cancel
Showing results for 
Search instead for 
Did you mean: 

how can I make only one user to be able to change a field

Former Member
0 Kudos

I want only one user to be able to change material group for example.

I want all other users when trying to change material, to see thie field - material group - display only.

How can I do this?? What are the steps??

Thank you

Accepted Solutions (1)

Accepted Solutions (1)

Former Member
0 Kudos

Dear Theodoros,

You can achieve this by giving "01" (create or generate), "02" (change), and "03" (display) activity in the material group authorization object for one user. For other users the activity should be "03" (display) only.

Users then can be granted permission based on these authorization objects based on the roles assigned to them. Each role has an authorization profile. The profile is where the specific data for the authorization objectu2019s field is assigned to the configured permitted activity.

Regards,

Naveen

Former Member
0 Kudos

in which transaction should I go to maintain these activities?

can you tell me the steps?

thank you

Former Member
0 Kudos

Dear Theodoros,

For the user to create/change material group:

Go to transaction PFCG -> enter the role that you are using -> Select "authorizations" tab -> Edit Profile -> Here you will maintain activities for different authorization objects. Maintain Acticity "01" for material group authorization object.

For the users to display material group:

Go to transaction PFCG -> enter the role that you are using -> Select "authorizations" tab -> Edit Profile -> Here you will maintain activities for different authorization objects. Maintain Acticity "03" for material group authorization object.

Authorization Object for Material Group: M_MATE_WGR

Regards,

Naveen

Former Member
0 Kudos

I did this but still nothing happens.

Do I also have to add anything in authorization group, under activities??

Former Member
0 Kudos

Dear Theodoros,

Have you generated your changes?

You can give * as authorization group. Make sure that you generate your changes.

Regards,

Naveen

Former Member
0 Kudos

i did generate and I did add * in authorization group.

I think the problem is different.

I do not have authorizations for all other transactions. in SU01 for the users, in tab profile, there are two profiles: SAP_ALL and SAP_NEW , that allow the users that have them to do everything in SAP with no restrictions.

When I generate the authorisation I did for material group, it adds in the tab profile in SU01, two new profiles given the name T-DV260006 and T-DV2600061. if I remove the profiles SAP_ALL and SAP_NEW the user is not allowed to do anything,

Is there a way to allow the user do anything but changing the material group??

thank you

Former Member
0 Kudos

Dear Theodoros,

SAP_ALL will give unrestricted access to the user.

Is there a way to allow the user do anything but changing the material group??

You will have to use SAP_ALL template and modify material group authorization object ("03" for display and remove all other activities). Use the same.

Regards,

Naveen

Former Member
0 Kudos

got it,

can you please tell me what should I do to copy SAP_ALL to another profile?

and the one that I will create how will I change its authorisations?

Thank you

Former Member
0 Kudos

Dear Theodoros,

Create a new role by adopting the SAP_ALL Template refrence. Modify the authorizations and generate your changes.

Regards,

Naveen

Answers (0)