cancel
Showing results for 
Search instead for 
Did you mean: 

BW aggregated authorization (colon :) issue

Former Member
0 Kudos

HI

I'm  new to BW authorization we have BW 7.0     SAP_BW     700     0019 system and we are facing issue in aggregation authorization

the scenario is we have 2 customized reports Daily_sales and Customer_Aging

and we have  authorization  ZPLANT_plant   Charact 0PLANT and EQ to the plant ID where the branch is located

We also have authorization ZPLANT_AGGR Charact 0PLANT and EQ :

The branch user required the 2 reports to be assigned to him

if we grant zplant_aggr to the branch user he can see other branches data (Unauthorized data)  in the report Daily_sales report if he keep the query input for plant empty.

if we don't grant the user zplant_aggr to the user the Customer_Aging will not work (No authorization)

Please help us what should we do in this case?

Thanks in advance.

Ameen

Accepted Solutions (0)

Answers (1)

Answers (1)

Loed
Active Contributor
0 Kudos

Hi,

Using the colon authorization will definitely grant the user to see all values from all PLANTS..What plant is he allowed?

You said that CUSTOMER_AGING report is not working if ZPLANT_AGGR is not assigned to him..What is the error? Can you check it in SU53? Or can you debug his account in RSECADMIN to check the error and post here?

Regards,

Loed

Former Member
0 Kudos

Hi Loed,

We give the user  X for example the following plant authorization 

ZPLANT_plant=1000

ZPLANT_AGGR= :

in Daily_sales report if user X keeps the plant filed empty in the input  he will see all other plants data example 2000 ,3000 ...etc(Unauthorized access). is this normal ?

for the report Customer_Aging if we don't give ZPLANT_AGGR to user X he will get the result but not correct numbers. (the previous post is not correct that he is not authorized please ignore that part)

We have also other reports that have same scenarios it will give unauthorized data and if we remove

ZPLANT_AGGR other reports will  not work correctly.

What should we do ?

Thanks and Regards.

Loed
Active Contributor
0 Kudos

Hi,

Whare are the characteristics shown? Maybe the problem lies to other objects? Maybe the user doesn't have authorization on some objects shown in the report?

If the user really doesn't have authorization, you can debug his username using tcode RSECADMIN..There is a TEST part there where you can check which objects the user need to show the report..

Regards,

Loed