Su01 - role or profile for MM module
hi experts.
i could like to set the role or profile to a user which only can access to Materials management.
do anyone can guide me which role or profile i should set?
thanks for fast reply.
i were enter the all the MM role as the reference u gave to a user.
doc patch = roles in back-end system -> logistics -> materials management (mm).
but the user still cant access the MM module at the logistics -> materials management.
did i still missing some configuration ?
Similar Messages
-
Standred Roles and profiles for OSS Connection User
Dears,
We open OSS connections several times for SAP support in which we also provide login credentials to SAP to login in our system.
Is there any standred roles or profile for this user in QAS and PRD that we can give to maintain our servers confidentiality.
Please suggest.
ShivamNot really. A note related to your question popped up in a previous discussion:Re: Exclude T-code from SAP all
> If you take a look at [SAP Note 1118396 - Roles for support activities|https://service.sap.com/sap/support/notes/1118396] you will see this explained nicely... -
SAPMEINT: Roles or profiles for ALE_USER?
When configuring the Message Listener in NetWeaver for SAPMEINT you have to set a "ALE_USER u2014 a valid SAP ERP user to perform ALE communication".
--> See Installation Guide for SAP Manufacturing Execution 5.2 (2.0 ‒ 06/30/2010 ‒ Page 35)
But which roles or profiles do I have to assign to the ALE_USER in ERP-Transaction SU01?Problem solved. The list of authorization objects is in the online documentation:
http://help.sap.com/saphelp_me52/helpdata/EN/78/ca9cfe2422444b9ecd76ef72fbb32a/frameset.htm -
What are the roles or profiles for auditor ?
hi,
are there any roles or profiles with display only for auditor to access to basis tcodes ?
comment and advice will be appreciated
regards,
kentmanually - how sad.
there are templates for that:
SAP_AUDITOR_A
SAP_AUDITOR_ADMIN
SAP_AUDITOR_ADMIN_A
SAP_AUDITOR_BA_A
SAP_AUDITOR_BA_CFM
SAP_AUDITOR_BA_CFM_A
SAP_AUDITOR_BA_CO
SAP_AUDITOR_BA_CO_A
SAP_AUDITOR_BA_EC_CS
SAP_AUDITOR_BA_EC_CS_A
SAP_AUDITOR_BA_EC_PCA
SAP_AUDITOR_BA_EC_PCA_A
SAP_AUDITOR_BA_EXPORT_DATA
SAP_AUDITOR_BA_FI_AA
SAP_AUDITOR_BA_FI_AA_A
SAP_AUDITOR_BA_FI_AP
SAP_AUDITOR_BA_FI_APMD
SAP_AUDITOR_BA_FI_APMD_A
SAP_AUDITOR_BA_FI_AR
SAP_AUDITOR_BA_FI_ARMD
SAP_AUDITOR_BA_FI_ARMD_A
SAP_AUDITOR_BA_FI_CJ
SAP_AUDITOR_BA_FI_CJ_A
SAP_AUDITOR_BA_FI_GL
SAP_AUDITOR_BA_FI_SL
SAP_AUDITOR_BA_FI_SL_A
SAP_AUDITOR_BA_HR
SAP_AUDITOR_BA_HR_A
SAP_AUDITOR_BA_MM
SAP_AUDITOR_BA_MM_IM
SAP_AUDITOR_BA_MM_IM_A
SAP_AUDITOR_BA_MM_IV
SAP_AUDITOR_BA_MM_IV_A
SAP_AUDITOR_BA_MM_PUR
SAP_AUDITOR_BA_MM_PUR_A
SAP_AUDITOR_BA_ORGA
SAP_AUDITOR_BA_RE
SAP_AUDITOR_BA_RE_A
SAP_AUDITOR_BA_SD
SAP_AUDITOR_BA_SD_A
SAP_AUDITOR_DS
SAP_AUDITOR_DS_A
SAP_AUDITOR_SA
SAP_AUDITOR_SA_BC
SAP_AUDITOR_SA_BC_CCM_USR
SAP_AUDITOR_SA_BC_CUS_TOL
SAP_AUDITOR_SA_CCM_USR
SAP_AUDITOR_SA_CUS_TOL
SAP_AUDITOR_TAX_A
SAP_AUDITOR_TAX_AA
SAP_AUDITOR_TAX_AA_A
SAP_AUDITOR_TAX_COPS
SAP_AUDITOR_TAX_COPS_A
SAP_AUDITOR_TAX_FI
SAP_AUDITOR_TAX_FI_A
SAP_AUDITOR_TAX_HR
SAP_AUDITOR_TAX_MM
SAP_AUDITOR_TAX_MM_A
SAP_AUDITOR_TAX_SD
SAP_AUDITOR_TAX_SD_A
SAP_AUDITOR_TAX_TR
SAP_AUDITOR_TAX_TR_A
SAP_CA_AUDITOR_APPL_AG_EXT
SAP_CA_AUDITOR_SYSTEM
SAP_CA_AUDITOR_SYSTEM_DISPLAY
SAP_FS_CMS_COL_AUDITOR -
SAP delivered roles or profiles for FICO developers and configurators
Hi all,
Can any one help me in building FICO developer roles and configuration roles. Are there any SAP delivered stuff.
