cancel
Showing results for 
Search instead for 
Did you mean: 

Authorization objects in RAR not updated

Former Member
0 Kudos

Hi everyone,

i'm facing an issue with RAR (GRC 5.3, SP10): i've just imported the authorization objects from SAP (SE38 -> /VIRSA/ZCC_DOWNLOAD_SAPOBJ -> saved in UTF8 format), but when i look the function in the rule architet the authorization objects setting are not the same:

Example: in SAP the transaction F-04 needs the auth obj F_BKPF_BLA/BUK/KOA (i use transaction SU22 to check the auth obj) and the export file has the same settings:

F-04 F_BKPF_BLA ACTVT

F-04 F_BKPF_BLA BRGRU

F-04 F_BKPF_BUK ACTVT 01

F-04 F_BKPF_BUK BUKRS $BUKRS

F-04 F_BKPF_KOA ACTVT

F-04 F_BKPF_KOA KOART $KOART

In RAR the transaction F-04 is in the function AP01, AR01, AR02, GL01. The transaction has different settings in every function: in AP01 there is only F_BKPF_KOA in status active, in AR01 there are F_BKPF_BUK and KOA in status active,...

I re-generated all the rules, but the settings are still the same.

I think the settings must be the same.

Am i right?

Thanks in advance!

Luigi

Accepted Solutions (0)

Answers (2)

Answers (2)

Former Member
0 Kudos

.

Former Member
0 Kudos

Luigi,

The function has all the associated auth objects, right? All the auth objects/permissions may not be enabled in the function. As you are using standard SAP ruleset, SAP has determined that the combination of F-04 and associated enabled auth objects create violation when assigned with another set of tcodes and auth objects. You can always enable all the auth objects if that is what makes sense as per your business.

Can you go through the RAR config guide to get an understanding on this?

Regards,

Alpesh