Solution manager_document authorization

Dear friends,
   I am in SOLAR01, Business blueprinting. In SOLAR01, in "Project documentation" tab, i am maintaing some five documents.
In the above five documents, first 2 documents i wants to give just "View" authorization for some project team member. For the same above 2 documents i wants to give "Edit" authorization for some other project team members.
Like that, depends on the team member who login, the document authorization to be maintained.
How to maintain? which authorization object needs to be used for this?
Thanks
Senthil

Hi Dolores,
    Thanks. But i am facing the problem with only document management. I have done whatever u have told. By doing so, we can only control node access with respect to team member.
I will explain one scenario.
Let us assume, in one single node, three team members are working. Each team member prepares some document for that same node.
Team member1( He can have all the authorizations View,Change&delete)-prepares 2 documents(namely DOC1 & DOC2) for that node.
For DOC1:
He wants to give authorization to "team member2" only to view the document. For the same document, he wants to give authorization to "team member 3" to view & change.
For Doc2:
He wants to give authorization to "team member2" only to "delete" the document. For the same document, he wants to give authorization to "team member 3" to view & change. (Not to delete).
So now "team member2" logins to the system. He enters into that node.(Project documentation tab)
If he selects the entire row of DOC1, the authorization is only "View" icon should be highlighted.
If he selects the entire row of DOC2, the authorization is only "Delete" icon should be highlighted.
This is my scenario. I am working with authorization object "S_IWB" , 'S_IWB_ATTR". There some "folder group" & "Area" option is available. Through that it may be possible.
Please give your valuable inputs
Thanks
Senthil

Similar Messages

  • I've tried all the suggested solutions to authorize my windows computer for itunes but nothing works. Is there an actual phone number I can call? Does anyone have a solution? Please spare me the "get a mac" rubbish.

    I have tried all the suggested solutions to authorize my windows computer for itunes. Is there a phone number I can call or what can I do? And please spare me the "buy a mac" comments.

    If you haven't already tried and seen these...
    Try this Discussion...
    https://discussions.apple.com/thread/4631735?tstart=0
    More Info here  >  About authorization and deauthorization
    If necessary Contact iTunes Customer Service and request assistance
    Use this Link  >  Apple  Support  iTunes Store  Contact

  • Solution manager Authorization issue

    Dear all,
    We are maintaining a enterprise solution manager.
    we maintain all our SAP clients issues which is posted in our solution manager.
    Now the issue is if the clients login in to our solution manager to see the issue status, they are able to see all the  clients issues which is posted.
    but we want to restrict the authorization not to see other clients issues which is posted in our solution manager.
    we want them to see the issues only which is posted by them.
    Please give me if there is set of authorization to do this.
    Regards
    Prakash

    HI,
    From ur post, I think u have provided authorization to access the tcode crm_dno_monitor. In that case, u cannot restrict him to see all other messages. If u want to restrict the authorization, create a variant with necessary inputs which shows the result ur customer wants to see and assign that to his favourites. Only provide access to call that variant.
    Rajeev.

  • SAP Solution Manager - authorizations

    Hello!
    Is there any functionality in Solution Manager for
    1. Adjust user rights per project
    - example:
    User1 has access in Project1 but no access to Project2 in same Solution Manager client
    2. Adjust user rights per part of project structure
    - example:
    User1 has access in Business scenario1 of Project1 but no access to Business scenario2 of Project1
    3. Adjust user rights per document belonging into project
    - example:
    User1 has access in Document1 of Process step1 of Project1 but no access to Document2 of Process step1 of Project1

    Thanks for the tip!
    What I was searching for was not in Change Request Management but more like Project Administration. It was found from the Solution Manager library help in Assign Authorization for Documents: 
    "You can control the access rights to documents in the project by assigning authorizations for groups of documents, e.g. you can specify that only the project management can change documentation templates. The system saves Solution Manager project documents in Knowledge Warehouse folders. Access to Knowledge Warehouse folders is controlled by the authorization object S_IWB, which is in the roles SAP_SOL_KW_ALL and SAP_SOL_KW_DIS, and in the Solution Manager Composite Rolles.
    You have role (transaction PFCG) and user maintenance authorization..."
    So, thanks for the guidance .

