cancel
Showing results for 
Search instead for 
Did you mean: 

Authorization objects of a transaction assigned to a specific role

Former Member
0 Kudos

Hello!

Like the title of this discussion says, I want to know where you can see the Transaction-Authorization objects relationship from a role. The table AGR_1251 helps me out a lot, giving me the relationship between ROLE, OBJECT, FIELD, LOW and HIGH; but it is still not enough.

I want to be able to know which authorization objects are affecting which transactions in a role, so in the end I can have a report with the following columns:

ROLE, TRANSACTION, OBJECT, FIELD, LOW and HIGH


Which table(s) from SAP contains this information?


Thank you a lot for your time.


Best Regards,


Luis.

Accepted Solutions (0)

Answers (5)

Answers (5)

0 Kudos

Hi Luis

I agree with Colleen. Also have a look at table USOBT_CD for all history on the SU24 updates.

Regards

Akhil

Colleen
Advisor
Advisor
0 Kudos

Hi Luis

There is no such report or table that will give you this complete view

The suggestions from others makes the assumption that you accurately maintain your SU24 data so you can join it. It is a good start but won't be an exact representation for transaction to authorisation object

Using USOBT_C and USOBX_C will help understand why the authorisations are in PFCG but they won't necessarily means the transactions needs all that access

Alos, if you have objects other than transactions in your role menu (e.g. services/RFCs/webdynpros), you will need to extract other tables to link to the objects as S_TCODE is not the only entry point.

Regards

Colleen

Former Member
0 Kudos

Hi Luis,

Proposal as 'Yes', in SU24 , will reflect in USOBX_C with OK Flag as Y.also check USOBT_C

Regards

Plaban

Former Member
0 Kudos

Hi,

Kindly check with the table USOTT which list out the T-code for the respective object.

Combine both AGR_1251 and USOTT for your requirement , since the role information is not available in the USOTT table.

anuj_kumar3
Participant
0 Kudos

Hi Luis,


Go to PFCG > Display Authorization data and then expend the required node. then click on the icon "Where-used list" for required object. This will give you all the t-code which associated to that object in that particular role. See below example.

Regards,

Anuj