Application Development Discussions
Join the discussions or start your own on all things application development, including tools and APIs, programming models, and keeping your skills sharp.
cancel
Showing results for 
Search instead for 
Did you mean: 

Profile copy got failed.

Former Member
0 Kudos

Hi,

We have a need of assigning sap_all and asked to do in alternate way. But when I am copying sap_all to new profile using su02, Nearly 04 Auth Classes not copied into new. They are:

Auth Class: CV, LO, PP, RSAN.

What could have happened here?

1 ACCEPTED SOLUTION

Former Member
0 Kudos

Hi,

Did you check /nSm21 for more info?

Regards,

5 REPLIES 5

Former Member
0 Kudos

Hi,

Did you check /nSm21 for more info?

Regards,

Former Member
0 Kudos

Can you subsequently add in the auths under those classes?

More importantly why are you copying SAP_ALL? If you need it (which you don't) then use SAP_ALL so it can be easily monitored. As you likely have no requirement to assign all authorisations to a user then create a role with the correct auths.

Usually copies of SAP_ALL are used to try and hide the use of the SAP_ALL profile. Not recommended.

Former Member
0 Kudos

Hi,

As mentioned by Alex, it is always best to assign SAP_ALL so that it can be monitored. What are the reasons behind making a copy of SAP_ALL?? If you are removing specific authorizations (For eg: SAP_ALL without Basis) it does have a purpose, else what you need 2 different profiles that does that same work?

As an alternative, you can create a role (can name it as sensitive) by importing SAP_ALL profile using the menu options. Else, create a role without any transaction codes, and when you go to profile modification, you will be prompted to select a template. Choose SAP_ALL and further restrict the access to S_TCODE with the specific transaction codes, and remove any authorization objects that are not required.

Regards,

Raghu

Former Member
0 Kudos

Hi Dillu,

Pls check if I am right, Go to SU21 and check that auth classes which you said below will not be there.. But instead they'll be in sap_all profile <in first profile of three profiles in composite profile sap_all>. Mean system doesn't shows all auth classes that are there in sap_all.

This is why has to be clarified by experts..!!!!!!!!!!!!!!!!

0 Kudos

Guys,

As said by Foru and Basis Ram.. It is correct that all the auth objs that are in SAP_ALL are not there in su21..!!

I don't know why.. Coming to profile copy, I did as said by raghu and created a copy out of sap_all but same auth classes haven't copied into role. I added them manually again as already every auth obj status is manual because of import from profile. So done..

But would be grateful if reason for not finding auth objs in su21 that are in sap_all would be deeply appreciated...

Thanks Ram for clear info. Points awarded to all on reply basis.