cancel
Showing results for 
Search instead for 
Did you mean: 

Restrict specific tables from SE16/SE11

Former Member
0 Kudos

Dear Experts,

We have a requirement of lock from view of some specific tables in SE16/SE11. Please provide the solution.

Regards

Shishir

Accepted Solutions (1)

Accepted Solutions (1)

former_member183424
Active Contributor
0 Kudos

Create a new authorization group from SE54.

Go to SE54, then select Authorization group and click create / change.

Here create a new authorization object by clicking the new entries.

Then note the authorization group and assign the authorization group to table.

Go to SE11, enter the table name, click display. Then select Utilities - Assign Authorization Group.

Then click edit and enter the authorization group (which is created earlier)

Then in PFCG, for authorization object S_TABU_DIS enter the authorization group.

Now check the tables in SE16.

Former Member
0 Kudos

Hi,

Thanks for the info. Now what if I have already assigned * in auth object for my users. Means user have rights for all tables.But we want to restrict only for 5-6 tables, rest all tables users should be able to view.

I think from your suggestion, I have to create separate roles for separate tables. Very lengthy task

Regards

Shishir

former_member183424
Active Contributor
0 Kudos

No. Not a separate role for separate table. You can assign one roll to many tables and this role will be assigned to user authorization.

Former Member
0 Kudos

But my query is to restrict few tables, if I have already assign * in auth object.

former_member183424
Active Contributor
0 Kudos

Okay lets think it differently. Try this

Go to PFCG, for this authorization object, remove the * and press F4 on the field "Form" (you will get the list)

Then filter the all authorization group for authorization object S_TABU_DIS.

Then select all and press copy. (If you have already created your custom authorization group (ZDEV), as per my previous comment then just remove the particular authorization group)

You can see the all authorization group will be assigned to the authorization object.

Then save your role.

Then go to SE11, enter the table name, which you don't want to give authorization

Assign the authorization group (ZDEV) (which you have not given the authorization or which is not listed in PFCG).

Then check the scenario again.

Hope it will be correct solution for you.

Former Member
0 Kudos

Thanks. Issue closed

Answers (1)

Answers (1)

divyanshu_srivastava3
Active Contributor
0 Kudos

Hi Shishir,

As you can restrict them using authorization objects, so you should to raise this in security community.

Regards,

Divyanshu