Application Development Discussions
Join the discussions or start your own on all things application development, including tools and APIs, programming models, and keeping your skills sharp.
cancel
Showing results for 
Search instead for 
Did you mean: 

HCM security authorization -- restrict by Employee SUbgroup

Former Member
0 Kudos

Hi All,

I need to restrict by EE Subgroup say for example 13, 14 , 17 - 20 . and i did that by adding these numbers in the MASTER DATA -->EMPLOYEE SUBGROUP,but still when executing PA20 Iam able to view the subgroup 15. Can anyone kindly let me know what i have to do now.

1 ACCEPTED SOLUTION

Former Member
0 Kudos

Hi Pearls,

Did you check the trace and also made sure the user is not getting this through some other role? Let us know what the trace looks like.

Thanks

Abhishek

7 REPLIES 7

Former Member
0 Kudos

Hi Pearls,

Did you check the trace and also made sure the user is not getting this through some other role? Let us know what the trace looks like.

Thanks

Abhishek

0 Kudos

Hello Abhishek,

Can you let me know how to see the trace .. and are you talking about the SQL trace in ST05?

I dont understand and the user does not have any other role associated with his profile .

Thanks in Advance.

Pearls.

0 Kudos

Hi Pearls,

I was actually talking about the security trace via ST01. Enable the trace for that user, test PA20 with the users id for data with EE subgp 15, and check the trace.

It might check on a hell lots of things, don't get confused with hr traces... just look for p_orgin for your data.

Thanks

Abhishek

0 Kudos

Hello Abhishek,

I did try ST01 for the user it shows

P_ORGIN RC=0 INFTY=0001;SUBTY=' ';AUTHC=W;PERSA=;PERSG=;PERSK=;VDSK1=;

but i have given like following and saved and generated: I dont know why it is generating like this..

P_ORGIN

INFTY=*;SUBTY=' '

AUTHC=R;PERSA=;PERSG=1;PERSK=13-14 , 17-20, 24 ;VDSK1=;

Can you kindly let me know what I have to do now.

Thanks,

Pearls.

0 Kudos

Hello Abhishek,

Can you Kindly suggest me how to proceed now.Iam stuck at this point and dont know what to do.

Thanks in Advance,

Pearls.

0 Kudos

Hi Pearls,

Seems like your user has more access than that you said you gave.

Run the report for displaying user assignment : RHUSERRELATIONS, when you run it, check the radio button which says "HR authorization", and leave the P_ORGIN check box like that.

This will show you from which profiles user is getting P_ORGIN and what level of access he is getting from those.

Let me know what you get !!

Cheers,

Zaheer

0 Kudos

Thanks Zaheer,

RHUSERRELATIONS report helped me a lot and i was able to find the authorization from which the system was taking all the other subgroups. the issue is been solved and thanks once again for your help.

Regards,

Pearls.