Application Development Discussions
Join the discussions or start your own on all things application development, including tools and APIs, programming models, and keeping your skills sharp.
cancel
Showing results for 
Search instead for 
Did you mean: 

Not able to remove authorization completely

kuldeep_ahuja1
Explorer
0 Kudos

Hi,

As per business demand i have been told to remove VF11 and J1IH tcodes from users so that they can't cancel any kind of invoices .i have removed from all the roles (master/composite & single). also checked in S_TCODE there is nothing related to said Tcodes but when i am checking through tcode S_BCE_68001398 it showing access is still with several of users but other side its not showing any role through which its accessing tcodes.

For Example am attached access of 1  user (CO_SP1)

If somebody has faced same problem. then please let me know from where the access is going to that users.



Regards

Kuldeep

1 ACCEPTED SOLUTION

yakcinar
Active Contributor
0 Kudos

Hello Kuldeep,

You say you also listed users using S_TCODE auth object in SUIM. And these users donot have this auth in any of their roles.

So, try PFUD transaction to perform user master comparison.

There could be assigned profiles to that user which are not seen on either role nor profile tabs.

Regards,

Yuksel AKCINAR

10 REPLIES 10

Former Member
0 Kudos

Please check whether anything assigned in Profile tab on Su01 with this user.

Thanks

Asad

0 Kudos

Hi,

Thanks for Reply.

In Profile tab there are profiles of assigned roles of that user.

Also that profile still there who's corresponding roles i have deleted.

and if i go to delete profile is does not allow to delete.

please suggest

Regards

0 Kudos

you should have unassigned the users from the roles at first before deleting the roles. That why you are facing this issue. Please delete the user and recreate again.

Thanks

Asad

Former Member
0 Kudos

Hi Kuldeep,

Try comparing the profiles with the user name in transaction SUIM.

Select the users tab provide the user id and compare all the profiles.

Hope this would resolve the issue.

Regards

Mohammed

yakcinar
Active Contributor
0 Kudos

Hello Kuldeep,

You say you also listed users using S_TCODE auth object in SUIM. And these users donot have this auth in any of their roles.

So, try PFUD transaction to perform user master comparison.

There could be assigned profiles to that user which are not seen on either role nor profile tabs.

Regards,

Yuksel AKCINAR

0 Kudos

Dear All ,

I have checked with PFUD generating user master comparison also with deleting and re-assigning of users in that specific roles also i have regenerated roles, but no result .

This is master roles in screenshot ,I have checked with derive roles also.

Please suggest what else i can do.

0 Kudos

Hi Mohammed,

Can you please share a screenshot regarding Profile Comparison as i have not get any result as i have checked in SUIM - comparisons-.Profile

Regards

Kuldeep

former_member298454
Active Participant
0 Kudos

Kuldeep ,
Make sure all the roles that've been assigned to users have current profile version(grenn colour).

then copy all roles from user and give it in PFUD and execute which does profile reconcilation.This activity removes the profiles from user which is not associated with roles. After this activity ,if any profile exists for user in su01 that could be manually generated profile.

Thanks, Krishna

0 Kudos

Hello Kuldeep,

You can use SUPC transaction for mass profile generation.

As Krishnakumar mentioned regenerate all related profiles giving role names.

And check whether users have the transaction auth.

Regards,

Yuksel AKCINAR

kuldeep_ahuja1
Explorer
0 Kudos

Hi Yuksel ,

As you suggested i have all roles through PFUD .Now everything is fine.

Thanks a lot.

also thanks to Krishna .

Regards

Kuldeep ahuja