Application Development Discussions
Join the discussions or start your own on all things application development, including tools and APIs, programming models, and keeping your skills sharp.
cancel
Showing results for 
Search instead for 
Did you mean: 

How to activate authorization profile in ERP 6.0

Private_Member_398166
Participant
0 Kudos

Hi,

Could you give me a hint please.

In ERP 6.0 system, I copied a authorization profile from &_SAP_ALL_13, and changed it.(saved successfully)

But clicking activation, message "Unable to activate, authorizations missing: ..." is shown in pop-up.

What happend in this process.

In R/3 46C system, such a message is not shown.

authorization profile activation process changed in ERP 6.0?

I did following actions;

T-CD: SU02

- Profile: &_SAP_ALL_13 / With any options off -> Create work area for profiles

- -> Copy Profile

- Copy profile From &_SAP_ALL_13 To Z_SAP_ALL_13 -> Execute

T-CD: SU02

- Profile: Z_SAP_ALL_13 / With any options off -> Create work area for profiles

- change some objects in the profile (include delete line) -> Save -> Activate

regards,

Katsumi

1 ACCEPTED SOLUTION

Former Member
0 Kudos

Hi Katsumi,

The user from which you're activating the profile doesn't seem to have enough authorizations. Check the SU53 report and find out whats missing. If you can't do it by your self, post the SU53 report.

Regards,

Srihari

10 REPLIES 10

Former Member
0 Kudos

Hi Katsumi,

The user from which you're activating the profile doesn't seem to have enough authorizations. Check the SU53 report and find out whats missing. If you can't do it by your self, post the SU53 report.

Regards,

Srihari

Private_Member_398166
Participant
0 Kudos

Hi Srihari,

I also checked auth role and profile.

But, logon user is admin user, whose role and profile are bellow.

<role>

- SAP_BC_AUTH_DATA_ADMIN

- SAP_BC_AUTH_PROFILE_ADMIN

<profile>

- SAP_ALL

- SAP_NEW

- S_A.SYSTEM

Does this user have enough auth?

regards,

Katsumi

0 Kudos

Hi Katsumi,

First of all, as said by Ashutosh, please check whether the two roles

  • SAP_BC_AUTH_DATA_ADMIN

  • SAP_BC_AUTH_PROFILE_ADMIN

are maintained properly and generated.

If not do as Ashutosh said.

workaround:

1. check for the object S_USER_PRO for the user through SUIM

2. If the user does have this object, check the role from which it is coming

3. go to the role, check the ACTVT field of this object.

4. if it does not contain 63,64 please give them. (by default these will not be there. You need to force them by pressing F7)

5. Save and generate the role.

6. Do the complete user compare.

Now your user must be able to generate and activate the profiles.

Regards,

Srihari

Edited by: Srihari Rao on Aug 13, 2008 12:11 PM

Former Member
0 Kudos

Dear Katsumi,

Go to change authorization data and check weather every node is in green.If not expand every node and check anything in yellow or red that should come in green.Then generate that profile Shift+F5.

Now after generating your profile make sure to click on User Comparison.

Also there might be a possibility that user must not be having enough authorization.In that case :

From the user login wherever this message authorization faliure is coming type /nsu53 and see for missing authorization.

Now go to your login(considering that you have full authorization) use tcode PFCG and role in which use tcode is residing.Add manually the missing object which reflects on the SU53.Again generate and make user comparision.

Now come back to user login and again try .If that is still not coming repeat the above 2 steps.

Regards,

Ashutosh

Edited by: ashutosh singh on Aug 13, 2008 7:53 AM

Edited by: ashutosh singh on Aug 13, 2008 7:54 AM

Private_Member_398166
Participant
0 Kudos

Hi Ashutosh & Srihari,

Thenk you for your infomation, but activation is still impossible.

I checked the role SAP_BC_AUTH_PROFILE_ADMIN & Z_BC_AUTH_DATA_ADMIN and updated every yellow node object to green in it, assigned * to them.

And did User Comparison, "User master record for all roles adjusted" was shown.

In authorization object S_USER_PRO of SAP_BC_AUTH_PROFILE_ADMIN, I checked 63:Activate & 64:Generate in ACTVY.

In T-CD: SU53, following

-User Name: ADMIN

-Authorization Object

-System: R02

-Client: 200

-Date: 2008/08/13

-Time: 15:23:13

-Instnce: vmvup02

-Profile Parameter auth/new buffering: 4

The last authorization check was successful

regards,

Katsumi

0 Kudos

Hi Katsumi,

Check if the user has the ACTVT 07 for S_USER_PRO in the roles assigned to him/her?

If not please give it.

Regards,

Srihari

Private_Member_398166
Participant
0 Kudos

Hi Srihari,

Yes, I did check 07:Activate&Generate in authorization object S_USER_PRO of SAP_BC_AUTH_PROFILE_ADMIN.

regards,

Katsumi

0 Kudos

Hi,

Did you solve this problem? i have the same problem. Can somebody help me please?

Thanks

Former Member
0 Kudos

I know this is an old post but I am answering to help future searchers. The message "Unable to activate, authorizations missing" was related to trying to activate in SU02. This means that the profile or one of the profiles in a composite did not have any authorization objects in it, not that the person did not have authorizations to activate it.

0 Kudos

Hi, Have you come across this error message when it says the authorization does not exist/activated when using SU02, but yet you can drill down into the authorisation from SU02. Is this a bug in the system. Do you know how to correct it so that it can see the already created object.

Regards Rose