  • SAP Solution Manager - authorization to reply

    Hello,
    I have a problem with my SAP Solution Manager. When I post a support message, and the support consultant answer and set the message status to "Author Action", I can't reply to say that the proposed solution didn't resolve the problem. I have the following message : "You are not authorized to perform this function". 
    This is in the web interface, and I didn't manage to see the traces, and necessary authorization.
    But I can confirm if I want. The user have theses followings roles :
    ZSAP_SMWORK_BASIC
    ZSAP_SMWORK_INCIDENT_MAN
    ZSAP_SUPPCF_CREATE
    ZSAP_SUPPDESK_CREATE
    I have to specify that I upgraded Solution Manager last week.
    This is a DEV SolMan, and all works very well on PROD SolMan, and the roles are the same.
    Thanks for help,
    Regards.

    Hi Michal,
    I've tried with web interface and there is no trace. But with transaction CRMD_ORDER, and with the good hour I have a result.
    http://www.hiboox.fr/go/images/cuisine/objects,45a6323dd0efddbd06c6cff29b43f71f.bmp.html
    So I have theses results, and if I read, this is CRM_TXT_ID Object which block the reply function?
    Regards,
    Charles.

  • Solution Manager_document URL link

    Dear friends,
      I have uploaded project documents in SOLAR01. If i get into document attributes, i am finding option "generate". If i click on that, message has shown as "URL buffered". But i could not find the URL link for my document.
    How to get a URL link for my document?
    Thanks
    Senthil

    Hi Senthil,<br>
    <br>
    Now what you have done is activated the service "/default_host/sap/bc/solman/SolmanDocuments". By doing this, now your documents can be accessed by anybody in the same domain irrespective of whether they have an user account in the solution manager system.<br>
    <br>
    In case, if you want to restrict the access to users based on SSO, then SSO needs to be activated.<br>
    <br>
    For that,<br>
    <br>
    Activate SSL in WAS - for that follow note no. 510007<br>
    (ii) Configure WAS as per note no. 612670, so that it will issue SSO logon tickets<br>
    <br>
    On doing this, whenever you try to open the document using URL, it will provide a secure access to your document.<br>
    <br>
    All these information you can find in a IMG activity as specified by other SDNers in their replies.<br>
    <br>
    <B>If your issue is solved, dont forget to reward points to all who have contributed valuable replies and close the thread.</B><br>
    <br>
    best regds,<br>
    Alagammai.<br>
    <br>

  • Possible solution to authorization issues

    Recently I had the issue with 8.1.1 where when you try to play a song you bought from iTunes it asks you to authorize your computer. You do and it doesn't matter. De-authing and re-authing does nothing. Deleting the sc shared folder doesn't work. So, I e-mailed iTunes support from the support page and someone responded back to reinstall a new copy of iTunes over the old. I did, rebooted and it works fine now. Just hoping some others can get help out of this.

    UPDATE: Okay, so as I mentioned that running kernel 3.10 with ipv6 (and powersaving) disabled it works, it isn't perfect, it loses connection every now and then, doesn't get any usable speeds and it randomly disconnects and requires a reauth, nothing major as it isn't exactly common (ugh, it's a major improvement over disconnects every two seconds)
    This card is still awful though (on an unrelated note I still find it hilarious that the card works even worse in windows *rolls eyes* I blame microsoft)

  • Solution for authorization in FMS

    Hello,
    Our scenario is that we have an Adobe ColdFusion8 server running a portal application which will serve up SWF content from a FMS3 installation. We need to protect the SWF content from being a) downloaded to a users local machine and b) being accessed without being logged into the portal application.
    Please correct me here if I am wrong - it looks like the combination of RTMPE + SWF Verification are the minimum necessary, but I am confused as to these other practices and which ones to use (or can be used on FMS and not FMIS):
    1) Refererr and pageURL check validation
    OR
    2) IP Address validation
    OR
    3) White list domains
    Any suggestions on the best method to accomplish this using RTMPE + SWF Verification + (1, 2, or 3)?
    Thank you,
    Steve

