07-31-2008 10:53 AM
Hi,
While creating roles, we used the ' change authorization object' instead of the expert mode for profile generation to maintain the auth objects. Now, when we add or delete transaction codes we get lot of duplicates (those which says 'new') and we have to manually delete these objects which is very time consuming . This happens inspite of using the 'expert mode for profile generation'. Is there any way that we can avoid it. Thanks very much in advance.
regards,
07-31-2008 6:05 PM
Hi,
When the authorization values are maintained in su24 and you use pfcg in expert mode with edit old status or with merge option you will get duplicate authorization block with the vaues pulled from su24.
If su24 does not have any values for authorization then only the status of the object may change and objects are not duplicated.
Just to add ..
If the status of the object is changed from "standard" to "changed" then newly entered tcodes have their object status "changed".
Also see note #679050
Rakesh
07-31-2008 11:16 AM
Hi Ajay,
SAP note #113290 gives the explanation why and how new authorizations are merged when using 'read old status and merge with new data' (which is used in fact when pressing 'change authorization data' and the menu of the role has changed since last merging).
b.rgds, Bernhard
07-31-2008 6:05 PM
Hi,
When the authorization values are maintained in su24 and you use pfcg in expert mode with edit old status or with merge option you will get duplicate authorization block with the vaues pulled from su24.
If su24 does not have any values for authorization then only the status of the object may change and objects are not duplicated.
Just to add ..
If the status of the object is changed from "standard" to "changed" then newly entered tcodes have their object status "changed".
Also see note #679050
Rakesh