Transport Authorization Objects

Hi all,
      Can you please clarify this issue. Is it a good practice to transport authorization objects from Dev to Q/A to Prod or create them separately in all the three environments. I transported the roles but I am not certain about the authorization objects.
Thank you for your time,
Ram

Hi,
It is a policy decision what will be the source system of your authorizations. From there you can use the transport system to spread the roles over the landscape. To keep everything in sync, use the transport system otherwise in a matter of time you have no idea which is coming from where.
have fun
Jan van Roest

Similar Messages

  • Problem in transporting authorization object

    Hi,
    I am facing a problem in transporting the authorization object. We have an existing cube in development and production. In production the object has 3 authorization objects checked. Now I want to change the authorization object assignment in my cube. So I changed the assignment in the development, but when I tried to transport the authorization object it collected all the cubes where the authorization object is used.
    I want to transport only the authorization object associated with that cube, not all. I understand that logically if we are transporting the authorization object from RSSM, it takes all the assignments. But I don't want to do that because there may be some inconsistencies between the system.
    Can you tell me weather we have any other way, so that the authorization object is transported only for one particular cube assignment not all.
    Thanks in advance
    Prashant

    Hi,
    I tried that but not getting anything.
    Can you please tell me the steps.
    Steps I have done are as follows.
    1. Go to RSSM and select the authorization object.
    2. We have a button which says transport authorization object. I clicked on that.
    3. I got a list of all the authorization objects there. I selected my authorization objects and clicked on Transfer Object button.
    4. Then I get the hierarchy authorization objects.
    5. After that I selected a request and everything is included in that request. I didn't got your above mentioned option.
    Do you want me to go to the table RSSTOBJDIR and delete all the other entries??
    It would be great if you can tell me the steps to do that.
    Thanks in advance
    prashant

  • Transport authorization objects in BW

    Hi gurus,
    I have this problem regarding authorization objects for reporting in BW:
    I hace created in DEV some authorization objects and linked them to some infoproviders.
    When I make the transport to PRD system, I can see these objects but they are link to other inforproviders and not the ones that are marked in the dev system. The OT doen´t seem to have any trouble, but ¿why has this happened?.
    As you know, I can´t select the correct infoproviders in prd system, and moreover I can´t erase them because I have already created profiles using these objects.
    I think an option would be to pass again an OT, but I think the same problem may arise again.
    I would appreciatte any kind of help.
    Thanks,
    Luis

    It's the same as you would in another system.
    SE84 -> Other Objects -> Auth Objects
    Choose your object and then there will be the option to transport it in menu item Authorization Obj's

  • Transporting Authorization Object

    Hi All,
    We are having two autherization objects.But we use only one in production. we noticed that the other object is also active in production. I checked in development and it is not active. So i need to capture it from development and transport to make the object inactive in production also.Can any one guide me out in this scenario.I checked in RSA1 Transport connection.But i couldnt find authorization objects there.I think we need to approach in another way.
    Any suggestions will be more help full....

    Hello,
    Assuming by inactive you mean the checking for particular infoproviders.
    De-activate a checking for the selected infoproviders and press the Transport Hierarchy Authorizations, InfoProvider button in the bottom of the RSSM transaction. Hit cancel on the hierarchy auths screen and select the auth object for hwich you want the settings transported. In the transport requst, table entries for table RSSTOBJDIR should be visible.
    Whenever an InfoProvider is activated for the first time (through transport or otherwise), it is automatically turned on for all auth objects to which it might be related.
    You might want to enable auth check maintenance directly in the production system. Makes life easier.
    Cheers
    Aneesh

  • Transporting authorization object (RSSM)

    Hi,
    I am having problem transporting my BW Custom authorization object over to the Quality system.
    I have successfully transported the table contents RSSTOBJDIR to the Quality system. However, when I search for the authorization object in RSSM in Quality after the transport , it complained saying u201Cobject is not available. Create?u201D
    How can I transport the authorization object?
    Thanks for your time.
    Regards,
    Raja

