10-17-2008 10:25 AM
hi experts
In my dev system i created fico role from sap menus for fico-module users.now they asking restrict the t-codes FSP0, FSS0, FS00 from that role.how can we restrict that tcodes from that role
10-17-2008 10:37 AM
> how can we restrict that tcodes from that role
By taking the tcodes out of the role menu and maintaing the authorization data.
Also please try not to thing in terms like restricting. SAP security is about allowing things.
10-17-2008 10:37 AM
> how can we restrict that tcodes from that role
By taking the tcodes out of the role menu and maintaing the authorization data.
Also please try not to thing in terms like restricting. SAP security is about allowing things.
10-17-2008 11:44 AM
Hi,
Julius is right. Be aware of the fact that when you changes a role by for instance deleting transactions or adding them, the authorization objects will be changed as well. This might give problems, so I advise you to copy the role do your actions and compare this with the origin and the authorization objects if there is not going something wrong. It is rather complicated. If you have never used the expert mode in the authorization tab, please do this and find out what the results are. Bottom line be carefully.
Have fun
Bye Jan van Roest
10-17-2008 11:45 AM
10-17-2008 12:02 PM
And I meant 'not to think' but typed 'not to thing'. Oh well, stuff happens
10-22-2008 12:21 PM
Hi Vasu,
You can restrict the tcodes from the role by removing the tcodes from the menu tab, once you delete the tcodes from the menu tab, you need to go to auth tab and maintain the missing auth obj values and again after deletion of tcodes the auth tab will turn YELLOW.
So make sure you delete the tcodes from the menu and then you need to go to auth tab and generate the profile, until the tab becomes GREEN and then do user compare.
Hope this answer is helpful
Best,
Suchitra