Application Development Discussions
Join the discussions or start your own on all things application development, including tools and APIs, programming models, and keeping your skills sharp.
cancel
Showing results for 
Search instead for 
Did you mean: 

Security Admin can deactivate Authorization Object (Standard)

shivraj_singh2
Active Participant
0 Kudos

Security Gurus,

I am facing a unique situation with regards to Security Admin’s access in Production to deactivate authorization objects.

The Security Admin in Production when opens a role in PFCG, then goes to Authorization tab and tries to deactivate authorization objects with different status, the results are as follows:

- Authorization Object (Manually) : Cannot deactivate/ or activate

- Authorization Object (Maintained) : Cannot deactivate/ or activate

- Authorization Object (Changed): Cannot Deactivate/ or activate

- Authorization Object (Standard): Can Deactivate, but cannot activate

So the Security Admin can deactivate “Authorization Object (Standard)”, however it cannot reactivate the same or any other authorization object.

The trace is not picking up any check when “Authorization Object (Standard)” is Deactivated, however for every other failed deactivation & re-activation it is showing missing authorization for S_USER_VAL (which is assigned as all ‘’, i.e. No authorization). S_USER_AGR is assigned with 02 access, which is coming in for user assignment.

Do you think it is a bug, or there is a way to that deactivation of “Authorization Object (Standard)” can be limited without affecting access for user assignment ?

2 REPLIES 2

shivraj_singh2
Active Participant
0 Kudos

sapnote - 312682 - has been very helpful with this issue. Regards, Shivraj

Bernhard_SAP
Employee
Employee
0 Kudos

Hi,

the behaviour should be as is described in note #642359. I suggest to recheck the values you have in s_user_val-auth-fields...

b.rgds, Bernhard