Application Development Discussions
Join the discussions or start your own on all things application development, including tools and APIs, programming models, and keeping your skills sharp.
cancel
Showing results for 
Search instead for 
Did you mean: 

Question about "Expert mode for Profile Generation

Former Member
0 Kudos

Hi, I have a question about expert mode for profile generation. When I click this icon, and choose "read old status and merge with new data". If the authorization was changed before, there will be two records, one is default value with "Standard" & "New" status, the other one is updated value with "Changed" & "New" status. I checked the manual and not exactly understand the solution in the manual, pasted the solution as below.

Solution:

Before you make a change to authorizations that generates the status Changed, you must first perform the following steps:

1. Copy the appropriate (standard) instance.

2. Set the template to inactive.

3. Make the changes to the copy.

In brief, before you process a specification in such a way that has the status Changed appears, you must copy the specification, and set the template to inactive.

Can anyone advise me the solution in detail as I don't understand it. Thanks.

James

18 REPLIES 18

Former Member
0 Kudos

Hi James,

there will be two records, one is default value with "Standard" & "New" status, the other one is updated value with "Changed" & "New" status.

Your question itself has the answer. When the default Activity/Field values are changes for an authorization object, the status will be set to Changed. When you use the "Read old status and merge with new data" option, since the earlier object was changed, it keeps it intact and adds a new one with status Standard. If you notice, they will be with the default activity/field values.

Profile Generator by this way, provides you room to adjust the profile data as per your requirements before you generate the profile again.

Hope this clarifies.

Regards,

Raghu

arpan_paik
Active Contributor
0 Kudos

Hi James,

If the authorization was changed before, there will be two records, one is default value with "Standard" & "New" status, the other one is updated value with "Changed" & "New" status

As Raghu mentioned that your qyuetion already contain the answer. Yes I didn't understand what actually your question was. However on the above I found the statement partially incorrect. Existing authorization should be "Changed" & "Old" status.

One further point to add that expert mode (merge with new data) will always check role menu. Results it will through default value maintained in customer table (USOBT_C, USOBX_C) in case for changed authorization. Sometimes you may get new object even the was maintained properly (by steps you mentioned) due to customer table change.

Regards,

Arpan Paik

Former Member
0 Kudos

This message was moderated.

0 Kudos

Sorry about the spam... it is probably caused by SDN's silly ponits system and people rushing in to "compete" against each other. Causes endless problems...

I like the comment and react to it with ha ha ha.....

However, there is one exception to this rule. A special case... I will leave that to Raghu and Arpan to find once they read the question carefully....

Well is this change one will remain as it is even all the linked transactions been removed? yes/no? Well I will watch this thread and will wait to know the special case

0 Kudos

> Well is this change one will remain as it is even all the linked transactions been removed?

Okay, fair enough... there are two exceptions in that case

Lets see who has encountered the other rarity.

Cheers,

Julius

0 Kudos

Hi Julius,

Sorry about the spam... it is probably caused by SDN's silly points system and people rushing in to "compete" against each other. Causes endless problems...

I too agree on this, and am against the point system. I will be much happy if it is removed .

However, there is one exception to this rule. A special case... I will leave that to Raghu and Arpan to find once they read the question carefully....

The solution provided is out of my expertise, where the similar issue happened even without making any SU24 changes.(Probably need to look at BACK to SCHOOL options). It is not provided in a hurry and I am also happy if you can identify and take an appropriate action, when you feel my posts are SPAMMING in the forum.

Thanks

Raghu

Edited by: Raghu Boddu on Dec 21, 2010 2:56 PM

0 Kudos

Hi Arpan, thanks for your correction, it's standard & old status. I am sorry for typo.

Hi Julius, thanks for your comments, I am not sure how to do it step by step in system in accordance with the 3 steps of solution provided by SAP. Can you please advise on that?

Thanks

James.

0 Kudos

@ James: See SAP note , section C (Combining Authorizations):

In exceptional cases, the combining of default authorization objects given in the example may be unwanted.

...

a) Copy the combined standard authorization as often as required. Maintain the empty fields in the copies and change the default values. This changes the authorizations to the status "Changed". Then deactivate the standard authorization (but do not delete it!). This creates a green status display for the object, and prevents the same standard authorization from being included in the next merge process.

