cancel
Showing results for 
Search instead for 
Did you mean: 

BI 7.0 Issues after upgrade - Migration of Reporting Authorisation

0 Kudos

Hi guys,

Client is upgraded froma BW 3.1c to BI 7.0 and plans to sue the new Analysis Authorisation for BI Reporting.

After completion of the Pre-requisites ie.- flagging the reqd,characterstics as authorisation revelant,and considering the special dimensions(OTCAACTVT),(OTCAIPROV),(0TCAVALID) and KF(OTCAKYFNM).

we Performed the migration by executing the Migration program RSEC_MIGRATION for manually converting the authorisation concept.

Step 1)- Migration Authorizations:Set user --> Selected - All users (1346 users)

Step 2) Migration Authorizations:Authorization Objects---> Selected the Z objects we had in the BW 3.x system and were listed in this screen.

Step 3) Migration Authorizations:Characteristics -


> In Select Assignment Method selected Option 1 -Direct Assignment to Users

Step 4 ) Details of Migration : Charactersitcs -->Selected Nav. attr. and Full Auth.and executed using Execute in Background.

After executing we also got the message - Migration scheduled successfully.Program will end.

After the migration program is run,next when we look in the application log in Tcode SLG1 and choose RSEC_BW_AUTH as the object and MIGRATE as the subobject,everything is green in log and no errors and has messages - Reading of authorizations for authorization object(Object name) was successful.

But after completing all the above steps for the migration of reporting authorisation we are not able to see any 'new analysis authorizations with the technical names that start with RSR_ and end with 8 digits' where are they existing ? are they supposed to be(come) in the Authorization pull down in Tcode RSECADMIN.-Authorizations tab --> Maintain Authorization screen ?

but we dont see any new analysis authorisation RSR_ and end with 8 digits in there......we were expecting the new RSR_ authorisation to be there.Didnt understand what was the use of the migration program ? Will we have to create the all Authorisations manually for each user group/users ?

Please let me know if you guys have done a migration of reporting Authorizations to the new concept using the above migration program and whether i am missing something or looking in the wrong place ?

Thanks,

Kishor

,and then next step using option -1.Direct assignment as the methods of migration

Accepted Solutions (1)

Accepted Solutions (1)

0 Kudos

I referred this same documentation from help.sap and the doc. for the migration process too....but it didnt help.

Plz give some out of the box solution or let me know answer for below

But after completing all the steps for the migration of reporting authorisation we are not able to see any 'new analysis authorizations with the technical names that start with RSR_ and end with 8 digits' where are they existing ? are they supposed to be(come) in the Authorization pull down in Tcode RSECADMIN.-Authorizations tab --> Maintain Authorization screen ?

but we dont see any new analysis authorisation RSR_ and end with 8 digits in there......we were expecting the new RSR_ authorisation to be there.Didnt understand what was the use of the migration program ? Will we have to create the all Authorisations manually for each user group/users ?

thanks,

Kishor

Former Member
0 Kudos

Its an OUT OF BOX documentation ,if you are not able to get it than am sorry to say you need some basic training for good authorization concept or a basis support person who can guide you.

In nushell all the S_RS objects you need has to be added to MANUALLY.

Hope it Helps

Chetan

@CP..

0 Kudos

I just stepped out from a Authorisation concept training class 5 mns back.The authorizatiion trainer also had the same doubt...

The help.sap document says 3 methods are available for migration of the existing reporting authorizations.First all existing reporting authorizations in profiles receive their own,new analysis authorizations."They have technical names that start with RSR_ and end with 8 digits.The three methods differ in the type of assignment to the users."

Where can i see the new analysis authorizations which have the technical names that start with RSR_ and end with 8 digits in the system ?

-Kishor

0 Kudos

Ok.I think my doubts are cleared,plz Refer the Wiki https://www.sdn.sap.com/irj/sdn/wiki?path=/display/bi/authorizationinSAPNWBI&(Authorization in SAP NW BI )

,the document on help.sap was confusing or i as missing something.

So i think in nutshell all the S_RS objects you need has to be added to MANUALLY.

Full 10 points have been assigned to Chetan.

Answers (1)

Answers (1)

Former Member
0 Kudos

Migration help is available to aid you in transferring existing authorization data from the previous concept of reporting authorizations to the new concept of analysis authorizations. You can start it using the program RSEC_MIGRATION. It leads you through the migration configuration step by step and performs a conversion of the old data at the end. The old data remains unchanged.

Migration help supports you in manually converting an authorization concept. You cannot replace this completely because the two concepts are not one-hundred percent compatible. You can expect to have to manually edit or partially remodel the authorization concept.

The simpler the authorization concept, the less editing required

Prerequisites


Before you migrate users and the authorizations assigned to them, you need to make sure that you only migrate complete user groups. Complete means that only those users selected have the profiles that are affected by the selection of users and authorization objects.

Three methods

are available for migration of the existing reporting authorizations. First all existing reporting authorizations in profiles receive their own, new analysis authorizations. They have technical names that start with RSR_ and end with 8 digits. The three methods differ in the type of assignment to the users.

· Direct assignment

In this method, the authorizations are assigned directly. This corresponds to the assignment using Manage Analysis Authorizations ® User Assignment. Maintenance and modification is only possible in the transactions for analysis authorizations.

· Generation of new authorization profiles

A profile is generated for every authorization and assigned to the users. The profile includes the authorization object S_RS_AUTH and the technical name of the analysis authorization as the value. The profile name is also structured like the authorization name, but is not identical to the authorization name. This procedure allows you to create a role concept relatively easily and to include the newly generated analysis authorizations. Old and new authorizations are separate, however, and the old authorizations and profiles can be deleted later as needed.

· Enhancement of existing authorization profiles

In principle, this procedure gets the authorization structure of an existing role concept because new NetWeaver authorizations are inserted into the existing profiles.

Authorizations for authorization object S_RS_AUTH are added to the old profiles, the values of which are the technical name of the newly generated analysis authorizations. In this way, old and new authorizations are included in the same profile and are transferred to the role structure.

Hope it Helps

Chetan

@CP..