function allow you to 'Change' field level values.
    Also as Diego has suggested , I have verified that this role is not part of a customizing project.
    This requirement is from one of a remote customer my organization supports.
    Mani

  • Behaviour of * in S_tcode object

    Hello,
            does anyone knows the behaviour of * in S_tcode aothorization object.
    1) If i assign ME* in S_Tcode in role manually.do i will get auth ME00 and ME01 tcode execution rights.
    but in my case i am not able to execute ME01.
    Regards
    Nilesh

    If you give ME* - ME21 then you will get all tcodes starting with ME as you have given a values that supersedes ME21 (ME*)
    If you are reporting via SUIM then it is possible that it is reporting transactions that are entered in the menu or evaluating the complete tcodes it sees in object S_TCODE.
    I don't have a system in front of me to check right now, but every system I have used will give you access to pass the auth check against S_TCODE for all tx starting with ME if you enter ME* into the S_TCODE object.

  • Statndard S_TCODE object in unmaintained (yellow) status

    Hi Experts,
    I came across a role in which standard S_TCODE object is in unmaintained(yellow) status.
    Is there any limit to number of Tcodes which can be added under S_TCODE object?
    Please help me out to find the reaon.
    Thanks,
    Mohit

    Hi Julius,
    Its new to me too Thanks for sharing the notes. I didn't guess and hence said as per my knowledge Limiting the guess to my knowledge.
    Thanks agian!!
    Rgds,
    Raghu

  • S_TCODE cannot be modified ?!

    Hello,
    I have a profil which includes the well-known auth. obj S_TCODE, but it is the first time this one appears in grey. That means I cannot maintain it manually.
    I have used the 3 ways to generate a new profil to get rid off that unmodifiable s_tcode, but without success.
    By the way, if I insert manually this object I can maintain it.
    Any clue guys?
    Regards

    Hello Julien,
    It seems that you are trying to change S_Tcode object in authorization tab. But when a Tcode is added in Menu tab of a role then you cant remove that Tcode from S_Tcode object but you need to remove from Menu of the Role.The Tcodes can be added in 2 ways , in the Menu where u add the Tcode or at authorization object level in S_TCODE object.When added in Menu the Tcode is visible in S_TCODE object but is greyed out.
    **Reward points accordingly
    Junaid

  • S_TCODE..TCD..FROM..TO

    When in the role maintence, if we do a search for the S_TCODE object we hit it. no wwhen we double click we get the box which states the tcodes executable. my question is :
    1. What does the From and To coloumns  mean?
    Is it a range of tcodes? does ti differ if I give one below the other?
    Thanks

    Do you mean
    From  -  To
    AC05  - AS00
    AS03  - F-01
    If yes then it means All tcodes falls under this range will be included.
    eg
    1. AC05, AC06, .... ACZZ, AD01, .... ADZZ, ..... AR00,....,ARZZ, and AS00
    2. AS03, AS04,..... ASZZ,AT00,...ATZZ, AU,...AZ,B....... E and F-01
    So from Rance AC05 to F-01 excluding AS01 and AS02.
       ***Rewarad the points if it is helpful****
    -Pinkle

Maybe you are looking for