cancel
Showing results for 
Search instead for 
Did you mean: 

ERM implemented: What about PFCG now?

Former Member
0 Kudos

Hi all,

Under the following scenario:

- ERM is the role management tool.

- Roles are generated from ERM to R/3 DEV System and then transported them from DEV to QA and PROD.

How would the role designer be able to transport role if we restrict access them from PFCG?

Which is the best practice for this scenario? Role designer will be using ERM for role definition but they will need to transport roles in the backend from DEV to QA and PROD.

Thanks for all. Best regards,

Imanol

Accepted Solutions (1)

Accepted Solutions (1)

Former Member
0 Kudos

Many thanks for your info FRank.

Where I could get details info regarding the authorizations objects related with PFCG in order to define a custom role for the "restricted PFCG"?

Many thanks in advance. Best regards,

Imanol

Former Member
0 Kudos

Hello Imanol,

You can get this info regarding the authorizations objects related with PFCG in order to define a custom role for the "restricted PFCG" from the transaction SU24, where you can get the information regarding objects that you have in your system and also the objects that SAP recommends to be there with that particular transaction.

Regards,

Hersh.

http://www.linkedin.com/in/hersh13

koehntopp
Product and Topic Expert
Product and Topic Expert
0 Kudos

Hi Imanol,

the objects are well documented in help.sap.com

You can also start an ST01 authorization trace and perform the actions in PFCG, and you will see what's being checked.

Frank.

Answers (1)

Answers (1)

koehntopp
Product and Topic Expert
Product and Topic Expert
0 Kudos

Hi Imanol,

you can limit access to PFCG through S_USER_PRO and S_USER_AGR (amongst others).

S_USER_AGR ACTVT 21 is transpport authorization.

Frank.