reading the SAP HELP online documentation, it is explicitely mentioned that 0TCAACTVT, 0TCAIPROV, 0TCAVALID needs to be flagged with "authorization relevant" if analysis authorization will be used.
I have a customer using analysis authorization (SPRO is correctly set too), having activated the flag "authorization relevant" for some info objects like e.g. 0comp_code and for the 0TCAxxx info objects mentioned before. 0COMP_CODE was transported to production BI system but not the 0TCAxxx info objects, they are only activated in production but without the flag.
On development, analysis authorizations were created with activity 03 in reporting roles and activity 02, 03, 06 in planner roles (they are using BI IP). The analysis authorization was transported into production.
In production, users having reporting role and 0TCACTVT = 03 are working correctly, they are not able to execute planning queries (authorization message is coming, there is no further restriction on query level). Does it mean, that internally BI is not really checking "authorization relevant" flag for 0TCAxxx info objects? Has anyone made the same experience? I thought without having flag set, the analysis authorization won't work properly.
Edited by: Stephan on Jan 12, 2010 4:14 PM