SAP* user doesnt have full authorizations.

Hi All,
my Admin user for EP7 portal is locked.
Tried to activate the sap* user to chang the password of my admin user,
but strangely the sap* user is not able to do so too.
When i click on User Admin on the sap* user I get a mesage saying
"you have not enough rights to perform this contact your systemadministrator"
I fail to undrstand how can sap* user not have rights to admin...when its purpose is to
act as emrgency admin user.
Now I am helpless as this is the only way to reset admin password....
What should I do...
please help......

Did you restarted the j2ee java.
Also check the below blog
SAP* - The Saviour
Raghu

Similar Messages

  • If the end user doesnt have acess to go through session

    if the end user doesnt have acess to go through sessions , how could he know the errrors occured in his process. can any one sugest me an answer...
    and the data transfer shld be done through session method only, we r not using call transaction......
          thank u
             with regards.........

    there is no other option expect that he should either have the access to check the sessions or else someone who runs the sessions need to get the error log and mail to the user....
    also just u can let know the queue id generated for the session and using program RSBDC_ANALYSE u can check the logs.

  • AmAdmin user doesnt have sufficient access

    Hi,
    Can someone please tell where things would have gone wrong for me to get the problem that I have mentioned below.
    I am using Access Manager of JES 2005Q4. After installation I logged in as amadmin user and added services, users and some of the other activites that the amadmin user can do. All of a sudden I have started getting that the amadmin user doesnt have sufficient access to do any changes in the Access Manager. Wheneven I try to create something new or try to edit any existing data I get "User does not have sufficient access".
    The other insteresting thing is that I am able to log on into the Directory Server console using cn=Directory Manager user and create users which can be viewed on the Access Manager but no changes could be made from AM. I am also not able to change the password or edit the user information when I log through that user as well.
    The strange part I have deployed an application which uses the AMConfig.properties file of the AM for its login module and even through that application I am able to change the password of a particular user.
    My worry is that what could have happened to the Access Manager and how can I solve it and also to avoid this happening again? Can someone please shed some light on this becasue I am totally stuck and I am not able to proceed in anyways to solve this issue.
    Thanks & Regards,
    Soma.

    Hi Everyone
    I installed JES 2005 Q4 on Solaris 10 x86 with schema 2 and Access Manager 7. The Directory Tree is as follows:
    Sol1.nucleussoftware.com:389
    dc=nucleussoftware,dc=com (34 acis)
    DSAME Users
    Internet
    People
    Groups
    Client Data
    services
    nucleussoftware.com
    People
    Groups
    o=Netscape Root (3 acis)
    cn=Schema (6 acis)
    cn=monitor (5 acis)
    cn=config (4 acis)
    Organization DN when I ran "configutil" after running comm_dssetup.pl, was specified o=nucleussoftware,dc=nucleussoftware,dc=com
    This is fresh installation and not any migration.
    Now I create user from Access Manager, http://sol1.nucleussoftware.com/amserver
    There are two organizations 1. Nucleussoftware and 2. Nucleussoftware->nucleussoftware.com
    So I have two locations to create users in People.
    When I create user from Access Manager and try to login into WebMail, I get Login Failed.
    But when I open "startconsole" or "mpsconsole" and open Messaging Server Console and in new user's property, Account Attribute, I mark the check box, and now try to login into WebMail, I get error message, "Mailbox is on a different server".
    I am missing one attribute that I used to get with schema 1 on iPlanet 5.2 for any user, Mail Server Address.
    Please tell me the exact method of creating a user for Messaging.
    Regards
    Amit Bist

  • After trying to up date Itune it has crashed and in trying to reinstall I get a message that mobile device faild to start and check if i have full authorization, where do I find how to get it????

    how do i get past a mobile device failed to start error.....while reinstalling itune in a pc???

    Try the following user tip:
    Troubleshooting issues with iTunes for Windows updates

  • Resetting the Registry so other Users have full access to Flash Player 9

    Does anyone have a solution for fixing the registry after
    installing FP9, so all users can have full access to it.
    I found this site
    http://www.donglefree.com/toppage1.htm
    to fix the installation problem, (and it worked perfectly),
    but now all other users have limited access to the Flash Player.
    (Some sites still say Flash needs to be installed).
    Operating System: Windows XP Home Edition, SP1, Internet.
    Exp. Version 6.0.2800.1106.xpsp2.050301-1526
    Any help would be appriciated.