@ Raghu: The exception is here:

If you have an inactive authorization with maintained fields from several transactions in the menu and a copy of it in changed status which remains active and is "protected" by the inactive original, it is possible that one of the transactions will propose a new field value from SU24 which then needs to be standard. As PFCG does not know whether you want to keep the maintained value as it was before or want the new standard value for the field, it proposes a new standard authorization for the object and removes any field values from the inactive maintained one.

This makes it possible for you to decide whether the new authorization should be "changed" as well or whether SU24 is correct for the transaction also in the case of this role and it can be left.

9 times out of 10 the choice of transaction in the menu is incorrect in the first place!

ps: thanks for being a sport about my rant against the ponits system.

Also a merry christmas to all and the best wishes for 2011. May all your authorizations be "standard" and your sy-subrc's still return rc=0 in the new year

Julius

0 Kudos

Hi Julius,

Thanks for sharing the merge info. I never faced it earlier (Or may be didn't notice!!). Will look for this now onwards.

ps: thanks for being a sport about my rant against the ponits system.

Well regarding this I would like to say one line from a movie (Charles Bartlett) -- "I am a teenager and popularity is damn important to me". Though I am no teenager but in SAP Practice I feel like teenager (sometimes kid) and points are damn important to me...

Regards,

Arpan Paik

0 Kudos

... and points are damn important to me...

And in the words of Harry Callahan...

What are you going to do with those, huh punk?

0 Kudos

When there will be enough then will think on that..

0 Kudos

- but tailored..."I know what you're thinking. "Did he award six ponits or only five?" Well, to tell you the truth, in all this thread I kind of lost track myself. But being as this is a Security Forum, the most powerful Forum in the world, and would blow your head clean off if you ever read all the threads, you've got to ask yourself one question: Do I feel lucky? Well, do ya, punk?"

Merry Christmas and may all your SU53's be true

Cheers

David

PS please - no points as they are a waste of time

Edited by: David Berry on Dec 22, 2010 4:19 PM

0 Kudos

When posting on thread but not getting point, does not mean it was rubbish. But when you are getting point means someone get benefited and points comes in terms of recognition. It's not six or five. When I read rules of engagement I learnt that. But I should have knew earlier that Harry is dirty anyway

0 Kudos

Hi Arpan

Please accept my apologies if my comment offended - it was not intentional and just a line (modified) from a favourite old film...

Kind regards

David

0 Kudos

I would also like to send season's greetings to all the Guest user ID's on SDN whom I have deleted in 2010 for having "gamed" the ponits system or made a stubborn pest of themselves by taking spoonfeeder bait all the time.

All in all it was a good year for practicing my forensic skills, but nothing as spectacular as 2008 (about 20 thousand user IDs deleted) and the "village idiots" of 2009 (about 50 thousand ponits removed).

I dream of a day when (strict) moderation will no longer be necessary and reputations are built on interesting and usefull contributions.

Note that the future of the SDN ponits system is under review and there is a lot of preference for a more community based rating system (thumbs up, thumbs down). I have volunteered the security forum to pilot this, so you may want to sell your ponits on Ebay beforehand and start investing in threads and posts which have high content value (low is that which already exists on help.sap.com or random searches for OSS notes with lucky hits).

Please think about this for your new year's resolutions to help improve the quality and community aspects of the SDN Security Forum.

Cheers,

Julius

0 Kudos

Really a good news:) Way to go!!

I wish all SCNers a very happy new year!!

Rgds,

Raghu

Edited by: Raghu Boddu on Dec 24, 2010 8:21 PM

0 Kudos

I was thinking not to post in this thread but there is something that I should made clear to all of you. In recent days I got addicted to SDN rather to going to any other social networking staff. I don't know the reason but I am spending lot of time here. I just got a thread and jump into it. but later I learnt from Julius that this is community for professionals not for some lazy staff can't google there need. I take that as a learning and keep going on. My intention was not to hurt anyone and I pay due respect to moderators for their effort to keep SCN cleen. BTW I like the idea for thumbs up and down though I see that somewhere else

@ David : I know the dialouge and it is one of my favorite.

Happy new year to all SCN users.

0 Kudos

Bless you and happy posting in the new year 2011!