08-04-2010 12:43 PM
I have to add access to a user in HR with authorization object P_ORGIN.
Currently she already have access to certain infotypes but only to a specific employee subgroup.
I need to give her additional access to infotype 2001 for all the employee subgroup.
Question is P_ORGIN being checked as a block or will it take the combination of all the P_ORGIN data that she has. Meaning when I give her * to the employee subgroup in one role, she can now have access to all the employee subgroup for the infotypes that she has from her other role.
Thanks in advance for the response.
08-04-2010 12:50 PM
Hi,
P_ORGIN will be checked only as block, which means it will check for combination of infotypes against emp sub groups.
If the user has * in emp sub group in one role against say 0000 infotype, that means she will have access on that infotype. Overall combination shud met.
Rgds,
gadde
Pls correct me if my suggestion was wrong
Edited by: Durga,Gadde on Aug 4, 2010 5:21 PM
08-04-2010 1:00 PM
Angel,
Question is P_ORGIN being checked as a block or will it take the combination of all the P_ORGIN data that she has. Meaning when I give her * to the employee subgroup in one role, she can now have access to all the employee subgroup for the infotypes that she has from her other role.
If infotypes are same then * will overdie(she can now have access to all the employee subgroup ). Whether you create two roles or one role.
eg1:
infotype: 2001
Subgroup: A
eg2. Infotype: 2001
Subgroup: *
If infotype is different then * will not override.
Infotype: 2001
Subgroup: A
eg2:
Infotype: 2002
Subgroup: *
Thanks,
Sri
08-04-2010 7:35 PM
As others have mentioned the authroization works explicitly
and remember to make manual entries for P_ORIGIN so that you can enter appropriate authorizations for different combinations of infotypes