cancel
Showing results for 
Search instead for 
Did you mean: 

PFCG Auth objects got deleted while adjusting roles

SAPSupport
Employee
Employee
0 Kudos


We tried to add and delete a t-code from user role in PRD system. but after adjusting the role, most of the auth objects got deleted for the particular role.

And this issue was faced for only particular role, but when we tried to check in SUIM logs against profile its showing many deleted entry. They have nothing to do with the t-codes which we have changed in the menu of the role.



Regards,



------------------------------------------------------------------------------------------------------------------------------------------------
Learn more about the SAP Support user and program here.

Accepted Solutions (1)

Accepted Solutions (1)

SAPSupport
Employee
Employee
0 Kudos

Dear M#####,

whenever you merge the authorizations in a role - and this is the default action after you have changed menu entries - the existing authorizations are compared with the SU24-proposals for _ALL_ entries in the menu. So not only changed entries are checked, but ALL menu entries!

That is why, also authorizations, which have nothing to do with the changed menu entries have been updated.

The rules for the merge process are summarized in SAP note 113290.

One thing you have to consider of course: If you have not synced the SU24 values in your PRD system with the actual ones in your DEV system (where you normally perform role maintenance), the behavior in PFCG in your PRD will be different to the one in your DEV. You have to mind that before you start updating roles in PRD directly. The sync is a standard step in SU25 (step 3).

b.rgds,

Bernhard

Answers (0)