Workbook authorisation S_USER_AGR
Dear all,
assigning workbook roles to user and saving into workbook roles for user is maintained in the same authorisation object S_USER_AGR.
As we have some IS people who are at same time have security access for assigning workbook roles and as key user save into workbook roles this leads to complication that they are allowed to create new workbooks although they shouldn't. Additionally they can change or delete existing workbook roles where they should not have access to.
Is there any way to separate security settings and simple workbook saving option?
Br
Stefan
Hi Stefan,
one solution would be to clearly separate the reporting roles from the security roles. For example make sure all reporting roles start with BW* and all the security roles start with Z*
Note that this is possible as the protected namespace is only "SAP_".
That way you could split the authorizations easier and make sure that the security guys don't have access to BW*
Also have a look at these 2 posts as they might help, too:
assigning S_USER_AGR Authorization Objects
assigning S_USER_AGR Authorization Objects
Regarding Saving the New Workbook
Re: Regarding Saving the New WorkBook
Best,
Ralf
Similar Messages
-
What auth obj to use for allowing user to create and save workbook?
Hi all,
We are on BI 7.0, we have requirement which will allow users to develop and save workbooks (NOT BEX query) via BEx Analyzer. I have examined the auth obj S_RS_WKBK but it is obsolete auth obj and there is nothing similar obj in BI 7.0.
i then looked at the S_BDS_D, is this all i need in order to allow user to save workbook on to the backend system?
pls note, user can only save workbook NOT BEx query.
regards,
JoeHi,
Actually there is no direct away to do it
First use the Authorisation s_user_agr , here in the activity field assign01,02,03 and 06 , in the role name assign a specific role name.
In s_user_tcd in transaction asssign - RRMX.
Got to PFCG, maintain the role.
Hopr this will be expedite.
ThaX and Regards
Vaibhave Sharma -
Display authorisation for workbook (BI Reporting)
Hi Experts
Is it possible to set the authorisation for workbook (in release 7.0) in such way, that user can open the workbook but not save it? The authorisation object S_USER_AGR controls only saving of workbooks for roles. I've also checked the object S_BDS* and removed it from user's role but user can still save the workbook in favorites.
Regards
RobertHi Robert,
first make sure, that note 955715 is applied.
Saving in favourites is controlled by the objects
S_USER_TCD
S_USER_AGR
S_RS_FOLD
Further information can be found in the notes 373979 and 316470.
I hope this information is helpful.
b.rgds, Bernhard -
Not allow saving workbooks by authorisation
Hi,
how to do this? which auth objects to be used?
thank youhi S B,
i see ... seems you need to apply correction
oss note 955715-Authorization check during saving of workbook.
you can ask basis to apply correction (tcode SNOTE)
Symptom
Saving of workbook possible even without authorization.
Other terms
Authorization
S_USER_AGR
Reason and Prerequisites
Authorization check was skipped when writing the workbook back to the server.
Solution
Apply the note to solve this issue.
FUNCTION RRMX_WORKBOOK_WRITE
Delta 001
Context Block
createmode = space.
endif.
Delete Block
if createmode = space and not i_t_blob is supplied.
Insert Block
<Start>Gopadi - Authorization check was skipped because i_t_blob was always supplied.
if createmode = space and not i_t_blob is supplied.
if createmode = space.
<end> -
How can I stop a user from saving over "standard" workbooks in a role?
Hello -
We are using BEx Analyzer 7.0.
I need help restricting our regular users so they can only save workbooks to their favorites and cannot override workbooks published to roles by our super users / authors.
My understanding is the regular users need the following in order to save workbooks to favorites.
S_GUI Activity = 60
S_BDS_DS Activities = 03 and 30 Class Type = OT
These users are able to save to their favorites.
However, if they open a workbook from a role and then just choose Save -> Workbook, it allows them to save their changed version of the workbook over the "standard" workbook that was published to the role for all users.
What can I do to only allow them to save to their favorites and not be able to override the standard workbooks in regular roles?
Our super user / authors have the following security to allow them to publish to roles.
