on 06-17-2022 10:54 AM
We tried to add and delete a t-code from user role in PRD system. but after adjusting the role, most of the auth objects got deleted for the particular role.
And this issue was faced for only particular role, but when we tried to check in SUIM logs against profile its showing many deleted entry. They have nothing to do with the t-codes which we have changed in the menu of the role.
Regards,
Dear M#####,
whenever you merge the authorizations in a role - and this is the default action after you have changed menu entries - the existing authorizations are compared with the SU24-proposals for _ALL_ entries in the menu. So not only changed entries are checked, but ALL menu entries!
That is why, also authorizations, which have nothing to do with the changed menu entries have been updated.
The rules for the merge process are summarized in SAP note 113290.
One thing you have to consider of course: If you have not synced the SU24 values in your PRD system with the actual ones in your DEV system (where you normally perform role maintenance), the behavior in PFCG in your PRD will be different to the one in your DEV. You have to mind that before you start updating roles in PRD directly. The sync is a standard step in SU25 (step 3).
b.rgds,
Bernhard
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
User | Count |
---|---|
71 | |
26 | |
10 | |
9 | |
7 | |
6 | |
4 | |
4 | |
4 | |
4 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.