Thanks
BharatHi Bharat,
please go thru this document
<a href="http://help.sap.com/saphelp_erp2005vp/helpdata/en/04/408242160b6255e10000000a155106/frameset.htm">Authorization Objects for Standard Conditions</a>
i guess, there are no special
hope this will help you.
with BR,
Raj -
Display authorization for all modules Including Basis.
Hi All,
Is there any Role or profile for display authorization for sap modules .
Regards,
Eswar.Dear,
That ROLE will be SAP_ALL_DISPLAY
"what is to be done"
just assign the role to the display user via SU01
Hope this help!
Also refer this ,
DISPLAY ONLY AUTHORIZATION
Regards,
R.Brahmankar -
Developing security Roles and profiles
Hi Team,
Can you guys let me know how to develop security roles and profiles. We are rolling out for a company in Japan, and the congif is completed. We are in the process of developing test cases ans also security roles and profiles for users? Can somebody guide and help me on this?
Regards,Hi,
Use Tcode = PFCG -->then create any customized roles and profiles for any users on module based.
user masters: USR01 to 09, UST04,
profiles: USR10, USR11, UST10S, UST10C,
authorisations: USR12, USR13, UST12.
password exceptions USR40.
History tables(may not be applicable but FYI): users: USH02, USH04,
profiles: USH10, auths USH12.
R/3 Security Tcodes
End User Transaction Code Menu Path Purpose
SU3 System > User Profile> Own Data Set address/defaults/parameters
SU53 System > Utilities > Display Authorization Check Display last authority check that failed
SU56 Tools --> Administration --> Monitor --> User Buffer Display user buffer
Role Administration Transaction Code Menu Path Purpose
PFCG
Tools --> Administration --> User Maintenance --> Roles Maintain roles using the Profile Generator
PFUD Work on SAP check indicators and field values
Select: Copy SAP check IDu2019s and field values
Installation
1. Initial Customer Tables Fill
Upgrade
2a. Preparation: Compare with SAP values
2b. Reconcile affected transactions
2c. Roles to be checked
2d. Display changed transaction codes
SU24
Same as for SU25:
Select: Change Check Indicators > Maintain Check Indicators>Maintain
Regards,
Srini Nookala -
HOW MANY ROLES ARE ELGIBLE FOR THE USER
hello gurus,
how many roles can we assign to the user... what is the maximum limit of the roles and profiles for the user.
thanks in advance!
sriDear Srinivas,
About roles it's indeed not to easy to tell..just imagine the scenario:
1. Maximum number of profile is 312 ... (however due to some known bug system reads about 300). So, let's say 300 profile maximum can be assigned to an user
2. Now you can have single ABAP role which generally one-to-one to profile. So, this theory says if you are only assigning single ABAP roles, you can assign maximum 312 (or 300) roles.
3. But, you might also have Composite ABAP role. A composite ABAP role can have one or more Single/Composite ABAP role. So, one Composite ABAP role can correspond to any number of Profile which is determined by number of individual Single roles under than composite role. So, when you are assiging Composite ABAP role, you have to take care underlying number of profiles and make sure total does not exceed 312 (or 300 without note correction)
4. Now, last part of complication (and my favourite one). Sometimes, there is an empty Role which does not have any ABAP authorization assigned to it. But, this type of roles are used to map a authorization role in JAVA system. These roles does not have any Profile (as it does not have any ABAP authorization). Now, that brings my confusion ..What happens you assign 300 ABAP profiles via ABAP Roles and another 20 empty role for JAVA system without profile. You see my point
Hope this clarifies a bit
Cheers !!
Satya. -
Tcode authorization without any role or profile
Hi Experts ,
Can you please suggest on authorization issue , if observed that one Tcode not given in to any roles or profile but some user still using this authorization.
When I checked role and profile for such user using the SUIM still it shows no data.
So is there any other way to assign direct Tcode without using any role or profile.
Thanks in advance .not sure how you are using SUIM to check, just to be sure, use the complex selection method or the authorization values method. the by transaction method only check for transactions that were added via the menu.
look for object= S_TCODE, value=(the transaction code)
SUIM will then calculate if the transaction code was added manually and as part of a wild card or a range.
i.e. if the transaction was MM02 it will be accessible if the S_TCODE had
wild card value M*, MM*, MM0* or
range value A*-Z*
Otherwise, it is possible that it was called indirectly and the BADI does not perform a S_TCODE check. -
Su01 recreate old user - lost roles and profiles
Situation: a person's sap account was deleted, but now that person needs it again with the same sap access as before
when you recreate an old sap user account in su01,
sap gives a message "found old user information, do you want to reacreate this".
Press yess, then all is copied except roles and profiles (empty)....
You can find them back via the menu : information<change dcuments for users.
Is there a way to make sure that roles (and/or profiles) are instantly copied from the old records of the sap account (like
the name, email user group, user parameters, etcetera)?
Regards,
ABCNo. There is no such feature.
The solution is not to delete the user but rather lock the ID and move it to a "retired" user group where it is protected. From there you can restore it again easily.