    all three =)
    http://www.adobe.com/devnet/flashmediaserver/articles/protecting_video_fms.pdf
    regards
    Leonardo França
    Adobe Certified Expert Flex 3 with AIR
    Adobe Certified Expert Rich Internet Application Specialist v1.0
    Adobe Certified Expert Flash CS3 Professional
    Certified Professional Adobe Flex 2 Developer
    Adobe Certified Professional Flash MX 2004 Developer
    http://www.leonardofranca.com
    http://twitter/leofederal
    Manager AUGDF - Adobe User Group do Distrito Federal
    http://www.augdf.com.br
    http://twitter/augdf
    sfister escreveu:
    Hello,
    Our scenario is that we have an Adobe ColdFusion8 server running a portal application which will serve up SWF content from a FMS3 installation. We need to protect the SWF content from being a) downloaded to a users local machine and b) being accessed without being logged into the portal application.
    Please correct me here if I am wrong - it looks like the combination of RTMPE + SWF Verification are the minimum necessary, but I am confused as to these other practices and which ones to use (or can be used on FMS and not FMIS):
    1) Refererr and pageURL check validation
    OR
    2) IP Address validation
    OR
    3) White list domains
    Any suggestions on the best method to accomplish this using RTMPE + SWF Verification + (1, 2, or 3)?
    Thank you,
    Steve
    >

  • Structural authorization with Context Solution

    Hey Guys,
    I have a requirement. For an example, I would like to restrict IT 0001 access for write access. A Manager should have read and write access to IT 0001 only for personnel#s under his org unit (for which he has a 'chief' position). For other personnel#s, he should have only read access for IT 0001.
    We would like to use Context Solution (P_ORGINCON authorization object). I have created a PD profile with O-S-P evaluation path and RH_GET_MANAGER_ASSIGNMENT as function module.
    In role, authorization object P_ORGINCON would be having following values (which gives read and write access to IT 0001 for Manager's org unit):
    Authorization Level - R, M, W, E, D, S
    Infotype - 0001
    Personnel Area - *
    Employee Group - *
    Employee Subgroup - *
    Subtype - *
    Organizational Key - *
    Authorization Profile - PD_PROFILE_1
    PD profile (PD_PROFILE_1) is restricted by RH_GET_MANAGER_ASSIGNMENT function module and so it gives list of personnel#s, a Manager is authorized for his org unit.
    My questions:
    1: For my requirement, what values should be in second authorization object, to have read only access for IT 0001 for all personnel#s? Do I have to use P_ORGINCON authorization object with Authorization Profile as '*'?
    2: At the time of turning on HR switch (transaction OOAC, table T77S0) for INCON (HR: Master Data (Context)) to 1, do we have to turn off switch for ORGIN (HR: Master Data)?
    3: If yes to question 2, do we have to update all transactions in SU24 to reflect P_ORGINCON for check/maintain instead of P_ORGIN? So, whenever we enter transaction code in a role thru PGCF, P_ORGINCON would be entered in authorization or it is not required.
    Thanks,
    Karan.

    Hi Karan,
    1: For my requirement, what values should be in second authorization object, to have read only access for IT 0001 for all personnel#s? Do I have to use P_ORGINCON authorization object with Authorization Profile as '*'?
    I think you can use it.
    2: At the time of turning on HR switch (transaction OOAC, table T77S0) for INCON (HR: Master Data (Context)) to 1, do we have to turn off switch for ORGIN (HR: Master Data)?
    Yes you need to turn off the switch for ORGIN
    3: If yes to question 2, do we have to update all transactions in SU24 to reflect P_ORGINCON for check/maintain instead of P_ORGIN? So, whenever we enter transaction code in a role thru PGCF, P_ORGINCON would be entered in authorization or it is not required.
    You dont need to update in SU24

  • Authorization control on material reservation creation and change (MB21 & M

    Hi Friends
    Please help me to find a solution on Authorization control on material reservation creation and change (MB21 & MB23).
    Client looking for a control over end user on those T.Code s but not at T.Code level;
    Client looking for control either based on "Storage location" and/or u201CProduct hierarchyu201D.
    More specifically, user A and B both can Create/Change MR but user A only can do it for the MR which related to storage location say YY while B authorized for storage location ZZ
    Thanks in advance.

    Hello Partha,
    Only available Standard SAP Authorization Objects, related to Reservations, are M_MRES_BWA (Reservations: Movement Type) & M_MRES_WWA (Reservations: Plant) where you can maintain authorizations based on Movement Type & Plant respectively and hence seggested enhancement.
    You can use Tcode-SUIM to search for Basis authorization details i.e. Roles defined for specific transaction/authorization object / profiles.
    Revert if any further info required.
    Regards,
    Anup

  • SOLMAN 7.0 SPS 17: MOPZ and EWA user authorization

    Hi!
    I installed SOLMAN 7.0 SPS 17 and have multiple solutions within tcode DSWP.
    Now I would like to give a MOPZ and EWA authorization for user x to see content of special solution x within DSWP.
    It should look like:
    User X --> tcode DSWP: Solution X (authorizations for MOPZ, EWA)
    User Y --> tcode DSWP: Soution Y (authorizations for MOPZ, EWA)
    What are the appropriate roles/profiles for this approach? 
    Thank you very much!
    regards

