06-02-2010 8:36 AM
after upgrade from ecc5 to ecc6,
why all of the users can use spro?
First, I think it is SAP_NEW profile, because I give it to all users. then I revoke the profile from all users.
but they can still use spro.
Could you give me some advices?
thanks a lot.
06-02-2010 9:25 AM
Hi,
Try to find out how the access is coming from SUIM with various avaialble options there like Users, Roles, Authorizations etc...
Regards,
Sharath
06-02-2010 9:25 AM
Hi,
Try to find out how the access is coming from SUIM with various avaialble options there like Users, Roles, Authorizations etc...
Regards,
Sharath
06-02-2010 12:56 PM
Hi,
what exactly do you mean by using SPRO? If executing transaction SPRO then you can search which roles or users have access to transaction SPRO using reports from SUIM. You can also user ST01 trace to see what authorization checks SAP perform. Check also SU24 if authorization check S_TCODE is turned off.
Cheers
06-03-2010 1:26 AM
thanks for your help.
I get the answer.
one of our roles have an authorization object:"S_TCODE",and it`s value is "*", so the users can use all tcodes.
Maybe, I make a mistake when changing this role. I manully add this object to this role and give the value:"*".
thanks again.