cancel
Showing results for 
Search instead for 
Did you mean: 

Authorization Objects assigned to a Transaction (GRAC_PFCG_AUTHORIZATION_SYNC)

Former Member
0 Kudos

Hi all,

I have trigger the GRAC_PFCG_AUTHORIZATION_SYNC in order to populate all tables related to Authorization Objects, Fields and Values.

Now, i'm creating a new function and assigned a transaction. When i check the Authorization Objects that are related to this transaction i see differents casuistics:

1) In portal are assigned more Authorization Objects than in USOBT

2) In portal are assigned more Authorization Objects than in SU24

So my conclusion for this is that we don't have USOBT a not SU24 transaction updated.

On the other hand, I have performed a test, creating a new role and assigning the same transaction and in this case PFCG assigns the same Authorization Objects that are assigned in portal. So, Portal and PFCG are syncronized but not USOBT and SU24. Where do this Authorization Object come from? I mean, how can i identify the authorization objects that PFCG will provide to a role related to a transaction?

Thank you in advanced.

Accepted Solutions (1)

Accepted Solutions (1)

former_member225453
Active Participant
0 Kudos

Hi Sara,

You can check Note 1618340   - Authorizations Synch GRAC_AUTH_SYNC  ERROR

Regards,

Shreya

Former Member
0 Kudos

Hi Shreya,

This is not my problem actually. I'm trying to get further information of my customer to try to find out why is having this unsyncronization between SU24/USOBT_C and PFCG. Does anyone know why if i add a transaction to a role in PFCG provides more Authorization Objects than SU24 and USOBT_C?

Thank you in advanced.

Former Member
0 Kudos

Sara,

Sounds like you are dealing with a parameter transaction. A parameter transaction will show fewer auth objects in SU24, because it will inherit the parent transaction SU24 setting.

You can get these detail in SU24, just change the layout to include "Transaction Type" & "Original Transaction Code".

Once you found the Original T-Code, you will see the auth object you created in the role will match with the SU24 of the original t-code.

Regards,

Lye

Former Member
0 Kudos

Hi Tse,

That was exactly what i was asking.

Thank you very much.

Answers (0)