    >
    Holger Thomasson wrote:
    > Hi!
    >
    > I installed SOLMAN 7.0 SPS 17 and have multiple solutions within tcode DSWP.
    >
    > Now I would like to give a MOPZ and EWA authorization for user x to see content of special solution x within DSWP.
    >
    > It should look like:
    > User X --> tcode DSWP: Solution X (authorizations for MOPZ, EWA)
    > User Y --> tcode DSWP: Soution Y (authorizations for MOPZ, EWA)
    >
    > What are the appropriate roles/profiles for this approach? 
    >
    > Thank you very much!
    >
    > regards
    See information in Security Guide, too.
    Please check authorization object D_SOL_VSBL. to restrict display, edit authorization for specific solutions.
    Best regards,
    Ruediger

  • I have laptop with digital persona (finger scanning) to automatic feed the passwords. it was working properly with the older version of firefox but is not working with the latest version of the firefox. why? give me a solution.

    i have laptop with digital persona (finger scanning) to automatic feed the passwords. it was working properly with the older version of firefox but is not working with the latest version of the firefox. why? give me a solution.

    Please authorize ADE 3 with same credentials that you used with older version of ADE

  • Restriction in Document new version

    Hi
    I have a DIR (document info record) with version 00, now in any new version (greater than version 00) :
    I want to restrict the change of any fields while create new version. In fact all version should be created with same value in DIR and they are only differ in original.
    Is there any solution?
    Is there solution by Authorization concept?
    Thanks for any help,
    Habib

    Hi Habib,
    I am not very sure but please can you try checking the below config node -
    a) Document Management => Control Data => Define Document Types => Select the document type => Activate "Change Docs".
    b) Document Management => Control Data => Define Document Types => Select the document type =>  Define document status => Status 'Released' => Inside "Attributes', please can you try activating "Content version".
    Thanks,
    Arijit

  • Query Saving takes long time and giving error

    Hi Gurus,
    I am creating one query that have lot of calculations (CKF & RKF).
    When I am trying to save this query it is taking long time and it is giving error like RFC_ERROR_SYSTEM_FAILURE, Query Designer must be restarted, further work not possible.
    Please give me the solution for this.
    Thanks,
    RChowdary

    Hi Chowdary,
    Check the following note: 316470.
    https://websmp130.sap-ag.de/sap(bD1lbiZjPTAwMQ==)/bc/bsp/spn/sapnotes/index2.htm?numm=316470
    The note details are:
    Symptom
    There are no authorizations to change roles. Consequently, the system displays no roles when you save workbooks in the BEx Analyzer. In the BEx browser, you cannot move or change workbooks, documents, folders and so on.
    Other terms
    BW 2.0B, 2.0A, 20A, 20B, frontend, error 172, Business Explorer,
    RFC_ERROR_SYSTEM_FAILURE, NOT_AUTHORIZED, S_USER_TCD, RAISE_EXCEPTION,
    LPRGN_STRUCTUREU04, SAPLPRGN_STRUCTURE, PRGN_STRU_SAVE_NODES
    Reason and Prerequisites
    The authorizations below are not assigned to the user.
    Solution
    Assign authorization for roles
    To assign authorizations for a role, execute the following steps:
    1. Start Transaction Role maintenance (PFCG)
    2. Select a role
    3. Choose the "Change" switch
    4. Choose tab title "Authorizations"
    5. Choose the "Change authorization data" switch
    6. Choose "+ Manually" switch
    7. Enter "S_USER_AGR" as "Authorization object"
    8. Expand "Basis: Administration"/"Authorization: Role check""
    9. From "Activity" select "Create or generate" and others like "Display" or "Change"
    10. Under "Role Name", enter all roles that are supposed to be shown or changed. Enter "*" for all roles.
    11. You can re-enter authorization object "S_USER_AGR" for other activities.
    Assign authorization for transactions
    If a user is granted the authorization for changing a role, he/she should also be granted the authorization for all transactions contained in the role. Add these transaction codes to authorization object S_USER_TCD.
    1. Start the role maintenance transaction (PFCG).
    2. Select a role.
    3. Click on "Change".
    4. Choose the "Authorizations" tab.
    5. Click on "Change authorization data".
    6. Click on "+ manually".
    7. Specify "S_USER_TCD" as "Authorization object".
    8. Expand "Basis - Administration"/"Authorizations: Transactions in Roles".
    9. Under "Transaction", choose at least "RRMX" (for BW reports), "SAP_BW_TEMPLATE" (for BW Web Templates), "SAP_BW_QUERY" (for BW Queries and/or "SAP_BW_CRYSTAL" (for Crystal reports) or "*". Values with "SAP_BW_..." are not transactions, they are special node types (see transaction code NODE_TYPE_DEFINITION).
    Using the SAP System Trace (Transaction ST01), you can identify the transaction that causes NOT_AUTHORIZED.
    Prevent user assignment
    Having the authorization for changing roles, the user is not only able to change the menu but also to assign users. If you want to prevent the latter, the user must loose the authorization for Transactions User Maintenance (SU01) and Role maintenance (PFCG).
    Z1>Note
    Refer to Note 197601, which provides information on the different display of BEx Browser, BEx Analyzer and Easy Access menu.
    Please refer to Note 373979 about authorizations to save workbooks.
    Check in the transaction ST22 for more details on the Query designer failure or query log file.
    With Regards,
    Ravi Kanth.
    Edited by: Ravi kanth on Apr 9, 2009 6:02 PM

