09-14-2010 6:15 PM
Hi,
Until recently, I was able to assign Roles to a user (by position) using the Organizational Management button on the User Tab in PFCG. For some reason now, in PFCG when I go to the user tab I see the User Assignments fine on this screen (both by position and manual assignment) but when I click on the Organizational Management button (which is showing RED), it shows the warning 'Require reconcilliation of indirect user assignment' before I even make a change.
What is happening now, if I assign a Role by position to a user and push the reconcile button, it causes all Roles assigned by position to dissappear in EVERY role (not just the one I am working on). When I run PFUD it does not correct anything. However, one of the other security administrators we have is not having this issue and when I get her to run PFUD, the Roles by position are back in all roles.
Basically, at this time I can no longer assign Roles by positions in PFCG.......
This is something that has come up only recently (there are 2 of us experiencing the same issue).
Any help would be greatly appreciated.
Thanks!
Sharon
09-15-2010 8:09 AM
Hi,
Try comparing your PLOG object (in HR group) authorisations against the user who can do the required task. Especially where object is S (position) and AC (role). Infotypes 1000 and 1001 are the main ones to check.
Cheers,
Saku
09-14-2010 8:19 PM
Hi,
Try this when the other two security admins are not doing what you are trying to do.
I am guessing that hey have certain roles in change mode , which are assigned to the organizational structure.
Or you are having two sessions of pfcg open on your own system which might be linked to the Organizational structure.
09-14-2010 8:42 PM
Franklin is implying that there is an enqueue lock on the role, but the PFCG function modules generally do not check the enqueue process (it happens prior in the application coding) so I would rather suspect that you should compare your own roles to those for whom it works, or check in ST22 for a dump (this is always usefull to do when anything unexpected happens).
Cheers,
Julius
09-15-2010 8:09 AM
Hi,
Try comparing your PLOG object (in HR group) authorisations against the user who can do the required task. Especially where object is S (position) and AC (role). Infotypes 1000 and 1001 are the main ones to check.
Cheers,
Saku
09-15-2010 1:19 PM
Please check ST22 dump.And also check when you run PFUD,it runs successfully
09-15-2010 1:46 PM
Thanks everyone for the responses...... What I did not realize before I posted this question is the one person that has no issues with assigning the roles by positon is doing it thru the HR PO13 transaction - NOT using PFCG. So, what that means is both of us that are using PFCG have the issue and the one using PO13 does not....I assigned the PO13 transaction to myself yesterday and the issue is gone however I would rather use PFCG so I still would like to figure out the issue. Do all of your answers still apply to what I've told you today?
09-15-2010 9:14 PM