cancel
Showing results for 
Search instead for 
Did you mean: 

'Authorization group' dysfunction in DMS

former_member210673
Participant
0 Kudos

hi All,

I am facing an issue related to 'Authorization Group' control. Please advise.

Requirement:

The document created should be ACCESSIBLE only to a set of Users within the organization.

Process folllowed:

SE54 - Authorization group is created

PFCG - A role is maintained for the set of Users for CV02N, CV03N and the Authorization group created in above step is assigned in: 'Maintained: Authorization for authorization group'

CV01N/02N: The Authorization group value is assigned in the 'Authorization Group' field

Error: The User who's not assigned to in PFCG is also able to view the document.

Note: The Entry for 'Authorization Group' in SE54 is maintained for Table: DRAW. The relevant document type is entered in: Maintained Authorization for document access. The other User has access to SAP_ALL transactions.

Q-1) Am I missing any other inputs to make this work?.

Q-2) Can I create multiple 'Authorization Group' and control the access at EACH Document level?

-Thanks

Accepted Solutions (1)

Accepted Solutions (1)

Makal
Active Contributor
0 Kudos

Hi sdn sap,

The other User has access to SAP_ALL transactions. 

:

:

Q-1) Am I missing any other inputs to make this work?.

If the user has SAP_ALL role assigned to him, then whatever role/ authorization you create will not impact the user with SAP_ALL.

You must not give SAP_ALL to any user. This is violation of SOD. You better discuss with business and design the roles. Only then, what you have done, with respect to Authorization group, will work.

Q-2) Can I create multiple 'Authorization Group' and control the access at EACH Document level?

Yes, you can do this.

Regards,

Amaresh Makal

former_member210673
Participant
0 Kudos

Amaresh,

Thanks for your inputs. We are now using the Sandbox which is the reason the test user has SAP_ALL access. However, I just wanted to make sure this is the reason.

I think I will need to pick another client (Ex: QA) and then test this.

-thanks and regards

Answers (0)