    Has anyone tried this to fix the registry problem?
    http://www.adobe.com/cfusion/knowledgebase/index.cfm?id=tn_19148

  • New sap user creation

    Hi All SAP experts,
    My company has implemented 2 Systems SAP Landscape with one development and one production server which are running on R/3 Enterprise 4.7 (Kernel Release 6.20) with Microsoft SQL 2000 as database server.
    I have the following questions regarding new sap user creation by using user copy function.
    1.When I request to create new SAP User by using user copy function ,should I just create the user acct in DEV and transport it to PROD System? If yes, how could I do that?
    2.When I request to create new SAP User by using user copy function, can I just create it on PROD System only? If yes, what is the impact?
    3.When using User copy function to create new user acct, should I select all parts (like adress ,defaults,reference user, user groups.....) of the existing user to be cloned to new user acct?
    Thanks.
    Leon

    Hi Leon,
    Answer to your questions in their respective order:
    1. You can create user in DEV and then make remote client copy to PRD system using scc9 t-code. Here you can choose user accounts and authorizations for the copy. ( Rem: Data will be overwritten in target system when copied).
    You can also use client export/import(scc8/scc7)
    But, When you do the client import from the exported files using STMS,you will have to select only one of the transport requests and then STMS automatically selects the other requests for you.
    Then it will show you the different transport requests that you have created during your export, the client copy profile and the target system and client. The customizing and application data is deleted in the target client before copying for all profiles except SAP_USER. This is technically unavoidable (and hence the data will be overwritten).
    So if you can afford overwritting of user data in target client , you can go with the above procedure.
    2. Using  user copy in su01, you can copy one user to another user only in that client and is confined to that system only. So yes, If you want 2 or more users to have same authorizations, profiles ,etc etc.. you can choose this in PROD system.
    3. It depends.. If you want user to be in same group, then you can choose user groups. If you want them to have same authorizations , you can choose roles and profiles... If you want them to have same company address and others,... you can select address.. and so on.
    Also below link provides required steps in case you choose local/ remote client copy:
    http://www.sap-basis-abap.com/bc/client-copy-by-using-scc8-and-scc7.htm
    Hope this helps...
    Thanks,
    Ajith
    Edited by: Ajith Kamath on Oct 20, 2009 8:28 AM

  • SAP User Authentication via Windows Active Directory

    The non-profit company I work for as an SAP Security Admin has been using SAP since 1999.  We are currently running ECC 6.0, BI 7.0, and CRM 7.0.  With fewer than 300 SAP users, we have not implemented CUA, so each of our multiple clients in these systems is managed independently. 
    The company recently licensed and implemented some non-SAP software to be used by all of our employees (~1200) in keeping track of & catagorizing their work time; a very handy feature of this software is that it depends upon Windows Active Directory for user authentication.  Therefore, each employee logs into this time-keeping package by entering his/her standard PC userID & password.  If you can log onto your PC, you can log into the time-keeping software. 
    That got me thinking & researching, because our SAP users - especially those who have access to three or more SAP clients - must maintain their passwords independently in each SAP client that they hope to access in the future.  I'm certainly not the first person who has thought of how nice it would be to permit SAP users to log into all SAP clients across the landscape in which they have defined userIDs, using the same password that they are using to log into their PCs (i.e., the password that is stored & maintained in Windows Active Directory).  My quest has led me to find presentations on this topic that typically involve modules we aren't using & very complicated configurations that we really lack the time & resources to employ; or, to third-party solution providers who claim to be certified SAP partners who would love to sell us more software to provide this convenience, usually irelated to single sign-on, LDAP, etc.  The lowest pricing tier for such software usually would cover many times the number of SAP users we have to serve here - and it feels like trying to push in a tack using a sledgehammer.  It is true that we have not used the same userID for our PCs that we have defined in SAP, so there would need to be some way to translate from one to the other, but our PC password rules are consistent with those we have configured in SAP clients, so it seems to me it should be very simple.   Can anyone lead me to a more straightforward solution?  If not, can you articulate why this has to be so complicated using SAP software when it seems so simple using relatively inexpensive timekeeping sotware?