S_USER_AGR with Activities = 01, 02 and 06 (Create, Change and Delete)
Our regular users have
S_USER_AGR but only with activities 03 and 08 (Display and Display Changes)
Any help that can be provided would be greatly appeciated. This is very frustrating.
Thank you -
AnnHello Anne,
Inspite of restricting the authorisation object S_BDS_DS you are not able to restrict the users in overwriting the workbooks, please implement the note 1167094 in your system.
Implementing this note with the help of yout BASIS team would surely fix your issue.
Let me know if this helps. Thanks.
Best Regds,
Suyog Chakot... -
Authorisations to Save in a role in Business Explorer
Good Afternoon,
I am attempting to allow certain users to save their workbooks in a certain role in Business Explorer, where they can share their workbooks with others that wish to see them (those who have access). But I dont want the users to be able to save changes or create workbooks in every role.
I am currently adding the authorisation object S_USER_TCD (Authorizations: Transactions in Roles) with the value * (All transactions) to the role. Unfortunately this allows the user to modify workbooks in EVERY role. How can I avoid this and only have the one role modifiable??
Your help would be greatly appreciated.Hi Simon,
Using Auth object: S_USER_AGR, provide activities: 01, 02, 03, 06 and in the Role Name add the name of the role to which the workbooks are stored. This new role will then become your workbook maintenance role.
Hope this helps... -
Internal error workbook storage fault 330
Hi All
Trying to save a new workbook in a role i created.
Anyone know why I am getting this error. I have seen many solutions for error 310 but not 330.
The role has S_GUI and S_USER_AGR with full authorisation on each.
Anyone know what is missing for the 330 fault.
Cheers
Andyi solved this with the following
S_GUI (60, 61)
S_USER_AGR (1, 2, 3 , 6)
S_RS_COMP
S_RS_COMP1 (full)
The 2 S_BDS objects (full)
S_USER_TCD with transaction RRMX -
Workbooks : Save as and Save
Hi,
we have read a lot of message about workbooks authorizations and how to allow users to save in their favorites. Also we have found differents message where some collegues try to avoid users to save workbooks, not in a role neither in their favorites.
In this topics the solution provided is to modify the workbooks object type as not modificable in the connection transport, that will not allow to users that has not SAP_ALL authorization create new workbooks and we have two differents types of user.
I will try to explain our scenario:
We have 3 types of users:
-- Keyuser: Users which can create queries, and workbooks and save it in a shared folder
-- Enduser: Users which can create workbooks and save only in their favorites, not in the shared folder.
-- Basicuser: Users should only execute the workbooks from the shared folder.
We have created one specific role for each type of user and one role with the folders where the users can share the reports.
For the Basicuser we have created a role with the next authorizations:
- S_RFC --> ACTVT = 16 ; RFC_NAME = *; RFC_TYPE = FUGR
- S_RS_AUTH --> BIAUTH = 0BI_ALL
- S_RS_COMP --> ACTVT = 16 ; RSINFOAREA = ZLO_14* ; RSINFOCUBE = * ; RSZCOMPID = * ;RSZCOMPTP = *
- S_RS_COMP1 --> ACTVT = 16 ; RSZCOMPID = * ;RSZCOMPTP = * ; RSZOWNER = *
- S_RS_FOLD --> SUP_FOLDER = 'X'.
- S_RS_PARAM --> ACTVT = * ; PARAMNM = *
In the role with the shared folder ZBI_SHARED_FOLDER the authorizations are:
- S_TCODE --> TCD = RRMX
- S_USER_AGR --> ACTVT = 03 ; ACT_GROUP = ZBI_SHARED_FOLDER
As far as I have understand the authorizations that user should not be allowed to save any workbook at his favorites. But the user can save workbooks and also view, and create folder in the favorites.
Please has some one avoid that type of users to save any workbook by authorization whithout change the changeability of the object workbooks.
Our system version is SAP NetWeaver BI 7.0
I will apreciate any help, we have go live in one week.
Many thanks in advanced.
MariaHi,
we have openned a message to sap and the answer is that there is no way to avoid users save in their favourites by authorization.
