on 10-31-2017 7:39 PM
Hi there,
I was just wondering if it was possible to assign personas/admin with display only access for such things as user and role management?
There is no delivered role doing this, but you could create your own.
Copy the standard role /PERSONAS/SUPPORT_ROLE. Among others, this allows certain user- and role-configuration accesses. Take away the user config 'Change' authorization, leaving only 'Display' in place. Also remove the theme and flavor display authorizations and the cache delete authorization. This should leave you with a role that allows displaying users and role configuration.
You may have to add S_TCODE authorization for transactions /PERSONAS/ROLES and /PERSONAS/USERS, since you don't want to grant access to the complete /PERSONAS/ADMIN transaction.
I haven't tried this myself yet but it looks like this should do what you are looking for.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Yes, of course you can base your custom role on /PERSONAS/ADMIN_ROLE if that's closer to the access you want to achieve.
The key thing is though that once you are assigning Admin authorization, this opens most of the admin activities. The current granularity of the Personas authorization objects is not too high. The upcoming support package will change that and allows much more detailed control.
User | Count |
---|---|
89 | |
10 | |
10 | |
9 | |
6 | |
6 | |
6 | |
5 | |
4 | |
3 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.