    >
    Gagan Deep Kaushal wrote:
    > Hi Tim,
    >
    > Its nice to see video.
    >
    > Is that mean using different username on OS and SAP level still we can achieve SSO.
    >
    > Correct if if am wrong.
    > The only thing we need to maintain SNC name.
    Once installed, yes. This is all you need to maintain when users are added. You can even use LDAP if you like to sync all user info between SAP and MS AD domain, but this cannot sync the password, so using SNC authentication instead of using SAP passwords is ideal.
    >
    > So for user test1 i can manage name as p:test2.....  ??
    Yes, that is correct. The mapping is maintained using standard SAP user management, such as su01. The user in AD domain might have long account name, e.g. "firstname.verylonglastname" which is too big for use as a SAP username so you can map this long AD account name onto a SAP user called FIRSTLAST in one or more SAP clients.
    >
    > I think that is what Ronald is also looking, user name need not to be same.
    >
    > Regards,
    > Gagan Deep Kaushal

  • Problem downloaden ebooks. i get the message: 'Elic already fullfilled by another user'  ( i had to authorize adobe digital editions on my comp to be able to share a certain book, but now doesnt download books anymore from shop) How can i solve this?

    Problem downloaden ebooks. i get the message: 'Elic already fullfilled by another user'  ( i had to authorize adobe digital editions on my comp to be able to share a certain book, but now doesnt download books anymore from shop) How can i solve this?

    You has a other Adobe ID in Adobe Digital Edition by the First open of the eBook....or you have open the eBook with empty authorization. When has used a other adobe id should change the adobe id, if not the eBook are looked with the empty authorization. In this case need a new Download of the eBook of his reseller.

  • User unable to view Excel button in ALV grid. Has full authorization

    Hi All,
    A user in our copany is unable to view Excel button in ALV grid. Has full authorization to S_BDS_DS, S_ALV_LAYOUT.
    Please note that this is not the export to Excel button. Its the excel icon which enables the users to view the output in excel format on screen.
    I am able to view the Excel Button. can you pls advise what might be the possible root cause.
    Are there any authorization objects as well that govern ALV Grid buttons (excel) display.
    Please help. 
    Can we add/delete the buttongs in the ALV grid from somewhere..
    Thanks,Phani

    Hi,
    oic, only specific user, not all user.
    I have a similar problem with you, but not excel button but inbox button on initial screen (session_manager)
    deleting this user and re-create this user solved my problem.
    hope it help you.
    rgds,
    Alfonsus Guritno

  • HT1451 Hi All, I have 2 users on my desktop, 1 i-tunes account and log-in but both users have different music contents i.e. one has the full iTunes library and the other only has some songs. How do i get both users to have the same music content?

    I Have 2 users on my computer and both access i-tunes using same password etc. however 1 library has the full content of music but the other one has only partial playlists. How do I get both users to have the same full library?

    The title of my initial post is a bit misleading. I already took a chance deleting one of the iPhones, hoping if I deleted the wrong one, I can still reauthorize it (all with the same Apple ID acct, so not subject to 90-day waiting period, right?) The iTunes database just updated itself, and it says I have 4 "devices" "in the Cloud", but 5 "computers" associated w my account. How can I find out what computers are associated? Isn't there a list I can see? I dont have a clue what computers they might be. If I use the  "Deauthorize All" option, is it a pain to add them all back in. I assume I would have to log in from each computer to reauthorize each one. Would I have to be running the newest OS or version of iTunes to reauthorize? I think I have a PowerBook G4 Titanium with an older OS and iTunes. I'd like to keep that authorized, if possible.