Thanks.
Best Regards,
Maria -
How to delete a workbook in Bex created by other user
Hi,
I had a query in BW,My requirment is to delete the query.....when i tried to delete the query the system is not allowing me to delete as some one created a workbook on that query
When i tried to access the workbook in query designer find option i can't able to locate the work book...
Please advise on how to delete the workbook and then the query
i got sap all authorisations
ThanksHi ,
RSZDELETE tcode is used to delete the query as well as work book also.
when you are deleting the query it will ask for work book also.
Thanks & Regards,
Ramnaresh . P. -
Error when opening a workbook with mandatory variables
BEx analyzer displays an error message window in the same time as the variable popup window.
The worbook is linked to 1 query that uses 2 mandatory variables (month ?, year ?), and was defined in the test system.
I assume that values are thus saved within the workbbok.
The developper had 0bi_all autorisation.
When a reporting user is opening it (also in the test system), the error message is displayed.
This happens only the 1st time when Analyzer is started, and by clicking on the OK button, we are able to run the query.
The next workbook refresh runs without the error message display.
Question = does anybody know the reason of this, and how to avoid the error message ?
more infos:
error message E019(R9E) appears for each variable (thus, 2 time with a query with 2 variables):
Help type 5 is not valid for the platform NONE
Exception 5 occured while calling IWB_HTML_HELP_URL_GET
the details of this error message is:
Diagnosis
You tried to start the online help with help type on platform. Help type is not supported on this platform.
System Response
Profile parameter eu/iwb/help_type must contain a valid help type.
Diagnosis
The documentation is not correctly connected to the BI server.
System Response
The documentation cannot be displayed.i checked the query and authorisation with RSRV, but this didn't help, furthermore, a lot a functions are not implemented in the system, sorry.
i also changed the query and workbook, and i think that it depends on the workbook release 3.x or 7.
imagine following situations: same query 7.0, same workbook 7.0
with BI7
1) opening the query with variables doesn't display the error message
2) refreshing the workbook with the query with variables displays the error message (only for a non mandatory variable - as soon as there is a variable, the error message is displayed)
3) refreshing the workbook with the query without variables doesn't display the error message
with BW 3.x
4) refreshing a new workbook 3.x with the query with variables doesn't display the error message
i also investigate in the function modules for workbooks (RS...), but nothing helped.
i still think that it is linked to authorisations, because with sap_all, the message isn't displayed.
how can i continue ?
Edited by: Claire Mignerey on Mar 17, 2009 2:37 PM -
Help Required in Authorization Roles for Workbooks
Hi All,
In our project, we have a requirement of creating a role for users with below authorizations.
1. Can display and execute the workbooks in the role menu.
2. Can create copy workbooks ( Save as) in the role menu.
3. Can not delete the original and the copy workbooks from role menu.
We are using an authorization object S_RS_FOLD with u2018FALSEu2019 for restricting the user from deleting workbooks.
We also need to add one more object S_USER_AGR (without u2018Deleteu2019 property) to give the authorization of creating copy workbooks in the role menu.
Object S_RS_FOLD this is working fine without S_USER_AGR. But after adding S_USER_AGR (without delete property), user is again able to delete the workbooks.
So how can we achieve both the functionalities where user can not delete the workbook but can create copy workbooks in the role menu.
Thanks,
SachinRe: Adding report (query & workbook, templates) in roles
Go through this thread.
And in our Project we have created one role for accessing workbooks. in that end user can access the work book but saved one and user cannot resave or delete the work book.
we have added Auth objects S_TCODE and S_GUI.
in S_TCODE we have added RRMX and in S_GUI we have given 60(IMPORT) access to the users.
So that they can just share the workbook. nothing else can be done.
Try like this. Hope this would help you. -
Save Workbook in a role in SAP BI
Hi All,
I'm facing an issue in SAP BI 7.0 Security . I have created a Workbook role for a user which she is not able to view when she goes to RRMX>Save Workbook> . The user has all the required authorizations and she can see all the other workbook roles but there is just one role which she can't get in the list when she tries to save workbooks in it.