Cheers,
Julius -
BDC recording for SU01 - Roles
Hi All ,
I am using BDC recoording of the SU01 T code for the modification of the end date of the assigned roles .
In few scenario there are few cases where user does have direct and indirect roles . I am able to change the end date of the direct roles via BDC in SU01 but since indirect roles which are depedent on direct roles and therefore the end date fields is not editable and hence on the warning my BDC is unable to update anything in SU01 .
Can any one advise , how can i proceed with BDC recording to capture editable and noneditable fields ?Hi,
it's not possible with BDC recording to know if a field is in input mode or only in output mode.
PS : Search if you cannot used a BAPI. f.e BAPI_USER_*
REM : Just one remark if you use time assignment
Time-dependency of user assignment and authorizations
o If you are also using the role to generate authorization profiles,
then you should note that the generated profile is not entered in
the user master record until the user master records have been
compared. When you specify the users for the role, the system enters
by default the current date as the start date of the user
assignment, and 12.31.9999 as the end date. If you want to restrict
the start and end dates of the assignment, for example, if you want
to define a temporary substitute for a user, the system
automatically makes the changes to the user. This automatic
adjustment of the user's authorizations is executed using report
PFCG_TIME_DEPENDENCY. In this case, you should schedule report
PFCG_TIME_DEPENDENCY daily, for example, early in the morning, to
run in the background (in transaction SA38, for example). This
compares the user master records for all roles and updates the
authorizations for the user master records. The system removes
authorization profiles for invalid user assignments from the user
master record, and enters authorization profiles from valid user
assignments to a role. -
Can't see the installed icc profiles for my paper in print module
I have downloaded and installed the icc profiles for my favourite Canson and Crane Museo papers on my new Macbook Pro but they don't show up in the options box in the LR 4 print module. Is there another step I have missed? Thanks in advance.
Where did you install the profiles? They should go into
Library/Colorsync/Profiles in your home folder or at the root level of your
hard disk. If you put it in that folder in your home folder, they show up
in user, if you put them in the root Library folder, they show up in
"Computer" in Colorsync utility -
Hello Experts,
We are having a problem dealing with a composite role.
Whenever we add the composite role to a user master; a profile appears for each of the single roles (which is normal) BUT we also get a profile for the composite role.
We verified in the table AGR_1016 and found that there is a profile asocited to the composite role.
We tried the clean-up option of the transaction PFUD which did not work in our case.
We were thinking that may be the role was firstly created as a single role with its profile; and then it mayhave been changed to a composite role without deleteing its profile. Is it possible ?
Any answer is most welcome!
Thanks & Reagards> We were thinking that may be the role was firstly created as a single role with its profile; and then it mayhave been changed to a composite role without deleteing its profile. Is it possible ?
Sounds to me as if there has been an import of a composite role overwriting a single role with the same name. The pfcg import facility has very few checks in them so something unwantend could have happened. I think it is not possible to change a role from single to composite with the PFCG or other tools. What does table AGR_PROF say about this role?
I would suggest to copy the composite to a new name (without copying the singles) and see how that looks. If it is OK you can delete the corrupted role, check wether it is completely gone and copy the new role back to it's original name. -
No camera profiles in development module for Panasonic GH4 rw2 files, imported in Lightroom 5.6.
Only the "Adobe Standard" is shown. In metadata I can see that the camera and lense were recognized correctly. What could be the reason?The sample GH4 raw file I found on PhotographyBlog does have a lens profile that the Adobe applies automatically without having lens profiles being enabled. This is indicated in Photoshop CC / ACR 8.x so perhaps LR 6 will give us the same indication:
By comparison, here is what the uncorrected raw file looks like in a raw converter that doesn't do lens corrections: -
Error in generating Profile for Child Role
Hi Experts,
My requirement is to chnage profile for child roles created. I'm using FM 'PRGN_AUTO_GENERATE_PROFILE_NEW' to generate the Profile for child role. However it gives an error saying "Open authorizations or org. levels in role & => no profile generated"
when I execute it. Infact the same error occurs when i run it for parent role also.
But prior to attaching the child role to parent role, profile gets generated with no issues.
Kindly help.
Regards,
AnjaliHello All/Experts,
I am also getting same error. how to resolve this?
regards
A
Maybe you are looking for
-
How to send email notifications
We have multiple target types, and would like to send notifications on specific target type to specific group of users. Does anybody know if it's possible to do? TIA
-
Mac noob... quick question
i just bought a mac book and airport extreme that work perfectly together along with a XP laptop. i have been using itunes on my pc for a while and have about 20 gigs of music on my pc that i want to put on my mac. can i do it wirelessly or without b
-
I have a Nokia 808 PureView, but my nfc is not working. It doesnt work with the test card or with other devices...
-
Can anyone tell me where to change the actions that are going to the audit log for an infotype? I am reading the audit log for infotypes IT07 and IT08. All changes and inserts are being returned, but only the IT08 is returning deleted records.
-
Faces missing from iPhoto.
How do I re-add the faces to my iPhoto? they are all issing, and when I go to the add function, the faces are missing on the ones that I try to asdd as well.