  • In vpd_admin user I have just tried to delete the policy and it doesnt dele

    In the dtabase in vpd_admin user I have just tried to delete the policy and it doesnt delete.
    Just sits there .
    (This works on the live system, just checked.)
    non working system looks like:
    Connected to:
    Oracle Database 10g Enterprise Edition Release 10.2.0.4.0 - Production
    With the Partitioning, OLAP, Data Mining and Real Application Testing options
    SQL> begin
    dbms_rls.drop_policy( 'CF', 'CF_PARTICIPANT_MENTOR', 'CF_PM_POL' );
    exception
    when others then null;
    2 3 4 5 end;
    6
    begin
    ERROR at line 1:
    ORA-01013: user requested cancel of current operation
    I have looked in the alert_pathway.log , error.log access.log for errors and found no obvious ones.
    Not sure where to look,
    originally posted in APEX as a problem with APEX
    I found this on a 3.2 apex install on a development machine 1 have a number of workspaces.
    in one workspace in which I have been developing 3 applications and in which I have VPD enabled.
    When I click next after choosing table name in create form form table it times out.
    It does not take you to the page where you enter or confirm the page number, page name, etc.
    I have tried another workspace on the same server and it works to fcreate the form.
    On a separate machine/install the same workspace which does not work above to create form form table does work.
    The VPD setup is not identical in this workspace, but very similar.
    I surmise it is an issue with that workspace, possibly but not certainly with the new VPD , the table has these settings in vpd
    GRANT SELECT ON CF.CF_PARTICIPANT_MENTOR to vpd_admin;
    create or replace function cf_admin ( p_schema in varchar2, p_object in varchar2 )
    return varchar2
    as
    l_x number;
    begin
    SELECT count(MENTOR_ID) into l_x FROM CF.CF_MENTORS where MENTOR_ID = nvl(v('APP_USER'),USER) and ROLES = 0;
    if l_x >0 then
    return '';
    end if;
    return 'PARTICIPANT_ID =''CF''';
    end;
    DBMS_RLS.add_policy
    (object_schema => 'CF',
    object_name => 'CF_PARTICIPANT_MENTOR',
    policy_name => 'CF_PM_POL',
    function_schema => 'vpd_admin',
    policy_function => 'cf_admin',
    statement_types => 'INSERT,DELETE,SELECT,UPDATE');
    END;
    I have looked in the alert_pathway.log , error.log access.log for errors and found no obvious ones.
    Form creation works in other workspace, and in the same workspace on another instance.
    Thanks for your guidance
    Frank

    A free account is never charged, if you have any charges in your Bank account without your knowledge from Adobe, I would request you to provide the following details by private message so that I can get it investigated.
    1. Adobe ID
    2. Last four digit of credit card
    3.Credit card name (visa/mastercard/Amex)
    If after investigation we are unable to detect the charges then you need to dispute the amount with Bank as it might can be case of Fraud.
    Regards
    Rajshree

  • List of users who have authorization for a particular transaction?

    Hi All,
    Can anyone guide me how to know the list of users who have authorization for a particular transaction?
    I need this to find out the list of authorizations that are obsolete ,when the particular trnsaction is obsolete in an Upgrade process.
    Thanks in advance.

    we can get the list of users for a particular transaction as below.
    get the tcode and place in AGR_TCODES and we get the list of roles .
    loop the roles and pass each role to AGR_USERS and we get list of users for that role.
    finally we got the list of users for that tcode.

  • OBIEE users have full access unfort.

    Hi guys, its my first query. I am a newbie.
    My company bought BIEE. I did the configurations and connected it our Active Directory.
    Problem is, everyone see everything in the forlders (analysis, dashboards etc...)
    I will create roles/policies and anything needed to give them specific permisions. But they all seem to have full Access.
    What can be the reason ? I dont want to give full permision to everyone

    By default all users belongs to BI Consumer
    There might be something wrong in your roles or assigning users double check
    ~ http://cool-bi.com

  • I want to download a tv show i bought on my phone on itunes... apparently my computer doesnt have "authorization" HELP!!

    i want to download a tv show i bought on my phone on itunes... apparently my computer doesnt have "authorization" HELP!!

    If the computer's running Mac OS X, move the cursor to the very top of the computer's screen, click on Store, and choose Authorize this Computer.
    If the computer's running Windows, press the Alt and S keys and choose Authorize this Computer, or click here, follow the instructions, click on Store in the menu bar, and choose Authorize this Computer.
    (89772)

  • Can I get a list of users who have a specific authorization role?

    Hello,
    I'm wondering if there is a BAPI or FM that takes as input a single authorization role and gives me back a list of all users who have that role?
    Thx.
    Andy Jacobs

    hi,
    please check the below FM
    'PRGN_1001_READ_USER_ASSIGNMENT'
    jaffer ,
    Please reward the helpful answers.

Maybe you are looking for