She can see the role otheriwse in the tab roles.
Any help is much appreciated.
Thanks and Regards
Manisha NadirHi,
If you have no authorizations for update a role, you will not see it when trying to save a workbook(s_user_agr with activity 01,02,06 and the name of the role or * is needed). I made a special role for saving workbooks and also had the name of it in s_user_agr, you will find this when save the workbook in save workbook as and if there is already an other workbook in the role you will also see this in the option add a workbook to a role.
It is also possible that the workbook is called from history or favorites and if you then will save it you need a role as described before.
It is advisable to try this out with the trace on in st01. I noticed that depending of queries and workbooks saving, it uses s_rfc, s_cts_admi(tabl), s_rs_tools (themes for workbooks and webpublish is also an option) and the object in previous answers from this thread.
I noticed that if you start a query from roles, that only the roles with queries are shown, the same for workbooks.
Have fun
Bye
Jan van Roest -
Authorisation issue(very urgent)
Hii all,
My client has asked to create a new user-id and to give a few authorisation of reports to it.Could anyone help me regarding this ASAP.
Till now I have identified the required reports & the data targets connected to it.Just help me to proceed further.
Thanks buddies.Hi,
These transaction code willbe helpful SU01,PFCG. Once you have created a role through PFGC , then goto Authorization tab of the role and need to carry out the following.
Role Name
|
>Manually Basis : Administration
>Manually Authorization Role check
>Manually Authorization :Role Check
>Activity < 03, 22 >
> Role Name < ur role name>
< > are value to be specified
And also on the menu tab please create a folder , here you can save your BEX Query as Workbooks. when you assign this role to the new User-ID , on the SAP Easy access page the user will be able to access these queries/ Workbook.
Hope this help.
cheers,
Balaji -
Restriction of data in workbook in SAP BI 7.0
Hi All,
We are restricting new queries and workbooks but a particular work book is displaying data even when the analysis authorization is removed from the user ie wether the user has this authorisation or not he is able to view the result in the workbook.
The ifoobject should restrict the customer division by consumer but it is also showing for commercial.
The infoobject and the attributes are allready authorisation relevant.can you please let me know where the problem can be
Regards
MohammedHi Mohammad,
What is reuslt when you run the query? Is it showing all values or restricted values? -
Impossible to "save as" a workbook in a role
Hello All,
I would like to know which authorization object allow an end user to save as a workbook into a role.
So far, our user only allowed to "save as" a workbook within their favourites folders, role folder is not display for them. I cannot find which authorization object is linked to this fonctionnality.
Thanks &
Regards
CatherineHi
Assigne these..
Saving workbooks in Roles:
S_USER_AGR= authorization for role check
S_USER_TCD=transaction in roles
Praveen.
Maybe you are looking for
-
Typing lag resulting in missing words
[Problem summary] We are having issues with the response speed of FrameMaker when we type. We encountered different cases but I'm submitting this one because it is easy to recreate. [Setup] -Adobe FrameMaker 8.0p277 -Windows XP SP3 (with all required
-
I am developing a function module in ECC that will be used to post inbound IDOC for customer creation DEBMAS07 The logic is as follows - The function receives an IDOC structure It then invokes function module 'IDOC_INPUT_DEBITOR' IDOC_INPUT_DEBITOR t
-
Invoice Attachment in MIRO/MIRA
Hi All, Please let me know how invoice pdf can attach in MIRO/MIRA. I am an abaper and I am facing an issue where the attached pdf values( Invoice no and PO no ) and the screen values are not matching. Please let me know, is the pdf is attaching manu
-
Hi, I have created a Jar out of a WSDL file and am using it to envoke a webservice. I am thriugh declaring all the objects ( instantiating them ) and when i make a web service call it give me a error saying invalid SOAP, The Web Service is behind 2 p
-
Oracle 9.2.0 Errors in DBCA
512 MB of memory I have tried both SuSE 8.0 (Ora-27123) and Red Hat 7.2 ( Ora-03113) DBCA either errors of lock the OS. 9i R1 works fine? What is the trick? Thanks!