cancel
Showing results for 
Search instead for 
Did you mean: 

How to determine the effective authorization in a user's access

0 Kudos

I understand that the authorization can have a few status, standard, maintained, changed and manually. I understand their differences but would like to understand the effective authorization a user has if there's a combination of them.

If the authorization object has more than 1 authorization (standard vs changed), which is the effective authorization a user has? Please see example below:

In this case, is the effective authorization T-QS95000800 ?

When ever there are further maintenance or changes to the authorizations, is the effective one always the one with suffice 0?

Thank you in advance.

Accepted Solutions (1)

Accepted Solutions (1)

Colleen
Advisor
Advisor
0 Kudos

Hi RX

You have two concepts at play here

1) PFCG Maintenance with SU24 integration - standard, maintained, manual and change is all about how an authorisation came to be the way it in in PFCG. SU24/PFCG Integration aim is to have mostly standard/maintained, avoid changed as much as well, and manual for exception. By doing this, you reduce orphan objects remaining in the role after your removed access from the role menu.

2) Effective authorisations is what ends up in the user buffer based on the values in PFCG authorisations, role profile generated, assignment to user, and user compare (you can see the current status in SU56 for a user)

The effective authorisations - what a user has access to and what they can do does not consider how the authorisation came to be in a role. You not see the SU56 user buffer and have a note identifying this as standard.


Back on Point 1 and the aims for maintenance

Standard - the entire authorisations comes from SU24 maintenance for the menu item. You make no changes


Maintained - partial proposal comes from SU24 and you will in the blank values in PFCG for the role


Changed - a full or partial proposal came from SU24 but you overrode on of the values that was maintained. This can cause problems next time your use expert mode on the role. However, I've noticed recent ABAP stack will automatically copy the standard and deactivate it if you attempt to change the proposal. This stops an additional permission being brought into the role. But changed status are treated like a manual object when you have to clean your role up - if you remove the original transaction from the menu, the changed version remains


Manual - you manually added the authorisation in PFCG and it has no connections to the SU24 data.

SU24/PFCG data merges and groups common permissions together when the fields match. The note Tammy linked to you explains this.

Finally, the role you have - the effective authorisation is Activity 01, 02, 03, C1, C2 for all master data. They contain the authorisations of the first two.

Answers (1)

Answers (1)

TammyPowlas
Active Contributor
0 Kudos

Hi - I think this is best explained by this SAP Note, which includes several examples of what you are asking: https://launchpad.support.sap.com/#/notes/113290