Application Development Discussions
Join the discussions or start your own on all things application development, including tools and APIs, programming models, and keeping your skills sharp.
cancel
Showing results for 
Search instead for 
Did you mean: 

BI Security migrations

Former Member
0 Kudos

Hi Gurus,

We are planning for a security migration from BIW 3.5 to BI 7.

We are already having roles designed for 3.5. How the migration will happen.

While migrating the old values will be changed/ removed?

What are the steps involved in it while migrating the old concept to a new one?

Do we have any standard roles for BIW which can be used to design the new roles?

I understood that only 80% will be automatic if we use the RSEC_MIGRATION program and the success rate is very less. In this case what is the suggestion from you all.

any more inputs

Thanks

Kind Regards

Praveen Kumar

4 REPLIES 4

Former Member
0 Kudos

after the upgrade most roles will work, just do extensive testing and only solve issues found there.

Former Member
0 Kudos

I belive this didn't answer my questions

0 Kudos

Hi Praveen,

To migrate the security from BW 3.10 to BI 7.0 ,follow these steps :-

A) Fixing the Roles using the SU25.

B) Migration Tool (program RSEC_MIGRATION):

1. Select Users.

2. Select Authorizations.

3. Pick Assignment Method.

4. Set Migration Mode.

Steps of Authorization Maintenance:

Follow these steps to create your authorizations:

1) Define Characteristic as Authorization-Relevant.

2) Defining/creating the Analysis authorizations object.

3) Defining/creating the Analysis authorizations object with

Hierarchies.

4) Steps for Assigning Authorizations to Users: Role based

Assignment.

5) Assign the role to user.

6) Authorization Monitoring.

To fix up the roles you can use SU25 tcode same as R/3. But in BW you have to more concentrate on authorization objects. Here new analysis authorization concept get introduced.

Regards,

Sneha

0 Kudos

Hi,

When you use the migration option on the roles with the objects you made yourself, you must realize that SAP will use non meaning names. Also the tools generate profiles that will be direct added in the user account. You do not have an overview anymore from what is going on. I suggest that you try it out with a small couple of users so you can see what happens. It is possible to undo your migration action.

Invest what kind of objects you made and have to rebuild, invest what the info areas are you need, see the s_rs_icube, s_rs_odso, s_rs_iset and s_rs_mpro for that. Use the functional authorization as you build in PFCG and add there object s_rs_auth in which you put your new authorization object. It will work fine.

Have fun

Bye Jan van Roest