    Yes you can transport an authorization object.
    It should give you an option to create a TR which creation of the auth obj in RSSM. If you have not done that then try to make a small change and see if it requests you to create a TR. If still you are not able to do it, then try adding the objec of typr R3TR - SUSO and give your authorization object name in SE03.
    Regards,
    Gaurav

  • Reg: Transporting Authorization Objects

    Hi,
    If a custom authorization object has been created, can someone please guide on it to be transported across landscape.
    Regards,

    Hi,
    Yes. create a workbench request and open it in change mode.
    Now you will have table with editable fields with 3 fields.
    1. In programID field enter R3TR
    2. In object type field enter SUSO
    3. In Object name field enter the respective Z authorization object.
    You also need to make sure that the respectie class is available in the target systems. if not, repeat the above procedure with object type as SUSC.
    Regards,
    Gowrinadh

  • Transport Authorization object

    Hi,
    I hope someone can help me with this issue:
    I tried to transport an Authorization object but when it's in productive, the part of the infocubes doesn't appear, If I select Check for Infocubes ( tr RSSM), it's empty. But in the develop system appears the infocubes.
    So I don't know if I have to do something else.
    I'll appreciate a lot if someone help me
    Thanksªª

    Hi
    Transport ur cube once again and just cross chek  wat is mising  in ur prod system or wat ever sys u are comp to with ur delv sys and  after moving it just chek if u can see data in ur cube,i think if it was showing u authorization prbm in the dev system it will show u the same thing in the prod system(RSSM) and if it shows the authorization prbm, ask ur basis team to give u the authorization for particular object which ever is being restricted to u
    thanks
    puneet

  • Open Authorization Objects in role after role Transport

    Hi All,
    I have transported a R/3 (ECC6, support) role from Dev to QA and Dev (Multiple clients). After transport, Role has authorization tab with status (green) but when i display authorization data i found one new open authorization object (yellow).
    I already have generated profile before tranporting. Role is also okay in  Dev other clients (We have multiple clients in Dev) with status green and no open authorizations (yellow)
    Any feedback/suggestions ?
    Thanks in advance
    Khasim.

    This happens when PFUD runs at the same time as you are generating the role. Refer to this note: 355030 - Loss of authorizations after profile generation. Another remote reason could be if your source (DEV) and target (QA) systems use different characters sets. (Note #535554).
    If it is the former case, re-transporting your role may just be the solution for you. Just re-generate the role in DEV and initiate a new transport.
    Hope this helps.
    Ashutosh

  • Authorization required for transporting XI objects

    Hi All,
    What authorizations are required to transport XI objects using File System?
    Thank you in advance

    I know Satish has answered your question, but just to add some more info to it , have a look at this
    http://help.sap.com/saphelp_nw04/helpdata/en/a8/5e56006c17e748a68bb3843ed5aab8/content.htm
    From above link :
    <i>Prerequisites
    During the export, a packaged binary file is created in a directory defined on the repository server (or directory server). To import this file to another Integration Repository (or Integration Directory), you must manually copy it to an import directory (see below). <b>You require the appropriate authorizations to be able to access directories on the SAP Web Application Server.</b>
    </i>
    thanks,
    Pooja
    PS: Award points for helpful answer

  • Transport Of Authorization Objects

    Hi,
    I have created the authorization objects in Development server. After creating we have selected the Infocubes from the option 'Check for infocubes'. This is working properly.
    Same I have transported to Quality. My reports are working but the authorisation objects has no impact.
    I have transported only the info-objects and the auth objects. Please let me know do I need to transport the Infocubes which I have selected at the time of creating the auth objects. Because When I am viewing the auth objects in quality, no infocubes are seen (Check for infocubes option)
    Please advise.
    Thanks & Regards
    Ramesh Ganji

    hi
    u need to transport the infocubes as well.
    because rssm u link that authorization object with infocube.if u do not do this,your authorization object is not checked in queries for that infocube.
    so u need to transport them and then tick them in rssm
    hope this helps