  • Cannot see BEx Query in Creating Universe Connection

    Hi,
    I have a BEx query based on Multiprovider
    I did check the box "Allow External Access to this query" from "Release for OLE DB for OLAP".
    When I come to Designer create a connection, that query does not show up.
    This has happened with some other query create on that Multi Provider too.
    I checked the query for operators.
    Note: Queries containing formulas with the operators %RT, %CT, SUMRT, SUMCT and LEAF cannot be released for OLE DB for OLAP. Mentioned in
    http://help.sap.com/saphelp_nw04/Helpdata/EN/07/0ab63c71f41d5ce10000000a114084/content.htm
    I cannot explain why.
    What could be possible reason?
    Thank you,

    Check to make sure the BW role that is used has auth obj S_RS_COMP that provides Display access to the InfoProvider that your query is built on.   The userid that runs the Bex query would also needs Execute access to that query.  You may need to get your SAP security person to run a trace when you start designer and try to create your connection if you find that your BW role already has the auth I mentioned.
    SAP made a recent change with 7.0 SP22 / 7.01 SP5 that applied BW security to the display of queries in the Designer.  We could no longer see out BEx quereis in Designer after we applied SP22 until we added Display access to the role we use for our Business Objects service acct we setup.
    From SAP Note 1364715 - MDX: Authorization check of BEx queries
    Symptom
    You use the BAPI "BAPI_MDPROVIDER_GET_CUBES" to read the BEx queries
    available in the BW server that have been released for OLE DB for OLAP
    (ODBO) (indicator "Allow External Access to this Query" is set in the Query
    Designer).
    Authorizations are ignored.
    Cause and Prerequisites
    The authorization check is ignored.
    Solution
    The authorization check is performed for the user that calls the BAPI. If
    an RFC is used to call the BAPI, the check is performed for the RFC user.

Maybe you are looking for

  • Client Security Solution Message

    Lately I am receving a message on start up that says, "There was a problem connecting to the TPM on this computer." It says that a firewall may be the problem or a "missing or disabled device driver" may be the problem. What does this mean?

  • How to fix vowel placement in Adobe Gurmukhi?

    I am using Adobe InDesign CS2. I bought the Adobe Gurmukhi font package. The vowels look good in my word processing program, but when I use the font in InDesign the siharis end up on the wrong side of the letters and most other vowel marks are too fa

  • Does JSF support component with dynamic fields?

    Webapps forms usually map a input text field to a java bean property. This mapping is one to one. I would like to know if the JSF can handle the situation where a form is dynamically generated with variable number of fields (eg. check boxes) and havi

  • Lexical Parameter in Matrix Report

    Hi , I am faced a problem when i used lexical Parameter in Matrix Report. I design Query and Report in Group Above Mode The Lexical Parameter Show the Values in the Field but when I make This Report in Matrix then This Lexical Parameter Showes The Va

  • Anybody Pre-Order that hasn't been charged yet?

    I Successfully pre-ordered on the 15th and received e-mail confirmation of delivery by the 24th, but I haven't been charged yet. Everything looks ok in the order status but I've read a lot of people saying that they've already been charged, should I