Application Development Discussions
Join the discussions or start your own on all things application development, including tools and APIs, programming models, and keeping your skills sharp.
cancel
Showing results for 
Search instead for 
Did you mean: 

Object found by SUIM, not visible in PFCG (same in AGR_1251 and UST10S)

Former Member
0 Kudos

Dear All,

In SUIM I get some roles listed when I search for a specific authorization object (S_USER_AGR in this case). Wehn I look at the role via PFCG however, the object is not visible.

When I look at the role/profile via tables:

- AGR_1251for the role : object S_USER_AGR not present

- UST10S for profile: S_USER_AGR is present

It seems that the output from UST10S is the one giving the actual authorization (as the testuser seems to have access to S_USR_AGR).

What can I do to have the PFCG listing the real/actual authorizations?

Thanks in advance

Kristof

1 ACCEPTED SOLUTION

Former Member
0 Kudos

>

> It seems that the output from UST10S is the one giving the actual authorization (as the testuser seems to have access to S_USR_AGR).

Hi,

In SU56 you will get info for the role & profile granting the S_USER_AGR authorisation.

5 REPLIES 5

jurjen_heeck
Active Contributor
0 Kudos

What color is the authorizations tab traffic light in PFCG for the role?

Former Member
0 Kudos

>

> It seems that the output from UST10S is the one giving the actual authorization (as the testuser seems to have access to S_USR_AGR).

Hi,

In SU56 you will get info for the role & profile granting the S_USER_AGR authorisation.

Former Member
0 Kudos

As Jurjen expected, I too feel that the authorizations are not generated, thats the reason UST10S and agr_1251 are showing different data. Please check if the colour of Authorization tab is "Yellow" and it says "Profile not generated". In this case generate the profiles and then check.

Also check out if there are any other profiles(directly) assigned to the test, as mentioned by Alex.

Even if all this does not help and you are sure that this is because of a role which is out of sync. then try adding S_USR_AGR -> with the values showing in UST10s > generate the role> Now delete this object and again generate the role.

Former Member
0 Kudos

Thanks for the replies.

The authorization tab is green... so according to PFCG, everything is ok :s

In the meanwhile I had deleted the profile and created a new one for the role in question.

Now the "ghost" objects are no longer listed via SUIM. So the problem is solved for this role.

I just wonder if there are lots of roles giving the same problem (containing authorization for object not listed in PFCG...). And also the cause of this problem.

Kind regards,

Kristof

Edited by: Kristof Smets on Jan 25, 2010 3:58 PM

0 Kudos

Hi Kristof,

Don't let the wonder go away:-)) Check why that role was inconsistent at the first place.

1 - Check the role if its out of sync in Dev- Production as well. (Assuming you have already corrected this in Test sysh tem by creating new profiles).

2 - Check out the recent transports for that role. Check out the status of those transports(RC=0/RC=4/8/12). If not RC=0 then whats the error message.

3 - Check out if there was a system refresh recently carried out in your test environment. If yes then from which system this refresh is carried out. check out the role status in that system as well.

Run PFUD for User Master Data Reconciliation.Hope this will resolve the issues for all the roles in your system.