  • Transport of Authorization Object

    Hi ,
    I have created an Custome authorization Object in dev Box .
    can you tell me how to transport it to QA Box ?
    Thanks
    Pankaj

    Hello Pankaj.
    On RSSM transaction enter your authorization object, Select Transport object and Hierarchies button.
    Which prompts a screen,there select your object and select continue.
    In the next screen a list will display cancel that screen, now it would prompt you for a transport request.
    Enter the type of request you wish to create as "Workbench Request" then provide you request name else create it.
    Thus would be available in SE09 screen.
    Assign points if helpful.
    Regards

  • Error in Transport of Authorization Object

    Hi,
    I have created a authorization object in my development and transported it to testing. In the transport log I can see that it was succesfully imported but I am not able to see the Authorization object in SU21 of testing system but I tried to see that Authorization object through SUIM and able to see that object.
    I tried to create a sample role and assign this authorization object manually to that role but not able to do that.
    Can any one help me in this issue.

    Hi Martin,
    Thanks for the reply
    Yes I forgot to transport Authorization class. I have done that now and able to access the Authorization object.
    Can you please let me know the complete process whether we have to transport only Authorization class...
    Then the Authorization object will be transported on its own..
    Thanks in advance

  • BW Authorization Object to restrict Transporting Requests

    Hi...
    In our BW systems, all the developers are given the profile SAP_ALL. So, the developers have the access to transport their objects from BW Development(BWD) client to BW Quality(BWQ) Client and from BWQ to BW Production client (BWP).
    I want to restrict the developers to do the transports. What is the authorization object used to restrict the users to transport requests?
    Any documentation how to do that?
    Thanks,
    Sai.

    It can be done with the authorization objects S_TRANSPRT and S_CTS_ADMI.
    S_TRANSPRT creating transport request and S_CTS_ADMI for moving transport request.
    I would like to work on that project where I can get SAP_ALL access..:)
    Check the documentation.
    http://help.sap.com/saphelp_nw04/helpdata/en/8d/45ef39521e3314e10000000a11402f/content.htm
    Thanks.

  • Authorization objects in transport request

    Hi All,
    I'm trying to get a table that contains all the authorization objects that are included in a transport request. I only can get the object list but without the authorization values for each object.

    Hi,
    As per your query this can be see in suim t-code.
    If you have any specific error or query then pls put it here then you will get the solution.
    Anil

  • XI object Transport authorizations to developer

    Hi All,
    I want that XI developer shoul be able to transport the objects from IR and ID using "transport using Filesystem" option. If possible, he should not be able to import anything in the system
    Once the developer knows, he is done with the development/modifications, he should be able to transport the objects to the file.
    Then all he needs to instruct the XI Admin is, that which filenames he want to import to the target system. XI admin will take that input and will import those files into the target system.
    Does anyone knows how to configure the roles in ABAP/J2EE side so that, I can acheive the above functionality.
    Thanks and Regards,
    Arundeep Singh

    Dear Singh,
    Well, the easiest way is to brows the XI roles available in the User management BUT when it comes to import export and transferring files I believe the following methodology can work for you:
    1.XI developer from the DEV host exports IR objects for example. after exporting the specific SWCV or name space he gets a confirmation for the exporting and the name of the object.
    2. then the BASIS person needs to access the file system of the DEV host to the export folder, grab the file and move them to the import folder of the QAS host.
    3.Then the developer imports the IR objects and start testing...
    Another very us full tool is the Transport groups configuration inside the SLD, this method is excellent when you have many Configuration scenarios that you need to transfer from the ID of the DEV to the QAS and PROD.
    doing so will allow your scenarios to be transfered untouched and just the Business system names will be replaced  automatically...it works like magic..i tell you when you have 40 scenarios...it makes life much easy and organized.
    Good luck with the transports.
    Nimrod

Maybe you are looking for